Close IAM Profile integration gate
This commit is contained in:
parent
7d823bd12f
commit
4158f05cff
4 changed files with 42 additions and 14 deletions
|
|
@ -84,6 +84,14 @@ mapping, readiness-summary inputs, and read-model gaps. This closes the T14
|
|||
definition gate while leaving deployed evidence, cutover coupling, and UI work
|
||||
for T16/T17/T18.
|
||||
|
||||
2026-06-27 T03 closeout: Core Hub now has a reusable IAM Profile verifier and
|
||||
FastAPI dependency plus `tests/test_iam_profile.py`, which proves OIDC
|
||||
discovery, JWKS signature validation, authorization-code + PKCE token issuance,
|
||||
protected endpoint access, required IAM Profile claims, missing-token rejection,
|
||||
wrong-audience rejection, and production rejection of local-development issuers.
|
||||
This closes the identity integration template while leaving production issuer
|
||||
wiring for the deployed Core Hub gates.
|
||||
|
||||
## Remaining Gates
|
||||
|
||||
- Run `make deployed-smoke` or `make operator-cli CLI_ARGS="deployed-smoke ..."`
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue