Implement bounded Forgejo credential mutations #29
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Ting/Vedanta#29
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Implement the narrow Forgejo mutation adapter that ratified OpenSpec 61 v0.1.4 requires: Vedanta causes Forgejo to mint and exactly delete one bounded queen-account token per lease.
Delivery class
agent-unit— addsrc/forgejo.rsand capture-double tests. A live least-scope proof against a deployed Forgejo remains a separate operator-gated record.Design
Kanidm and Forgejo are independent issuers: distinct APIs, distinct permission models, distinct failure modes, distinct acceptance doubles. #8 owns the Kanidm half; this leaf owns the Forgejo half, and the Session still returns one interface-compatibility verdict over both.
Mint requires explicit expiry and returns value, token ID, expiry, and subject once. Deletion targets one exact token ID; it succeeds externally for an unknown or already-deleted token while the audit trail retains the observed-before distinction. Forgejo denial is final and never triggers broader authority or an authority-widening retry.
Tasks
Specification Delta
Requirement: one lease mints and deletes exactly one bounded Forgejo token
Scenario: a lease is issued and later revoked
Scenario: the adapter is asked to exceed its scope
Owner ruling (2026-09-03)
#20 Q1 ratified: the Forgejo native adapter becomes a separate Session #20 leaf rather than a broadening of #8. The structural gap named in #8's grooming record and carried by #20 Q1 is closed by this record.
OpenSpec
OpenSpec 20
Structural parent
Vedanta#20