From 260029e2f623829bd057c009e79f37e889f365d0 Mon Sep 17 00:00:00 2001 From: tegwick Date: Tue, 18 Aug 2026 10:53:41 +0200 Subject: [PATCH] Record flex-auth fail-closed coverage Co-Authored-By: Claude Opus 5 --- workplans/USER-WP-0023-flex-auth-caller-identity.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/workplans/USER-WP-0023-flex-auth-caller-identity.md b/workplans/USER-WP-0023-flex-auth-caller-identity.md index be78d11..7cd56c7 100644 --- a/workplans/USER-WP-0023-flex-auth-caller-identity.md +++ b/workplans/USER-WP-0023-flex-auth-caller-identity.md @@ -28,6 +28,14 @@ Read the audience-scoped caller token from a file per authorization decision, fail closed on rotation/read errors, and cover token rotation. Completed 2026-08-18; the full suite passes 143 tests with three provider-gated skips. +2026-08-18 fail-closed coverage: the contract promised denial on a missing, +empty, or unreadable token file, but only rotation was proven. Conformance now +covers all three unusable-token cases and asserts the adapter never reaches +flex-auth without a usable credential, so an unauthenticated call cannot be +mistaken for an authorized one. A further test proves the token value appears +in neither the deny reason nor the decision repr. Suite: 148 tests, three +provider-gated skips. + ```task id: USER-WP-0023-T02 status: done