#838 Adopt key-backed users (auth rak_ API keys) per auth deprecation notice 2/2 (SPEC 0008)

closed high architecture security Created 2026-07-31 00:50 · Updated 2026-07-31 02:29

Description

Edit
EARS SPEC: - When auth 3.0.0 strict identity becomes default, every Highway authorization subject (user email in auth_rbac) shall be key-backed (active, unexpired rak_ API key) or permission checks answer negatively. - When Highway provisions a user (add_membership path), the platform shall issue a rak_ API key for that user via the embedded create_api_key API and store/distribute it per a design to be agreed. - When Highway exposes programmatic API access, the platform shall evaluate replacing/augmenting its bespoke token mechanisms (e.g. #749 hw_k1_) with auth rak_ validation (validate -> user -> has_permission, or the 2.5.0 check_permission single round trip). - While the design is unresolved, Highway shall reply 'Need time' to auth thread thr-8efc34bed5594cb5893d with concrete questions (embedded-mode strict semantics, bulk backfill for existing users, service/machine subjects, OAuth-web users who never hold a secret). Blocked on design decisions; nothing enforced by auth until platforms confirm. Origin: auth notice 01KYTQ2YG1R92GPSV0GRKAE4AN.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...