Close recovery acceptance and reconcile blocked workplans
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Account journey acceptance / journeys (push) Successful in 10s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e38e-e5bb-7b50-968d-a738a0294997
This commit is contained in:
tegwick 2026-09-27 17:54:47 +02:00
parent b73f553c18
commit eca7c54748
9 changed files with 162 additions and 46 deletions

View file

@ -4,12 +4,12 @@ type: workplan
title: "Account recovery and visible identity and access"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: user-engine
created: "2026-09-12"
updated: "2026-09-12"
updated: "2026-09-27"
state_hub_workstream_id: "0aea0a52-13f9-515b-bda8-665f8a4f2d5e"
---
@ -37,7 +37,7 @@ MFA downgrade, global JWT revocation claim or inferred workload entitlements.
```task
id: USER-WP-0026-T02
status: progress
status: done
priority: high
state_hub_task_id: "ad5b0a77-d8ec-5e07-9a9e-2fa231a6f792"
```
@ -49,11 +49,19 @@ logout. Related: USER-WP-0025-T03 and VERGABE-WP-0019-T06.
Source verification: 182 tests passed with three optional integration skips; layer conformance passed. Immutable publication and live checks are in progress.
2026-09-27: closed against the completed release and attended owner evidence.
The 2026-09-12 release receipt is supplemented by
`key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`:
the founder confirmed fresh login and account switching, and the issuer recorded
three fresh portal authentication/token-issuance sequences after an MFA failure.
KEY-WP-0034-T02 is done. Existing application JWTs may still outlive provider
logout. This does not accept the remaining multi-user Vergabe pilot.
## Discover workload access from authoritative application records
```task
id: USER-WP-0026-T03
status: todo
status: wait
priority: high
state_hub_task_id: "95e9a6d4-7e57-5483-97c5-3f4a45bb6767"
```
@ -74,3 +82,11 @@ checks and six fresh anonymous Chromium checks pass, including actual provider
logout POST and return to the portal without test overrides. Real-user identity
switching is still awaiting operator evidence; no authenticated/MFA acceptance
is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md.
2026-09-27: blocked on an owner-supported workload catalogue/admission and
scoped grant/revocation contract. The access-engine policy evaluator and local
user-engine application/membership records do not establish that contract.
Need registered HTTPS entry points, exact identity/tenant/action mapping,
authoritative allow/deny/unavailable results, and scoped mutation/readback
semantics from the application and authorization owners. Continues jointly with
USER-WP-0028-T02; no local grant inference or substitute catalogue was added.