Repository navigation
feat(identity): compose request-context authority on credential resolution (stacked on #46) - #79
Merged
Conversation
…ution Recovered from the parked Codex claim codex-eg-identity-producer-01a10219 (isolated GR1080 checkout, base afcf5638). PrincipalResolution and IdentityReply gain a request-context parameter; the public Identity result carries RequestContextClaims composed at the live store boundary. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Knucklessg1
changed the base branch from
feat/land-identity-operations
to
main
October 8, 2026 18:23
…ter main merge Ports the IsolationLayer::with_policy_store adapter seam from Codex 6a235113e that the resolution-context tests use. Regenerates contract artifacts with gen_contract for the changed Identity result type. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Extract locked_fixture_snapshot() so arbitrary_broker_lookup_refuses_ before_store_change and unauthorized_broker_cannot_use_subject_credential share the bootstrapped-state + pre-mutation snapshot setup instead of repeating it verbatim. Fixes the jscpd new-duplicate-pair gate (fragment feba492f03a1) on PR #79; merged origin/main first (already resolved the check-public-specs homelab-token failure in specs/engine-identity-and-scope/test-spec.md). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Knucklessg1
marked this pull request as ready for review
October 8, 2026 19:16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #46 (
feat/land-identity-operations). Draft until #46 lands; then retarget tomain.Recovers the parked Codex identity-producer work (claim
codex-eg-identity-producer-01a10219). The work was uncommitted in an isolated checkout on a stale #46 base. It cherry-picks cleanly onto the current #46 head.Change
PrincipalResolution<C = ()>andIdentityReply<C = ()>gain a request-context parameter.Identityresult now carriesIdentityReply<RequestContextClaims>.dispatch/identity_store/resolution_context.rscomposes request-context claims at the live store boundary, under the write lock. A bareUser::Resolvelookup cannot issue a context.Known follow-ups
Identityresult type change moves the contract schema. Regenerate the contract artifacts with the generator after feat(identity): serve the identity operation family #46 lands. Do not hand-edit them.🤖 Generated with Claude Code