docs(auth): clear Phase C freeze for scoped REST agent credentials
Thinking freeze for DURABLE-AGENT-AUTH-C (kt_agent_ + agent_access JWT, Netlify mint/list/revoke/rotate/exchange, propose-scope REST). Freeze-review pass; boards point NEXT at C-b Auto. Trend-agent wiring remains follow-on.
sha256:e81978a957c8e61ce6916b2848fbe96b4f6428d358c57314e51768feb1af146b
sha
+62
~4
−5
symbols
sha256:145fe53cd11fb00376cd2e265533516faa8741e560b77a3b6f740eab66fe58da
snapshot
+62
symbols added
~4
symbols modified
−5
symbols removed
0
dead code introduced
Semantic Changes
71 symbols
+
Durable Agent Auth Phase C — frozen spec: scoped REST agent credentials
section Durable Agent Auth Phase C — frozen spec: scoped REST agent credentials L1–479
+
Test matrix (seven tiers — Aaron standard)
section 11. Test matrix (seven tiers — Aaron standard) L405–421
+
Implementation map (Auto; no redesign)
section 13. Implementation map (Auto; no redesign) L436–451
+
Definition of Done (Phase C Auto) — after this freeze passes review
section 16. Definition of Done (Phase C Auto) — after this freeze passes review L468–479
+
Ground truth — what the code does today (file+line)
section 2. Ground truth — what the code does today (file+line) L65–94
+
Incident diagnosis — why the trend-agent path dies
section 3. Incident diagnosis — why the trend-agent path dies L94–126
+
2 Why Phase A/B cannot fix this consumer
section 3.2 Why Phase A/B cannot fix this consumer L105–112
+
3 Reliability follow-on (server) — in scope for diagnosis, Tier-3 for prod flip
section 3.3 Reliability follow-on (server) — in scope for diagnosis, Tier-3 for prod flip L112–126
+
1 Opaque agent credential (long-lived secret)
section 5.1 Opaque agent credential (long-lived secret) L142–158
+
1 Mint — POST api/v1/auth/agent/credentials
section 6.1 Mint — POST api/v1/auth/agent/credentials L189–240
+
2 Exchange — POST api/v1/auth/agent/token
section 6.2 Exchange — POST api/v1/auth/agent/token L240–264
+
3 List — GET api/v1/auth/agent/credentials
section 6.3 List — GET api/v1/auth/agent/credentials L264–270
+
4 Revoke — DELETE api/v1/auth/agent/credentials/:id
section 6.4 Revoke — DELETE api/v1/auth/agent/credentials/:id L270–276
+
5 Rotate — POST api/v1/auth/agent/credentials/:id/rotate
section 6.5 Rotate — POST api/v1/auth/agent/credentials/:id/rotate L276–280
+
REST acceptance + scope enforcement (frozen)
section 7. REST acceptance + scope enforcement (frozen) L292–350
+
2 agentScopesPermitMethod(scopes, method, path)
method
section 7.2 agentScopesPermitMethod(scopes, method, path) L307–316
+
3 Propose-create path allowlist (Phase C)
section 7.3 Propose-create path allowlist (Phase C) L320–334
+
Primary consumer contract — VideoFactory-trend-agent (follow-on)
section 9. Primary consumer contract — VideoFactory-trend-agent (follow-on) L372–391
−
NEXT SESSION — build-verification FINISH-COMPLETE-APPLY-KN-b (PRIMARY)
section NEXT SESSION — build-verification FINISH-COMPLETE-APPLY-KN-b (PRIMARY) L21–63
−
Paste-ready prompt — FINISH-COMPLETE-APPLY-KN-b
section Paste-ready prompt — FINISH-COMPLETE-APPLY-KN-b L43–63
+
NEXT SESSION — DURABLE-AGENT-AUTH-C-b Auto (PRIMARY)
section NEXT SESSION — DURABLE-AGENT-AUTH-C-b Auto (PRIMARY) L21–70
+
Parallel / parked — FINISH-COMPLETE-APPLY-KN-b BV
section Parallel / parked — FINISH-COMPLETE-APPLY-KN-b BV L63–70
+
Paste-ready prompt — DURABLE-AGENT-AUTH-C-b
section Paste-ready prompt — DURABLE-AGENT-AUTH-C-b L44–63
← Older
Oldest on feat/durable-agent-auth-phase-c
All commits
Newer
feat(auth): Phase C scoped REST agent credentials (kt_agent_)
sha256:4e0e0dd680824306e9be1023b06d40bb907b459ef1779d3991ed4c83610a253e
0 comments
To add a comment, use the Muse CLI:
muse hub commit comment sha256:e81978a957c8e61ce6916b2848fbe96b4f6428d358c57314e51768feb1af146b --body "your comment"
No comments yet. Be the first to start the discussion.