Close recovery acceptance and reconcile blocked workplans
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Account journey acceptance / journeys (push) Successful in 10s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e38e-e5bb-7b50-968d-a738a0294997
This commit is contained in:
tegwick 2026-09-27 17:54:47 +02:00
parent b73f553c18
commit eca7c54748
9 changed files with 162 additions and 46 deletions

View file

@ -4,12 +4,12 @@ type: workplan
title: "User account journeys and recovery"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-13"
updated: "2026-09-27"
state_hub_workstream_id: "145df9d5-a7e9-5d20-8280-9d3ea069838b"
---
@ -31,13 +31,19 @@ U01–U04/U10–U13: preserve safe profile input on validation failure; confirm
```task
id: USER-WP-0028-T02
status: todo
status: wait
priority: high
state_hub_task_id: "5d1bf977-034d-5448-b4fb-5a8b630af6ba"
```
U09 and T05: integrate a supported catalogue/admission source and scoped grants/revocation. Do not present static links or membership as effective authorization. Continues USER-WP-0026-T03; establish provider contract before deployment.
2026-09-27: blocked on the provider-owned catalogue/admission and scoped
application grant/revocation contract described in USER-WP-0026-T03. Current
membership CRUD and PDP evaluation cannot supply fleet-wide admission or mutate
application-owned grants. Resume integration after owners identify the supported
source, entry-point registry, identity/action mapping and mutation contract.
## Complete optional OTP onboarding with provider evidence
```task
@ -54,3 +60,11 @@ Validation: 210 database-enabled regression tests passed with no skips,
including independent-connection last-admin protection and nested bootstrap
rollback. Thirteen isolated Chromium checks passed. Provider OTP and application
access integration remain explicitly open; no complete-journey claim is inferred.
2026-09-27: credential custody and optional-policy rollout are complete
(KEY-WP-0035, RPF-WP-0040); NK-WP-0033 is also finished. The earlier missing-
credential dependency is superseded. P04/P06 installed-provider evidence covers
enrollment/cancellation, recovery/replacement and old-session enforcement.
The remaining blocker is attended real-user U05–U08 acceptance and verified
portal setup handoff, not another service token. See USER-WP-0027-T04 and
`docs/evidence/2026-09-13-p06-authentication-policy.md`.