43 lines
3.1 KiB
Markdown
43 lines
3.1 KiB
Markdown
|
|
# Loose-end review — 2026-09-27
|
|||
|
|
|
|||
|
|
Reviewed all 37 workplan files: 32 finished and five active. No ready,
|
|||
|
|
proposed, backlog or already-blocked workplans were present. The five open
|
|||
|
|
workplans are now blocked; no task or workplan was created.
|
|||
|
|
|
|||
|
|
## Completed existing task
|
|||
|
|
|
|||
|
|
USER-WP-0026-T02 is done. The immutable release and anonymous browser evidence
|
|||
|
|
in `railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md` is now
|
|||
|
|
supplemented by `key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`.
|
|||
|
|
The founder confirmed fresh login/account switching; issuer telemetry records
|
|||
|
|
three fresh portal authentication/token-issuance sequences following an MFA
|
|||
|
|
failure. KEY-WP-0034-T02 is also done. U10 now reflects this evidence.
|
|||
|
|
Application JWTs may outlive provider logout. The receipt does not complete the
|
|||
|
|
second-user/company-workflow pilot in VERGABE-WP-0019-T06.
|
|||
|
|
|
|||
|
|
## Remaining blockers
|
|||
|
|
|
|||
|
|
| Workplan / tasks | Current dependency and resumption condition |
|
|||
|
|
| --- | --- |
|
|||
|
|
| USER-WP-0026-T03, USER-WP-0028-T02 | Application/authorization owners must establish the supported workload catalogue, registered HTTPS entry points, identity/tenant/action mapping, authoritative decisions and scoped grant/revocation contract. Local application records, memberships and the PDP evaluator do not supply fleet admission. |
|
|||
|
|
| USER-WP-0027-T04, USER-WP-0028-T03 | Attended real-user OTP enrollment, cancellation, replacement/lost-factor recovery and fresh-login acceptance; verified portal setup handoff. KEY-WP-0035 and RPF-WP-0040 already delivered credential custody, renewal and optional policy. P04/P06 prove the implementation using disposable installed-provider fixtures. NK-WP-0033's separate incident also closed on September 23. |
|
|||
|
|
| USER-WP-0027-T06 | Full matrix depends on the preceding application/OTP work, setup-link delivery and VERGABE-WP-0019-T06 second-user/setup-to-workflow acceptance. |
|
|||
|
|
| USER-WP-0034-T02 | FLEX-WP-0020 section 8 still waits for the renamed canonical checkout. `/home/worsch/access-engine` is absent; `/home/worsch/flex-auth/docs/iam-profile-consumption.md` exists. Keep the current source link until registration. |
|
|||
|
|
| USER-WP-0035-T02 | The provider-owned password-setup link still needs a supported delivery handoff and intended-person receipt evidence. EMAIL-WP-0004 and P05 delivered the mail service; its invitation outbox adapter is not a setup-link delivery contract. |
|
|||
|
|
|
|||
|
|
The review corrects stale missing-credential and missing-mail-infrastructure
|
|||
|
|
claims rather than requesting replacement secrets or rebuilding working provider
|
|||
|
|
features. Existing tasks retain all remaining work. No production configuration
|
|||
|
|
or real account was changed, and no email was sent.
|
|||
|
|
|
|||
|
|
## Validation
|
|||
|
|
|
|||
|
|
- `make test`: 264 tests run, eight optional integration skips, no failures;
|
|||
|
|
layer conformance passed.
|
|||
|
|
- `make test-journeys`: 66 tests passed, no skips. The report remains incomplete
|
|||
|
|
for U02–U09, T02, T04 and T05; account switching U10 is no longer a blocker.
|
|||
|
|
- `git diff --check`: passed.
|
|||
|
|
|
|||
|
|
Local tests validate the implementation and journey mappings. They do not
|
|||
|
|
substitute for the external acceptance evidence listed above.
|