secrets-engine/workplans
tegwick 10baad914e
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
fix: compare structured binding fields, not a digest we cannot reproduce
The live proof in 03c0569 showed validate_decision_envelope rejecting every
real allow. The evaluator normalizes before hashing -- the request tenant is
copied onto subject and resource, and a registry hit copies type, tenant and
selected attributes onto the refs -- so binding.request_digest covers
material we never sent. Byte-equality against our unenriched request was
unsatisfiable, not merely mismatched.

THE RULE WAS ALREADY PUBLISHED. flex-auth's canonical-request-digest.md
section "Normalization" states the enrichment and tells consumers what to do
instead: compare structured binding fields to the proposed action, treat
request_digest as the evaluator's statement of what it hashed, and recompute
independently over the tuple the binding carries. I raised this with them as
an unpublished gap and asked them to pick between three shapes; it was in
their contract already and the answer was the first of the three. Nothing
was blocked on them, and this follows the published rule rather than one I
inferred.

- _require_binding_corresponds: everything we proposed must survive
  unchanged -- tenant, action, context, subject.id/type,
  resource.id/type/system, and every attribute we sent.
- Enrichment may add only type, tenant, attributes. Any other added field is
  refused, and an enriched tenant must be the request tenant, so a
  cross-tenant binding cannot arrive wearing our request's clothes.
- request_digest is still verified, now against binding_tuple(binding) for
  self-consistency rather than against material we never sent.
- The envelope's top-level subject/resource get the same rule; they are
  enriched too.

Proved against the artifact: the real decision:0f9c98f14545c42d now
validates, and the unrefreshed envelope is refused on lifetime -- reaching
the lifetime check at all is the evidence the binding checks pass on a real
decision. Negatives cover a restated resource.attributes.stage, a foreign
subject.tenant, and an unexpected enrichment field.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E4tNMAYcSQmZWUE4wqP4ij

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715726@bnt-lap001
Assistant-Session: 80a42b32-cba6-4b23-8be0-68819b1a6092
2026-09-07 09:04:57 +02:00
..
archived CUST-WP-0055 T07: add archive workplan terminology grandfather note 2026-07-08 20:26:38 +02:00
ADHOC-2026-08-21.md repo.work.assign_missing_identifiers 2026-09-04 00:03:13 +02:00
ADHOC-2026-08-23.md repo.work.assign_missing_identifiers 2026-09-04 00:03:13 +02:00
SECRETS-WP-0001-statehub-bootstrap.md chore(wp-0001): close State Hub bootstrap workplan; de-template repo identity 2026-06-29 12:14:00 +02:00
SECRETS-WP-0002-bootstrap.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
SECRETS-WP-0004-warden-sign-token-lane.md Close warden-sign token lane 2026-06-30 01:01:55 +02:00
SECRETS-WP-0005-scope-intent-value-gaps.md Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
SECRETS-WP-0006-catalog-lane-adoption.md docs: record whynot-design lane pointer discrepancy from ops-warden 2026-09-06 00:46:02 +02:00
SECRETS-WP-0007-production-lifecycle-hardening.md feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
SECRETS-WP-0008-layer-model-lifecycle-conformance.md feat: implement the PIP claim + validate authorization join 2026-09-06 01:01:55 +02:00
SECRETS-WP-0009-glas-claude-native-delivery.md fix: compare structured binding fields, not a digest we cannot reproduce 2026-09-07 09:04:57 +02:00