user-engine/docs/evidence/2026-09-27-loose-ends-review.md
tegwick eca7c54748
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Account journey acceptance / journeys (push) Successful in 10s
Close recovery acceptance and reconcile blocked workplans
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e38e-e5bb-7b50-968d-a738a0294997
2026-09-27 17:54:47 +02:00

42 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Loose-end review — 2026-09-27
Reviewed all 37 workplan files: 32 finished and five active. No ready,
proposed, backlog or already-blocked workplans were present. The five open
workplans are now blocked; no task or workplan was created.
## Completed existing task
USER-WP-0026-T02 is done. The immutable release and anonymous browser evidence
in `railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md` is now
supplemented by `key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`.
The founder confirmed fresh login/account switching; issuer telemetry records
three fresh portal authentication/token-issuance sequences following an MFA
failure. KEY-WP-0034-T02 is also done. U10 now reflects this evidence.
Application JWTs may outlive provider logout. The receipt does not complete the
second-user/company-workflow pilot in VERGABE-WP-0019-T06.
## Remaining blockers
| Workplan / tasks | Current dependency and resumption condition |
| --- | --- |
| USER-WP-0026-T03, USER-WP-0028-T02 | Application/authorization owners must establish the supported workload catalogue, registered HTTPS entry points, identity/tenant/action mapping, authoritative decisions and scoped grant/revocation contract. Local application records, memberships and the PDP evaluator do not supply fleet admission. |
| USER-WP-0027-T04, USER-WP-0028-T03 | Attended real-user OTP enrollment, cancellation, replacement/lost-factor recovery and fresh-login acceptance; verified portal setup handoff. KEY-WP-0035 and RPF-WP-0040 already delivered credential custody, renewal and optional policy. P04/P06 prove the implementation using disposable installed-provider fixtures. NK-WP-0033's separate incident also closed on September 23. |
| USER-WP-0027-T06 | Full matrix depends on the preceding application/OTP work, setup-link delivery and VERGABE-WP-0019-T06 second-user/setup-to-workflow acceptance. |
| USER-WP-0034-T02 | FLEX-WP-0020 section 8 still waits for the renamed canonical checkout. `/home/worsch/access-engine` is absent; `/home/worsch/flex-auth/docs/iam-profile-consumption.md` exists. Keep the current source link until registration. |
| USER-WP-0035-T02 | The provider-owned password-setup link still needs a supported delivery handoff and intended-person receipt evidence. EMAIL-WP-0004 and P05 delivered the mail service; its invitation outbox adapter is not a setup-link delivery contract. |
The review corrects stale missing-credential and missing-mail-infrastructure
claims rather than requesting replacement secrets or rebuilding working provider
features. Existing tasks retain all remaining work. No production configuration
or real account was changed, and no email was sent.
## Validation
- `make test`: 264 tests run, eight optional integration skips, no failures;
layer conformance passed.
- `make test-journeys`: 66 tests passed, no skips. The report remains incomplete
for U02–U09, T02, T04 and T05; account switching U10 is no longer a blocker.
- `git diff --check`: passed.
Local tests validate the implementation and journey mappings. They do not
substitute for the external acceptance evidence listed above.