Follow-up to #1029.
ThunderID sets registry_grant_source_issuer from the verified iss of the exchanged assertion, through the connection mapping rendered in crates/registry-thunderid-tooling/src/render.rs, and overwrites a value the signer supplies. The value Casework signs into the task assertion (crates/registry-casework/src/task_grants.rs) is therefore never used, and suggests the signer controls it.
Follow-up to #1029.
ThunderID sets
registry_grant_source_issuerfrom the verifiedissof the exchanged assertion, through the connection mapping rendered incrates/registry-thunderid-tooling/src/render.rs, and overwrites a value the signer supplies. The value Casework signs into the task assertion (crates/registry-casework/src/task_grants.rs) is therefore never used, and suggests the signer controls it.registry_grant_source_issuerfrom the task assertion payload and update its testsourceIssuerin the status response, which BREG compares with the retained task binding