Bind native OpenRouter approval to custody and delivery inputs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 00:54:55 +02:00
parent 0783b50216
commit 7ba1b6223e
16 changed files with 656 additions and 7 deletions

View file

@ -710,9 +710,15 @@ priority: high
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
```
Dependency: T01T03, T05, T06 are done. T04 still waits on the durable
ActionAuthorization serving path. Also requires explicit per-lane approvals
and scoped production authority from railiance-platform.
Dependency: T01T03, T05, T06 are done. T04 implements claim/PDP Check/CAS consume;
ActionAuthorization is deferred, not its serving prerequisite. Production still
waits on the admitted Approval Engine identity/audit/service and client-reader
path, explicit per-lane approval and scoped attended platform authority.
2026-09-14: SECRETS-WP-0010-T01/T02 implemented exact catalog-target binding and
the proposed value-safe OpenRouter recipient. FLEX-WP-0026 promoted the dedicated
PDP to revision 4 and verified the live replay join. Native admission/verification
remains SECRETS-WP-0010-T03; no real key was retrieved and this task remains wait.
Resume `SECRETS-WP-0006-T05` lane by lane. Apply only the exact native policy and
bounded AppRole, verify every field plus unrelated-consumer denial, confirm the