secrets-engine/tests/fixtures/flex-auth-replay/PROVENANCE.md
tegwick ee4e901611
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
fix: bind approval consumption to actual Flex Auth submissions
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 08:55:46 +02:00

1.2 KiB

Flex Auth replay contract fixtures

Copied byte-for-byte on 2026-09-09 from flex-auth revision 88b354377c8e26b162f1234e673072f1c06dcd89, examples/secrets-engine/ and its replay/ directory. Contract: FLEX-DEC-2026-012. These are standalone evaluator outputs, not deployment evidence.

Each output is paired with its independently supplied check_request input. Tests compute submitted_request_digest from that input; they do not reconstruct it from the enriched response. Existing request_digest, approval_binding_digest, policy-package and registry-snapshot pins are unchanged. Policy remains v2. Approval correspondence compares claim.binding.pdp_digest with the evaluator's approval_binding_digest. Neither is computed from the unenriched request.

Tests inject the actual decision time instead of modifying captured lifetimes. The older flex-auth-live fixture remains untouched and must fail the new contract because it has no submitted_request_digest.

tools/exercise_approval_identity.py additionally compiles the owner evaluator and runs real KeyCape/Approval Engine/Flex Auth joins with synthetic credentials, including registry override and destructive-action dual control. Its receipt pins source, binary and producer inputs; it makes no live admission claim.