Skip to content

feat(lab): integrate native eSignet BREG token-client candidate - #42

Draft
jeremi wants to merge 6 commits into
mainfrom
feat/contextual-authorization
Draft

jeremi wants to merge 6 commits into
mainfrom
feat/contextual-authorization

Conversation

@jeremi

@jeremi jeremi commented Sep 12, 2026

Copy link
Copy Markdown
Member

Update the optional identity profile to the native eSignet 2.0 BREG provider candidate and issuer-neutral token-client configuration. The ordinary portal relying-party flow validates signed identity responses, keeps the provider's existing consented individual_id claim contract, and maps that opaque value to the governed BREG person reference. Provider candidate images must be built explicitly; no unpublished release digest is invented.

Add owned local fixture tooling and protocol tests, update local and hosted configuration, and preserve the existing published Stack runtime pins. This draft does not integrate the deferred ThunderID citizen federation fork or claim that the legacy published runtime is Mint-free.

Validation: just lint, just test, and config-only just compose pass. Test gate includes 317 Python tests, three protocol helper tests, 163 portal tests and 62 home tests. Focused BREG/seed/topology tests also pass. Compose validation starts no services; no complete live lab smoke or deployment is claimed. The new provider contract remains paired with the companion authenticator draft PR.

Rebased on freshly fetched origin/main before pushing. No merge, publication, deployment or tag is included.

Work-package checkpoint. Existing citizen-related work is preserved but phase 4 is deferred pending a separate decision; institutional delivery must use stock ThunderID.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Work-package checkpoint. Existing citizen-related work is preserved but phase 4 is deferred pending a separate decision; institutional delivery must use stock ThunderID.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi marked this pull request as ready for review September 12, 2026 18:22
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 12, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-12T18:26:01.356660Z 39e711b Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 39e711b229

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread justfile
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant