# flex-auth T03 replay fixtures Copied verbatim from `flex-auth/examples/secrets-engine/replay/` (commit `9e10d1c`, `FLEX-WP-0021-T03`). Real `DecisionEnvelope`s emitted by the published `secrets-engine.catalog-lane.lifecycle` v1 package via `go run ./cmd/flex-auth check`, from `flex-auth/local` in `standalone` mode. Vendored so the digest contract test is hermetic. Regenerate upstream and re-copy if the contract version changes. Re-copied 2026-09-06 (twice, both upstream regenerations): 1. commit `9f3e7e3` completed the approval-claim on `context.approval`. Because `context` is hashed material, completing the claim moved the request digest. 2. commit `dd3ce4c` (`FLEX-DEC-2026-007`) published `binding.approval_binding_digest` and set the embedded claim's `binding.pdp_digest` to it with `binding.pdp_path` true. The request digest moved once more with the claim's contents; the approval-binding digest did **not**, which is the property the fixture now demonstrates rather than asserts. `decision_rotate.json` is unchanged and carries no `approval_binding_digest` — the field is omitted on claim-free decisions rather than duplicated onto them. **Pinned here** (stable across runs, per the upstream README): `binding.request_digest`, `binding.approval_binding_digest`, `provenance.policy_package_digest`, `provenance.registry_snapshot_digest`, and the presence/absence of `provenance.input_claim_digests.context`. `approval_binding_digest` is not only pinned but **rederived** by `test_pdp_digest_equals_the_published_approval_binding_digest`: our canonical implementation must reproduce it from the fixture's own request. A pin asserts the constant; rederiving it proves we hash the same material flex-auth does. **Never pin:** `id`, `provenance.decision_time`, `lifetime.not_before`, `lifetime.expires_at` — all move with the clock.