Bind native OpenRouter approval to custody and delivery inputs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 00:54:55 +02:00
parent 0783b50216
commit 7ba1b6223e
16 changed files with 656 additions and 7 deletions

View file

@ -1,3 +1,15 @@
> Current protocol correction (2026-09-14): follow claim → validated PDP Check →
> CAS consume, as implemented in docs/approval-consumption.md. ActionAuthorization
> is deferred and never ratified. The OpenRouter-specific current implementation,
> live PDP receipt and remaining service/reader gates are in
> docs/openrouter-native-access.md (SECRETS-WP-0010).
> Current protocol correction (2026-09-14): follow claim → validated PDP Check →
> CAS consume, as implemented in docs/approval-consumption.md. ActionAuthorization
> is deferred and never ratified. The OpenRouter-specific current implementation,
> live PDP receipt and remaining service/reader gates are in
> docs/openrouter-native-access.md (SECRETS-WP-0010).
# Native lane cutover (SECRETS-WP-0006-T05 / T06)
Status: procedure only. Live apply is still fail-closed until
@ -44,7 +56,7 @@ Provenance CCR: `CCR-2026-0003` (existing workload lane only).
Required before OpenBao:
1. Canonical ActionAuthorization for `action=apply`, resource
1. Live approval-claim, validated PDP Check and CAS consume for `action=apply`, resource
`catalog:openrouter-llm-connect`, stage `prod`, exact policy/auth targets
`se-prod-openrouter-llm-connect`.
2. Successful approval-engine CAS consume of that request digest