2026-07-23 21:56:43 +02:00
|
|
|
# Work Records — tenant-engine
|
|
|
|
|
|
|
|
|
|
> Generated by `statehub fix-consistency` (CUST-WP-0061-T04, work-record
|
|
|
|
|
> stage 3). Do not edit by hand — edit the source file/block listed for
|
|
|
|
|
> each record and re-run fix-consistency to refresh this index. Archived
|
|
|
|
|
> workplans are omitted; closed decisions/intakes/engagements stay listed
|
|
|
|
|
> so recently-resolved work is still visible. [auto]
|
|
|
|
|
|
|
|
|
|
| Kind | ID | Status | Lane | Source |
|
|
|
|
|
| --- | --- | --- | --- | --- |
|
|
|
|
|
| workplan | TEN-WP-0001 | finished | — | workplans/TEN-WP-0001-statehub-bootstrap.md |
|
2026-07-23 22:24:37 +02:00
|
|
|
| workplan | TEN-WP-0002 | finished | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
TEN-WP-0003: FlexAuthWriteAuthorizer -- gate writes through flex-auth
flex_auth.py: CheckRequest + FlexAuthCheckClient against flex-auth's real
POST /v1/check contract (schemas/check_request.schema.json,
decision_envelope.schema.json, read directly from the flex-auth repo, not
guessed). Fail-closed by construction: only effect=="allow" authorizes;
every other effect, non-200, malformed body, or transport failure resolves
to deny, nothing raises past is_allowed().
authz.FlexAuthWriteAuthorizer implements the existing WriteAuthorizer
Protocol. Action -> resource-type mapping coordinated with FLEX-WP-0008's
planned vocabulary (both repos reference the same table).
DefaultDenyWriteAuthorizer stays the fallback when no flex-auth URL is
configured.
config.py: Settings.from_env(), mirroring qonto-assistant's pattern.
docs/flex-auth-integration.md documents the contract, fail-closed rule,
and current real state (denies everything until FLEX-WP-0008 lands).
60 tests passing. Verified live twice over real HTTP between separate
processes (not just MockTransport): a deny-returning flex-auth double
produces 403 from POST /tenants, an allow-returning one produces 201.
Also registered (not implemented) the two workplans this depends on for a
complete picture: flex-auth/FLEX-WP-0008 (protected-system registration --
what makes allow reachable) and key-cape/KEY-WP-0005 (discovered key-cape
emits none of iam-profile_v0.3.md's core claims yet, not just missing
tenant_roles -- a bigger, security-sensitive gap flagged rather than
quietly worked around).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 22:54:44 +02:00
|
|
|
| workplan | TEN-WP-0003 | active | — | workplans/TEN-WP-0003-flex-auth-write-authorizer.md |
|
2026-07-23 21:56:43 +02:00
|
|
|
| task | TEN-WP-0001-T01 | done | — | workplans/TEN-WP-0001-statehub-bootstrap.md |
|
|
|
|
|
| task | TEN-WP-0001-T02 | done | — | workplans/TEN-WP-0001-statehub-bootstrap.md |
|
|
|
|
|
| task | TEN-WP-0001-T03 | done | — | workplans/TEN-WP-0001-statehub-bootstrap.md |
|
2026-07-23 22:01:51 +02:00
|
|
|
| task | TEN-WP-0002-T01 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
|
|
|
|
| task | TEN-WP-0002-T02 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
|
|
|
|
| task | TEN-WP-0002-T03 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
2026-07-23 22:24:37 +02:00
|
|
|
| task | TEN-WP-0002-T04 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
|
|
|
|
| task | TEN-WP-0002-T05 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
|
|
|
|
| task | TEN-WP-0002-T06 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
|
|
|
|
| task | TEN-WP-0002-T07 | done | — | workplans/TEN-WP-0002-domain-model-and-scaffold.md |
|
TEN-WP-0003: FlexAuthWriteAuthorizer -- gate writes through flex-auth
flex_auth.py: CheckRequest + FlexAuthCheckClient against flex-auth's real
POST /v1/check contract (schemas/check_request.schema.json,
decision_envelope.schema.json, read directly from the flex-auth repo, not
guessed). Fail-closed by construction: only effect=="allow" authorizes;
every other effect, non-200, malformed body, or transport failure resolves
to deny, nothing raises past is_allowed().
authz.FlexAuthWriteAuthorizer implements the existing WriteAuthorizer
Protocol. Action -> resource-type mapping coordinated with FLEX-WP-0008's
planned vocabulary (both repos reference the same table).
DefaultDenyWriteAuthorizer stays the fallback when no flex-auth URL is
configured.
config.py: Settings.from_env(), mirroring qonto-assistant's pattern.
docs/flex-auth-integration.md documents the contract, fail-closed rule,
and current real state (denies everything until FLEX-WP-0008 lands).
60 tests passing. Verified live twice over real HTTP between separate
processes (not just MockTransport): a deny-returning flex-auth double
produces 403 from POST /tenants, an allow-returning one produces 201.
Also registered (not implemented) the two workplans this depends on for a
complete picture: flex-auth/FLEX-WP-0008 (protected-system registration --
what makes allow reachable) and key-cape/KEY-WP-0005 (discovered key-cape
emits none of iam-profile_v0.3.md's core claims yet, not just missing
tenant_roles -- a bigger, security-sensitive gap flagged rather than
quietly worked around).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 22:54:44 +02:00
|
|
|
| task | TEN-WP-0003-T01 | todo | — | workplans/TEN-WP-0003-flex-auth-write-authorizer.md |
|
|
|
|
|
| task | TEN-WP-0003-T02 | todo | — | workplans/TEN-WP-0003-flex-auth-write-authorizer.md |
|
|
|
|
|
| task | TEN-WP-0003-T03 | todo | — | workplans/TEN-WP-0003-flex-auth-write-authorizer.md |
|
|
|
|
|
| task | TEN-WP-0003-T04 | todo | — | workplans/TEN-WP-0003-flex-auth-write-authorizer.md |
|