Skip to content

Expose consent-gated Lumin signing workflow - #189

Merged
silverstein merged 5 commits into
masterfrom
codex/lumin-public-workflow-20260905
Sep 5, 2026
Merged

Expose consent-gated Lumin signing workflow#189
silverstein merged 5 commits into
masterfrom
codex/lumin-public-workflow-20260905

Conversation

@silverstein

@silverstein silverstein commented Sep 5, 2026

Copy link
Copy Markdown
Member

Summary

  • expose six public MCP tools for Lumin authorization, request preparation, one-shot request creation, status polling, and artifact download
  • require a fresh exact confirmation before a PDF or signer details leave the device
  • keep OAuth access tokens and signed artifact URLs out of tool results, logs, and durable state
  • preserve zero automatic create retry, no-overwrite downloads, source/share parity, schemas, manifests, annotations, and user-facing documentation

Safety boundaries

  • no live provider call or real signature was performed by this change
  • confirmation proves the exact statement and timestamp supplied through the host, not independent human identity
  • public PKCE clients use polling; app webhooks remain a future server-only path
  • this PR does not publish a release

Verification

  • exact final head: afd5474
  • focused and adjoining Mac suites: 314/314 passing
  • release-gate regressions: 106/106 passing
  • full serial Mac Vitest: 181 files and 2,951 tests passed, with 107 intentional skips
  • Mac native partition: 62 passed, with 9 intentional skips
  • two deterministic MCPB production builds matched at SHA-256 48f7c1c17d0972766c98facdca3a661fbd1506c7c5dc9499a4bef44dbe5bfc00
  • exact packaged MCPB smoke passed on macOS with 57 tools and 14 prompts
  • GitHub Actions passed the complete gate on Node 20.19 and Node 22.12
  • independent exact-head review returned GO with no P0, P1, or P2 findings

Tracks pdf-toolkit-mcp-ik9e. Follow-up pdf-toolkit-mcp-tnpc tracks bounded status-observation retention.

@silverstein
silverstein merged commit c80d7bb into master Sep 5, 2026
2 checks passed
@silverstein
silverstein deleted the codex/lumin-public-workflow-20260905 branch September 5, 2026 03:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant