merge: land DURABLE-AGENT-AUTH-C (scoped REST agent credentials)
Merge feat/durable-agent-auth-phase-c onto current main for Trend Agent. kt_agent_ mint/list/revoke/rotate + agent_access JWT exchange; Hub UI; Netlify store; docs/OpenAPI. Resolve ROADMAP/HANDOVER conflicts keeping main board structure; mark Phase C DONE/landed. Keep SEC-KN-3/SEAM return shapes exact; classify agent_access at approve call site. Seven-tier agent-credentials 22/22; SEC scanners 75/75.
sha256:42919023ffff77574949050319e777825cb77022c4770f9ca88e5f1482f9a150
sha
sha256:64a516df951f75f2df9215a224180f4b5987ad579e29c6094560e264fd9a1564
sha256:b34738b0fc5dbbece5c98336e06e0d3025bb940fb2cc6099dc465f58d33fe32b
parent
+109
~73
−3
symbols
sha256:4040c77afa59f1985c0162122fc231c2d13aaf384cc4d77d77464d3c1f6defe0
snapshot
+109
symbols added
~73
symbols modified
−3
symbols removed
0
dead code introduced
Semantic Changes
185 symbols
+
Durable Agent Auth Phase C — frozen spec: scoped REST agent credentials
section Durable Agent Auth Phase C — frozen spec: scoped REST agent credentials L1–479
+
Test matrix (seven tiers — Aaron standard)
section 11. Test matrix (seven tiers — Aaron standard) L405–421
+
Implementation map (Auto; no redesign)
section 13. Implementation map (Auto; no redesign) L436–451
+
Definition of Done (Phase C Auto) — after this freeze passes review
section 16. Definition of Done (Phase C Auto) — after this freeze passes review L468–479
+
Ground truth — what the code does today (file+line)
section 2. Ground truth — what the code does today (file+line) L65–94
+
Incident diagnosis — why the trend-agent path dies
section 3. Incident diagnosis — why the trend-agent path dies L94–126
+
2 Why Phase A/B cannot fix this consumer
section 3.2 Why Phase A/B cannot fix this consumer L105–112
+
3 Reliability follow-on (server) — in scope for diagnosis, Tier-3 for prod flip
section 3.3 Reliability follow-on (server) — in scope for diagnosis, Tier-3 for prod flip L112–126
+
1 Opaque agent credential (long-lived secret)
section 5.1 Opaque agent credential (long-lived secret) L142–158
+
1 Mint — POST api/v1/auth/agent/credentials
section 6.1 Mint — POST api/v1/auth/agent/credentials L189–240
+
2 Exchange — POST api/v1/auth/agent/token
section 6.2 Exchange — POST api/v1/auth/agent/token L240–264
+
3 List — GET api/v1/auth/agent/credentials
section 6.3 List — GET api/v1/auth/agent/credentials L264–270
+
4 Revoke — DELETE api/v1/auth/agent/credentials/:id
section 6.4 Revoke — DELETE api/v1/auth/agent/credentials/:id L270–276
+
5 Rotate — POST api/v1/auth/agent/credentials/:id/rotate
section 6.5 Rotate — POST api/v1/auth/agent/credentials/:id/rotate L276–280
+
REST acceptance + scope enforcement (frozen)
section 7. REST acceptance + scope enforcement (frozen) L292–350
+
2 agentScopesPermitMethod(scopes, method, path)
method
section 7.2 agentScopesPermitMethod(scopes, method, path) L307–316
+
3 Propose-create path allowlist (Phase C)
section 7.3 Propose-create path allowlist (Phase C) L320–334
+
Primary consumer contract — VideoFactory-trend-agent (follow-on)
section 9. Primary consumer contract — VideoFactory-trend-agent (follow-on) L372–391
−
2 P1 WASM + T1 (PRIMARY relay → Scooling board)
section NEXT SESSION — §FCA.2 P1 WASM + T1 (PRIMARY relay → Scooling board) L20–192
−
THE ONE NEXT STEP — Model: Operator (Scooling board owns product order)
section THE ONE NEXT STEP — Model: Operator (Scooling board owns product order) L34–50
+
NEXT SESSION — Trend Agent: use Phase C REST credentials (PRIMARY for this track)
section NEXT SESSION — Trend Agent: use Phase C REST credentials (PRIMARY for this track) L20–203
+
Prior session — DURABLE-AGENT-AUTH-C land to Muse main (2026-07-28)
section Prior session — DURABLE-AGENT-AUTH-C land to Muse main (2026-07-28) L51–61
+
THE ONE NEXT STEP — Model: Operator + Auto (Trend Agent)
section THE ONE NEXT STEP — Model: Operator + Auto (Trend Agent) L35–51
~
handler
~
div#app
← Older
Oldest on feat/land-phase-c-rest-agent-creds
All commits
Newer →
Latest on feat/land-phase-c-rest-agent-creds
0 comments
To add a comment, use the Muse CLI:
muse hub commit comment sha256:42919023ffff77574949050319e777825cb77022c4770f9ca88e5f1482f9a150 --body "your comment"
No comments yet. Be the first to start the discussion.