#838 Adopt key-backed users (auth rak_ API keys) per auth deprecation notice 2/2 (SPEC 0008)
Description
EditEARS SPEC:
- When auth 3.0.0 strict identity becomes default, every Highway authorization subject (user email in auth_rbac) shall be key-backed (active, unexpired rak_ API key) or permission checks answer negatively.
- When Highway provisions a user (add_membership path), the platform shall issue a rak_ API key for that user via the embedded create_api_key API and store/distribute it per a design to be agreed.
- When Highway exposes programmatic API access, the platform shall evaluate replacing/augmenting its bespoke token mechanisms (e.g. #749 hw_k1_) with auth rak_ validation (validate -> user -> has_permission, or the 2.5.0 check_permission single round trip).
- While the design is unresolved, Highway shall reply 'Need time' to auth thread thr-8efc34bed5594cb5893d with concrete questions (embedded-mode strict semantics, bulk backfill for existing users, service/machine subjects, OAuth-web users who never hold a secret).
Blocked on design decisions; nothing enforced by auth until platforms confirm. Origin: auth notice 01KYTQ2YG1R92GPSV0GRKAE4AN.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...