user-engine/docs/evidence/2026-09-27-loose-ends-review.md

43 lines
3.1 KiB
Markdown
Raw Normal View History

# Loose-end review — 2026-09-27
Reviewed all 37 workplan files: 32 finished and five active. No ready,
proposed, backlog or already-blocked workplans were present. The five open
workplans are now blocked; no task or workplan was created.
## Completed existing task
USER-WP-0026-T02 is done. The immutable release and anonymous browser evidence
in `railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md` is now
supplemented by `key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`.
The founder confirmed fresh login/account switching; issuer telemetry records
three fresh portal authentication/token-issuance sequences following an MFA
failure. KEY-WP-0034-T02 is also done. U10 now reflects this evidence.
Application JWTs may outlive provider logout. The receipt does not complete the
second-user/company-workflow pilot in VERGABE-WP-0019-T06.
## Remaining blockers
| Workplan / tasks | Current dependency and resumption condition |
| --- | --- |
| USER-WP-0026-T03, USER-WP-0028-T02 | Application/authorization owners must establish the supported workload catalogue, registered HTTPS entry points, identity/tenant/action mapping, authoritative decisions and scoped grant/revocation contract. Local application records, memberships and the PDP evaluator do not supply fleet admission. |
| USER-WP-0027-T04, USER-WP-0028-T03 | Attended real-user OTP enrollment, cancellation, replacement/lost-factor recovery and fresh-login acceptance; verified portal setup handoff. KEY-WP-0035 and RPF-WP-0040 already delivered credential custody, renewal and optional policy. P04/P06 prove the implementation using disposable installed-provider fixtures. NK-WP-0033's separate incident also closed on September 23. |
| USER-WP-0027-T06 | Full matrix depends on the preceding application/OTP work, setup-link delivery and VERGABE-WP-0019-T06 second-user/setup-to-workflow acceptance. |
| USER-WP-0034-T02 | FLEX-WP-0020 section 8 still waits for the renamed canonical checkout. `/home/worsch/access-engine` is absent; `/home/worsch/flex-auth/docs/iam-profile-consumption.md` exists. Keep the current source link until registration. |
| USER-WP-0035-T02 | The provider-owned password-setup link still needs a supported delivery handoff and intended-person receipt evidence. EMAIL-WP-0004 and P05 delivered the mail service; its invitation outbox adapter is not a setup-link delivery contract. |
The review corrects stale missing-credential and missing-mail-infrastructure
claims rather than requesting replacement secrets or rebuilding working provider
features. Existing tasks retain all remaining work. No production configuration
or real account was changed, and no email was sent.
## Validation
- `make test`: 264 tests run, eight optional integration skips, no failures;
layer conformance passed.
- `make test-journeys`: 66 tests passed, no skips. The report remains incomplete
for U02–U09, T02, T04 and T05; account switching U10 is no longer a blocker.
- `git diff --check`: passed.
Local tests validate the implementation and journey mappings. They do not
substitute for the external acceptance evidence listed above.