Establish scoped KeyCape factor custody and verified automatic renewal
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-13 16:25:33 +02:00
parent 6fe39a9b6a
commit 259deb2763
2 changed files with 12 additions and 2 deletions

View file

@ -41,7 +41,7 @@ P02/P04/P07: preserve first-admin setup on retry without duplication, explicit t
```task
id: USER-WP-0030-T03
status: wait
status: progress
priority: high
state_hub_task_id: "07510026-caee-54d7-998c-a8d2b2f17773"
```
@ -70,3 +70,13 @@ Provider gate rechecked: net-kingdom-privacyidea-admin-token remains non-resolva
T04 release evidence: docs/evidence/2026-09-13-platform-admin-support.md. Source b8506ef, 216 regression tests (seven optional skips), 19 platform tests, 16 browser checks; CI and rollout verified. T03 stays waiting; P04/P05/P06 completeness is not claimed.
Provider consumer progress: KeyCape source 632b1f1 implements exclusive adminTokenFile renewal without issuer restart, fresh credential reads for both factor lookup and validation, no stale fallback, bounded/sanitized errors, request timeout and redirect refusal. OTP validation now requires successful provider status as well as a positive value. All Go suites pass; owner custody/issuance and live factor/policy acceptance remain T03. KEY-WP-0035-T04 tracks release evidence.
2026-09-13: the user authorized establishing custody and authenticated through
the contained OpenBao lane. RPF-WP-0040 / CCR-2026-0023 now provide a dedicated
realm-scoped provider credential, separate issuer custody, automatic renewal,
namespace-restricted ESO delivery and KeyCape mounted-file activation. Native
scope denial, per-user factor lookup and mounted renewal passed; fourteen
offline tests pass and exact-commit CI is configured. This supersedes the earlier
missing-owner gate for factor reads. T03 remains in progress for P04 audited
factor/account recovery, P05 notification operations and remaining expiry drills,
and P06 scoped policy/onboarding acceptance. Historical NK-WP-0033 is separate.