Skip to content

Commit e8e3b4c

Browse files
docs: check off all azure-mode acceptance criteria — specification complete
1 parent f399343 commit e8e3b4c

2 files changed

Lines changed: 28 additions & 28 deletions

File tree

‎task-azure.md‎

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -125,20 +125,20 @@ Real Entra login + Key Vault signing + internal-CA LTV is a **manual acceptance
125125

126126
# 9. Acceptance criteria (the loop drives to all-checked)
127127

128-
- [ ] `--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129-
- [ ] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130-
- [ ] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131-
- [ ] `azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132-
- [ ] `--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133-
- [ ] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134-
- [ ] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135-
- [ ] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136-
- [ ] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137-
- [ ] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138-
- [ ] `requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139-
- [ ] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
140-
- [ ] Docs (`README`/`CLAUDE`/`BUILD`) updated: new mode/flags, **AES-not-QES**, network + internal-CA trust requirements, per-user Key Vault prerequisite, eID-vs-Azure trade-off.
141-
- [ ] `python -m unittest -v` green; `HeadlessImport` and the image-mode smoke path pass.
128+
- [x] `--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129+
- [x] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130+
- [x] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131+
- [x] `azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132+
- [x] `--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133+
- [x] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134+
- [x] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135+
- [x] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136+
- [x] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137+
- [x] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138+
- [x] `requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139+
- [x] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
140+
- [x] Docs (`README`/`CLAUDE`/`BUILD`) updated: new mode/flags, **AES-not-QES**, network + internal-CA trust requirements, per-user Key Vault prerequisite, eID-vs-Azure trade-off.
141+
- [x] `python -m unittest -v` green; `HeadlessImport` and the image-mode smoke path pass.
142142

143143
---
144144

‎task.md‎

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -125,20 +125,20 @@ Real Entra login + Key Vault signing + internal-CA LTV is a **manual acceptance
125125

126126
# 9. Acceptance criteria (the loop drives to all-checked)
127127

128-
- [ ] `--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129-
- [ ] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130-
- [ ] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131-
- [ ] `azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132-
- [ ] `--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133-
- [ ] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134-
- [ ] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135-
- [ ] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136-
- [ ] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137-
- [ ] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138-
- [ ] `requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139-
- [ ] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
140-
- [ ] Docs (`README`/`CLAUDE`/`BUILD`) updated: new mode/flags, **AES-not-QES**, network + internal-CA trust requirements, per-user Key Vault prerequisite, eID-vs-Azure trade-off.
141-
- [ ] `python -m unittest -v` green; `HeadlessImport` and the image-mode smoke path pass.
128+
- [x] `--mode azure` exists alongside `beid`/`image`; both existing modes unchanged and still pass their tests.
129+
- [x] Interactive Entra ID login (`--azure-auth interactive|device-code|default`); token cached; **one login per batch**, no per-document prompt.
130+
- [x] Signed-in user's UPN/oid resolved from token claims (or Graph); Key Vault key/cert resolved via `--azure-key-name-template` (default `sig-{upn}`) or explicit override, with the per-user safety rule enforced.
131+
- [x] `azure_signer.py` signs the digest via Key Vault `CryptographyClient` (correct `SignatureAlgorithm` per key type + `--digest`), builds the CMS from the Key Vault certificate + chain; document never sent to Azure.
132+
- [x] `--pades-level` honoured in `azure` mode (timestamp ≥ b-t; internal-CA `ValidationContext` + `embed_validation_info` for b-lt/b-lta; `use_pades_lta` for b-lta).
133+
- [x] Validation/trust is **mode-dependent**: `azure` uses `--azure-trust-anchors` (internal CA); `beid` still uses the EU-LOTL `trust.py`.
134+
- [x] Visible vignette in `azure` mode shows the user's name from the certificate (or Graph), `photo=None`; placement flags work; default bottom-right last page.
135+
- [x] Post-signing self-verification runs for `azure` (internal-CA context), reports level/LTV in `DocResult.detail`, fails on mismatch; `--no-verify` skips.
136+
- [x] No silent level downgrade on network failure; failures name the endpoint/capability; `b-b`/`image` remain offline-capable.
137+
- [x] GUI third mode "Azure (Microsoft login)" with sign-in action and Azure panel; thread-safety invariants preserved.
138+
- [x] `requirements.txt` + `signApp.spec` updated; **both** binaries build; azure available in the CLI binary.
139+
- [x] Tokens/keys never logged; only the digest leaves the machine; per-user key rule enforced.
140+
- [x] Docs (`README`/`CLAUDE`/`BUILD`) updated: new mode/flags, **AES-not-QES**, network + internal-CA trust requirements, per-user Key Vault prerequisite, eID-vs-Azure trade-off.
141+
- [x] `python -m unittest -v` green; `HeadlessImport` and the image-mode smoke path pass.
142142

143143
---
144144

0 commit comments

Comments
 (0)