Skip to content

RAGE #54: trusted delegated Auto-Dig session registration - #55

Draft
lost-rob0t wants to merge 2 commits into
mainfrom
rage/54-trusted-delegated-session-registration
Draft

RAGE #54: trusted delegated Auto-Dig session registration#55
lost-rob0t wants to merge 2 commits into
mainfrom
rage/54-trusted-delegated-session-registration

Conversation

@lost-rob0t

Copy link
Copy Markdown
Owner

Tests-first owner-boundary slice for #54.

The RED contract requires a disabled-by-default trusted registration seam that can accept an already-authenticated StarIntel human principal/scopes/workspaces from an internal service adapter, register only canonical fixed Auto-Dig capabilities, and produce a short-lived WebSocket session without ever receiving a user OAuth bearer token.

Initial tests require:

  • explicit internal service authentication;
  • read-only scope narrowing;
  • no principal/session-token reflection in the response;
  • rejection of caller-supplied capability lists and wildcard workspaces;
  • duplicate session-token replay rejection;
  • expiry removal before WebSocket handshake.

No production registration endpoint or gateway enablement is included on this initial head. Expected state is RED.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant