The caller side of USER-WP-0023 is deployed, but FLEX-WP-0015-T02 is still
wait: flex-auth's TokenReview choke point exists in source while the running
digest is unchanged, so production accepts unauthenticated callers and our
Authorization header is ignored. Running the T03 probe now would record a
false pass on the negative case.
Captures both owed live exercises as concrete commands so they can be run by
whoever holds cluster credentials the moment flex-auth promotes A2, and notes
that they share one rollout.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Closes the caller side of FLEX-WP-0015. FlexAuthHTTPAdapter reads the
audience-scoped projected ServiceAccount token from a file on every decision,
so hourly rotation needs no restart, and runtime configuration now requires
USER_ENGINE_FLEX_AUTH_TOKEN_FILE.
A missing, empty, or unreadable token file fails closed as a denial without
reaching flex-auth: OSError joins the caught set and an empty read raises.
Coverage proves all three unusable-token cases deny before any request is
made, and that neither the deny reason nor the decision repr carries the
token value.
Tenant-authority reads now identify user-engine as actor `user-engine` under
the protected tenant.read action, keeping tenant ids opaque and URL-encoded.
Contract: docs/flex-auth-caller-identity.md. Full suite: 148 tests, 3
provider-gated skips.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>