docs(remediation): complete the D-11b addendum with coder-mos1's status-code control
The advisory on coder-mos1 is retracted and the hold released; the token was valid all along and the 403 was a scope refusal on /user, not an authentication rejection. coder-mos1 contributed the piece neither Mos nor I had. My differential proves capability but cannot tell a BROKEN credential from a NARROW one, and that distinction is exactly what a credential advisory turns on. Its addition: a genuinely invalid token returns 401, while a scope refusal returns 403 with a required-scope body. So body-aware classification plus an invalid-token 401 control settles credential validity without needing read:user at all. A status code read as a bare number cannot distinguish "wrong key" from "right key, narrow door", and reading it as a bare number nearly cost an escalation on f10-coder and an indefinite silent hold on coder-mos1 on the same day. A held seat is externally indistinguishable from an idle one, which is what makes that false negative expensive. Also banked: capability and identity are separate conditions with different evidence and neither substitutes for the other. coder-mos1 held that line in its own release criterion after I had corrected only the capability half, and refused to widen its own token scope to make a check pass — which would have been D-45, an audited party relaxing its own audit. read:user is an enhancement for mechanical self-checking, not a repair. The classification belongs in the seat-provisioning checklist rather than only in this ledger. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 5
parent
8fe14d8e1a
commit
673fbdb978
@@ -1999,6 +1999,32 @@ governs the raw-API path, the tea login governs the tea path, and the two can di
|
||||
> perfectly working seat to the coordinator as unprovisioned — burning a provisioning round trip and
|
||||
> stalling the keystone on a phantom.
|
||||
|
||||
> **★ COMPLETION — THE STATUS-CODE CONTROL (contributed by `coder-mos1`, 2026-08-05, and it is better
|
||||
> than what either the orchestrator or the coordinator had).** The differential proves **capability**.
|
||||
> It does **not** distinguish a _broken_ credential from a _narrow_ one — and that distinction is what
|
||||
> a credential advisory actually turns on. The cheap, complete classification:
|
||||
>
|
||||
> | observation | means |
|
||||
> | --------------------------------------------------------- | ----------------------------------------------------------- |
|
||||
> | **401** | **authentication rejected — a REAL credential failure** |
|
||||
> | **403 + scope message** (`required=[read:user]`) | **token is VALID, scope is narrow — not a failure** |
|
||||
> | authenticated `push=true` / unauth `push=false` | **capability**, attributable to this token |
|
||||
> | `/user` 200 with matching login **or** authored read-back | **identity** (needs `read:user`, or coordinator sequencing) |
|
||||
>
|
||||
> **Body-aware classification plus an invalid-token 401 control settles credential validity WITHOUT
|
||||
> needing `read:user` at all.** A status code read as a bare number cannot tell "wrong key" from "right
|
||||
> key, narrow door" — and reading it as a bare number is what nearly cost an escalation on `f10-coder`
|
||||
> and an **indefinite silent hold** on `coder-mos1` the same day. **A held seat is externally
|
||||
> indistinguishable from an idle one**, which is what makes that false negative expensive.
|
||||
>
|
||||
> **Capability and identity are SEPARATE conditions with DIFFERENT evidence — do not let one stand in
|
||||
> for the other.** `coder-mos1` held that line in its own release criterion after the orchestrator
|
||||
> corrected only the capability half, and declined to widen its own token scope to make a check pass
|
||||
> (that would be D-45: an audited party relaxing its own audit).
|
||||
>
|
||||
> **Belongs in the seat-provisioning checklist, not only in this ledger.** `read:user` is an
|
||||
> **enhancement for mechanical self-checking, not a repair.**
|
||||
|
||||
### D-12 — a requested SAFETY flag was silently degraded, and I did not check
|
||||
|
||||
I created PR #1027 with `pr-create.sh ... -d` (draft) because it carries **partial, unproven work**.
|
||||
|
||||
Reference in New Issue
Block a user