Repository navigation
Align security routing specs with fail-closed identity verification - #175
Conversation
|
Tracked by #174. Root cause: #169 introduced ServiceRoutingHarness without an identity-resolution opt-out after #164 made IdentityVerification default to Required. RecordingBackend answers /.cratis/me with {}, not an explicit positive verification verdict, so authenticated routing requests receive 403 before reaching the routing behavior under test. The routing-only services now set ResolveIdentityDetails=false; product defaults, Required-verification specs, claim requirements and all assertions are unchanged. The baseline at e5e0f84 reproduced 18 failures and 269 passes. No management-listener failure occurred in the baseline or fixed runs; its fixture already selects an OS-assigned port using TcpListener on port zero, so it was left unchanged. Local checks passed through pi-phase with --timeout 300 --queue-timeout 600:
Frontend and .NET dependency audits were not run locally; GitHub's Security workflow will run them. Docker publishing is not applicable to this no-release PR. The full review workflow remains for the orchestrator before any merge. Do not merge as part of this task. |
Summary
The service-routing security specs opt their routing-only services out of identity resolution, so routing and service-authorization assertions run independently of the fail-closed identity-verification default. (#176)