From a87a794cc9ea8b679663383cdcc3346131d79d25 Mon Sep 17 00:00:00 2001 From: codex Date: Tue, 25 Aug 2026 20:26:33 +0200 Subject: [PATCH] fix(workplans): adopt ADR-007 derived identifiers for unregistered records These workplans exist only in the retired local hub. Their random pre-ADR-007 identifiers are refused by C-06 as stale references, so they cannot be registered. Deriving from the canonical record id takes no identity from anything: central does not hold them and the old ids die with the cache. Records central already holds were deliberately left untouched. Refs CUST-WP-0068-T06 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006 --- ...f-service-and-user-administration-portal.md | 18 +++++++++--------- .../USER-WP-0021-portal-product-expansion.md | 12 ++++++------ ...egistration-and-jit-application-profiles.md | 12 ++++++------ .../USER-WP-0023-flex-auth-caller-identity.md | 8 ++++---- 4 files changed, 25 insertions(+), 25 deletions(-) diff --git a/workplans/USER-WP-0020-self-service-and-user-administration-portal.md b/workplans/USER-WP-0020-self-service-and-user-administration-portal.md index a072947..49d793e 100644 --- a/workplans/USER-WP-0020-self-service-and-user-administration-portal.md +++ b/workplans/USER-WP-0020-self-service-and-user-administration-portal.md @@ -13,7 +13,7 @@ depends_on: - USER-WP-0014 - USER-WP-0015 - USER-WP-0019 -state_hub_workstream_id: "35b9c315-e721-4e0b-9710-bad04f8d2519" +state_hub_workstream_id: "9d03e5da-9182-52a5-bdda-521a6c3bdfb6" --- # USER-WP-0020 - Production self-service and user administration portal @@ -36,7 +36,7 @@ authorization decisions. id: USER-WP-0020-T01 status: done priority: high -state_hub_task_id: "9886ac8d-7456-4de0-b019-351dfd74ec20" +state_hub_task_id: "ff492121-cdef-5900-9914-2645f648cc71" ``` Define browser/API trust boundaries, public and authenticated routes, role @@ -56,7 +56,7 @@ metadata for that later stage. id: USER-WP-0020-T02 status: done priority: high -state_hub_task_id: "fdb0c322-3efe-4077-bfba-1648787ef411" +state_hub_task_id: "01892337-2e06-53ab-95d2-d5ca01471596" ``` Expose versioned APIs for registration start/resume/complete, invitation @@ -87,7 +87,7 @@ breadth and OpenAPI/outbox delivery keep this task in progress. id: USER-WP-0020-T03 status: done priority: high -state_hub_task_id: "45ed1485-003d-4e5f-99fb-91b1b430f3fa" +state_hub_task_id: "701fbbf6-e58e-5f2e-a312-c8f2d135d3cd" ``` Build an accessible responsive browser flow for sign in, registration, @@ -111,7 +111,7 @@ accessibility breadth remain. id: USER-WP-0020-T04 status: done priority: high -state_hub_task_id: "16555b68-17ef-4902-bd30-f9a0cfe10f9e" +state_hub_task_id: "f33ec57b-0000-553d-a89c-024937c778df" ``` Tenant admins can invite, list, inspect, suspend, reactivate, and remove only @@ -136,7 +136,7 @@ removal, and full cross-tenant conformance remain. id: USER-WP-0020-T05 status: done priority: high -state_hub_task_id: "65ff5c96-134a-4ec2-ad92-511f0e5f6f04" +state_hub_task_id: "0ac332ed-35e2-5fd0-a376-8f595c0f4e69" ``` Package the service and web assets, use the provider-backed Postgres adapter, @@ -177,7 +177,7 @@ identity reconciliation passed. No secret value entered recorded evidence. id: USER-WP-0020-T06 status: done priority: high -state_hub_task_id: "39dc383c-7213-495d-8e12-58e614706afe" +state_hub_task_id: "f6f3f7f2-9106-58d9-8240-350c440c9722" ``` Automate positive and negative flows for self-registration, invite-only @@ -207,7 +207,7 @@ drifted, reconciled to `in_sync`, and removed without leaving directory state. id: USER-WP-0020-T07 status: done priority: high -state_hub_task_id: "b8d1c048-24d2-416c-908f-e500d63c6865" +state_hub_task_id: "62b5ee83-536d-5ee9-8b82-57f263de5811" ``` Through the deployed portal—not a one-shot script—create or claim Binky, @@ -253,7 +253,7 @@ open `tenant:platform` and `tenant:coulomb` administration were both denied. id: USER-WP-0020-T08 status: done priority: medium -state_hub_task_id: "ecbdeef3-a0a9-40d6-9722-5cc650d78a49" +state_hub_task_id: "8d9e2ce4-c99e-52b4-839b-03433fc34d44" ``` Close after the portal is production-operable and the Binky acceptance case diff --git a/workplans/USER-WP-0021-portal-product-expansion.md b/workplans/USER-WP-0021-portal-product-expansion.md index f7fbbb6..afa1b57 100644 --- a/workplans/USER-WP-0021-portal-product-expansion.md +++ b/workplans/USER-WP-0021-portal-product-expansion.md @@ -12,7 +12,7 @@ updated: "2026-08-19" depends_on: - USER-WP-0020 - TEN-WP-0005 -state_hub_workstream_id: "ba217f48-5fa5-4178-9c79-73aa225f3f2e" +state_hub_workstream_id: "1f8ef8dd-b937-5601-8522-30eb7f7e0994" --- # USER-WP-0021 - Portal product expansion @@ -26,7 +26,7 @@ holding the proven production MVP open. Activate according to tenant demand. id: USER-WP-0021-T01 status: done priority: high -state_hub_task_id: "342299b8-d9a3-408d-bf0d-914496714d5f" +state_hub_task_id: "a3f20b37-6a6d-578c-8bdf-56ac73d98695" ``` Add invitation claim/resend/expiry, platform tenant management and recovery @@ -53,7 +53,7 @@ Broader tenant update/retirement operations remain. id: USER-WP-0021-T02 status: done priority: medium -state_hub_task_id: "dc548cfb-db7c-4cbd-864f-2effeebc3dbd" +state_hub_task_id: "10426f13-0a1e-5ad6-bb86-dad4264f3774" ``` Add invitation acceptance, email-verification status, consent/profile, @@ -89,7 +89,7 @@ resume the durable journey. This completes the self-service onboarding scope. id: USER-WP-0021-T03 status: done priority: high -state_hub_task_id: "3e0b41ee-6159-46a4-a9fe-c5b6d714cc2a" +state_hub_task_id: "37077db0-b53e-5671-9615-5adfc8053812" ``` Add platform tenant creation, first-admin bootstrap, invitation/recovery @@ -128,7 +128,7 @@ provider-neutral lifecycle ports, and redacted diagnostics. id: USER-WP-0021-T04 status: done priority: high -state_hub_task_id: "fb59245e-6989-4bd9-b72a-68e53ea9f0af" +state_hub_task_id: "6aae1965-5ba2-58b4-a631-47cad0139e54" ``` Automate duplicate/expired/replayed invitation, session expiry, provider @@ -192,7 +192,7 @@ deployed and wants its own permission. id: USER-WP-0021-T05 status: done priority: low -state_hub_task_id: "05046780-9625-47c2-8caf-f57e9239c603" +state_hub_task_id: "2d6b38c4-6007-58a3-aebe-09a90102ebec" ``` When a tenant requires SAML/OIDC federation, SCIM, directory synchronization, diff --git a/workplans/USER-WP-0022-public-registration-and-jit-application-profiles.md b/workplans/USER-WP-0022-public-registration-and-jit-application-profiles.md index 82394ba..edb2119 100644 --- a/workplans/USER-WP-0022-public-registration-and-jit-application-profiles.md +++ b/workplans/USER-WP-0022-public-registration-and-jit-application-profiles.md @@ -12,7 +12,7 @@ updated: "2026-08-19" depends_on: - USER-WP-0021 - NK-WP-0025 -state_hub_workstream_id: "97145e5b-5f8f-4cb1-9135-2593f5baac8f" +state_hub_workstream_id: "3de6231e-4712-543f-8177-9697133c366e" --- # USER-WP-0022 - public registration and application JIT @@ -28,7 +28,7 @@ identity creation to NetKingdom. id: USER-WP-0022-T01 status: done priority: high -state_hub_task_id: "43dd49b7-6dbc-4117-a401-6d9f6e59aa26" +state_hub_task_id: "048d78c0-f105-5473-a5f8-6e2ae7596829" ``` Add accessible browser/API entry points for start, email verification, @@ -138,7 +138,7 @@ below. id: USER-WP-0022-T02 status: done priority: high -state_hub_task_id: "74239ce4-5c1e-46cf-8abf-3cbec3f3f989" +state_hub_task_id: "38a46eac-ee55-5992-9955-5a180a5172da" ``` Use the existing provisioning port to create or resume an ordinary NetKingdom @@ -177,7 +177,7 @@ orchestration boundary without exposing provider credentials or passwords. id: USER-WP-0022-T03 status: cancel priority: high -state_hub_task_id: "01fa1a22-0f4a-4a36-a9b3-0f94d3c70be1" +state_hub_task_id: "3e5061f8-0602-51a1-a8eb-89ff3c3bdb7e" ``` Implement an idempotent ensure-application-profile operation keyed by @@ -199,7 +199,7 @@ coulomb-social consumer implements this under CSOC-WP-0003 using its unique id: USER-WP-0022-T04 status: cancel priority: high -state_hub_task_id: "d3bec8c6-e8d8-46d5-8fa2-b4675ff1ade8" +state_hub_task_id: "a1b998af-a4db-5daf-af03-00e4f08c6e3a" ``` Model the application's minimum assurance and per-user/profile step-up policy @@ -219,7 +219,7 @@ step-up. user-engine must not become the token assurance authority. id: USER-WP-0022-T05 status: done priority: high -state_hub_task_id: "0a5a5f3a-0d47-4d5d-bda5-e2c7c737fee6" +state_hub_task_id: "a1d70171-7490-5fe0-b374-0b7faed670c0" ``` Cover enumeration resistance, duplicate username/email, verification diff --git a/workplans/USER-WP-0023-flex-auth-caller-identity.md b/workplans/USER-WP-0023-flex-auth-caller-identity.md index a4ba691..b82c77e 100644 --- a/workplans/USER-WP-0023-flex-auth-caller-identity.md +++ b/workplans/USER-WP-0023-flex-auth-caller-identity.md @@ -9,7 +9,7 @@ owner: codex topic_slug: netkingdom created: "2026-08-18" updated: "2026-08-19" -state_hub_workstream_id: "014d0886-b690-4860-8337-c718e440f678" +state_hub_workstream_id: "4255c44c-70f3-5aa9-a301-4a0c0e1a9a47" --- # USER-WP-0023 — flex-auth caller identity @@ -21,7 +21,7 @@ authorization semantics. id: USER-WP-0023-T01 status: done priority: high -state_hub_task_id: "8dae0fe1-f8a0-4276-8ae3-fe1f5b410669" +state_hub_task_id: "f513c592-35df-5950-91ae-f4d5297b67d0" ``` Read the audience-scoped caller token from a file per authorization decision, @@ -40,7 +40,7 @@ provider-gated skips. id: USER-WP-0023-T02 status: done priority: high -state_hub_task_id: "4a6c85e8-1ada-4147-b6b7-d340b7e5192c" +state_hub_task_id: "eb4ec2b0-36b3-5cc8-b912-d0bdf3d51cf0" ``` Align tenant-authority reads with the protected `tenant.read` action and actor @@ -51,7 +51,7 @@ adapter request coverage. id: USER-WP-0023-T03 status: done priority: high -state_hub_task_id: "0499c65b-491d-4ed1-8549-f58dba48f612" +state_hub_task_id: "dc4c771e-c16f-5609-bd09-20f051a6aae9" ``` Promote together with the flex-auth A2 digest and the NetKingdom projected