Implement bounded Kanidm credential mutations #8
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Blocks
Reference
Ting/Vedanta#8
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Implement the one narrow Kanidm mutation adapter used by the private Vedanta lifecycle service.
Delivery class
agent-unit— addsrc/kanidm.rsand capture-double tests. The live narrow-manager proof remains flake-ops #123.Design
Mint requires explicit expiry and returns value, token ID, expiry, and subject once. Rotation creates a distinct successor rather than extending in place. Invalidate targets one authenticated token ID. Kanidm denial is final and never triggers broader authority.
Tasks
Specification Delta
Requirement: every credential mutation is bounded and exact
Scenario: a successor is rotated and its predecessor invalidated
OpenSpec
OpenSpec 20
Structural parent
Vedanta#20
Grooming state: Clarified
Owner ruling (2026-08-26): Vedanta owns IDM
mint_api_token,rotate_api_token, and explicitinvalidate_api_token. Jostoph has no legitimacy in the IDM plan; its scope here is Forge-only.Current placement: #8 remains the bounded Kanidm native-adapter unit under OpenSpec 20. The later ratified OpenSpec 61 also requires a Forgejo native adapter, but no current Session leaf owns it; that structural gap is carried by #20 Q1 rather than by silently broadening this record.
Clarification: rotation mints a successor; caller-selected grace leaves the old credential valid until explicitly invalidated. Invalidating unknown or already-invalid credentials succeeds externally while the audit trail retains the distinction.
Larandar: no API-token ownership decision remains on this record.
agent.odin referenced this issue2026-08-26 07:38:30 +00:00
agent.odin referenced this issue2026-08-26 07:38:31 +00:00
agent.odin referenced this issue2026-08-26 10:08:03 +00:00
wave-1 B5/D1: mint_api_token / rotate_api_token in the kanidm effectorto Kanidm effector: bounded mint, successor rotation, and token-ID invalidationKanidm effector: bounded mint, successor rotation, and token-ID invalidationto Implement bounded Kanidm credential mutationslarandar referenced this issue2026-09-02 19:23:32 +00:00
Delivered by PR #27, merged 2026-09-02, which carried
Closes #8and landedsrc/kanidm.rswith 10 capture-double tests — bounded mint with typed result metadata, successor rotation with caller-selected grace, exact token-ID invalidation with the observed-before distinction, and terminal unrelated-subject denial.The
Closeskeyword did not fire on merge for this record, nor for #23 or #24, while #12, #21 and #22 closed normally. Closing by hand against the merge rather than leaving three delivered Deliverables reading as open work.The live narrow-manager proof remains flake-ops#123, per this record's own delivery class — that was never this issue's to close.
Dependency on flake-ops#123 removed (freeholder direction, 2026-09-03), and this record closed.
The edge asserted a blocker this record's own scope disclaims. Its delivery class reads "
agent-unit— addsrc/kanidm.rsand capture-double tests. The live narrow-manager proof remains flake-ops #123" — the proof is named as a separate record, not as a precondition — and PR #27 merged carryingCloses #8. Two independent statements that the agent-unit work is complete, against one triage edge from 2026-08-13 that predates both.The proof is not cancelled, only unlinked. flake-ops#123 stays open and
Status/Blocked, behind flake-ops#98 —just bootstrap vedanta-token, an owner act with no undo that revokes every liveidm_adminsession. Until that runs,sa-vedantadoes not exist and the narrow delegation is unproven against a live directory. What closing this record says is thatsrc/kanidm.rsis written and tested, not that the authority it assumes has been demonstrated.The same edge blocked #23, #24 and #9 transitively; all four close together.