docs: specify approval client workstation custody procedure
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-10 10:15:08 +02:00
parent 42b48aa54f
commit 98d72ceb1d
2 changed files with 66 additions and 2 deletions

View file

@ -226,3 +226,15 @@ CCR-2026-0019 operator-group/file-delivery return, INFD-WP-0001-T07/T08 real hum
approval, audit custody and deployed services/PDP/native delivery. CCR-2026-0020
was cancelled on owner withdrawal; do not wait for or recreate its presenter.
No runtime artifact rebuild is needed for this credential-engine change.
### 2026-09-10 workstation procedure return
`docs/approval-service-auth.md` now gives the concrete CCR-2026-0019 consumer
procedure requested by Platform: an operator-owned 0700 runtime session directory
outside Git, a new 0600 file, path-only CLI configuration, claim/consume lifetime,
EXIT/INT/TERM cleanup and explicit residual-file handling after hard interruption.
The source review distinguishes implemented permission/location/empty-file checks
from operator-owned creation, parent custody and cleanup. No automatic cleanup
or live reader proof is claimed. The exact group remains NetKingdom/KeyCape's
return, followed by reviewed attended admission and positive/negative evidence.
T03 stays wait; no identity, role, secret, runtime or route readiness changed.