You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: task-azure.md
+14-14Lines changed: 14 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -125,20 +125,20 @@ Real Entra login + Key Vault signing + internal-CA LTV is a **manual acceptance
125
125
126
126
# 9. Acceptance criteria (the loop drives to all-checked)
127
127
128
-
-[]`--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129
-
-[] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130
-
-[] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131
-
-[]`azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132
-
-[]`--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133
-
-[] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134
-
-[] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135
-
-[] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136
-
-[] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137
-
-[] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138
-
-[]`requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139
-
-[] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
-[]`python -m unittest -v` green; `HeadlessImport` and the image-mode smoke path pass.
128
+
-[x]`--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129
+
-[x] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130
+
-[x] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131
+
-[x]`azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132
+
-[x]`--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133
+
-[x] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134
+
-[x] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135
+
-[x] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136
+
-[x] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137
+
-[x] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138
+
-[x]`requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139
+
-[x] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
Copy file name to clipboardExpand all lines: task.md
+14-14Lines changed: 14 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -125,20 +125,20 @@ Real Entra login + Key Vault signing + internal-CA LTV is a **manual acceptance
125
125
126
126
# 9. Acceptance criteria (the loop drives to all-checked)
127
127
128
-
-[]`--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129
-
-[] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130
-
-[] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131
-
-[]`azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132
-
-[]`--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133
-
-[] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134
-
-[] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135
-
-[] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136
-
-[] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137
-
-[] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138
-
-[]`requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139
-
-[] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
-[]`python -m unittest -v` green; `HeadlessImport` and the image-mode smoke path pass.
128
+
-[x]`--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129
+
-[x] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130
+
-[x] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131
+
-[x]`azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132
+
-[x]`--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133
+
-[x] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134
+
-[x] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135
+
-[x] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136
+
-[x] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137
+
-[x] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138
+
-[x]`requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139
+
-[x] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
0 commit comments