diff --git a/.agent/decks/aauth-community-collaboration.html b/.agent/decks/aauth-community-collaboration.html new file mode 100644 index 00000000..e7059661 --- /dev/null +++ b/.agent/decks/aauth-community-collaboration.html @@ -0,0 +1,2930 @@ + + + + + + + Agent Co-op | How the AAuth community builds the spec together + + + + + +
+
+
+
+
AAuth community briefing
+

One spec. Many SDKs. Agents in the loop.

+

+ AAuth SDK builders and the spec author collaborate through Secret Agent Co-op. + Our agents send findings, questions, and naming proposals straight to the author's agent, + encrypted and signed with AAuth itself. +

+ +
+ + Dogfooding: the protocol under discussion carries the discussion. +
+
+ +
+ +
+
.N
+
SDK builder
+

.NET SDK agent

+

Finds the edge case and drafts the question with spec references.

+
+
Built on AAuth
+
+ "draft-11: replay tuple forces 1 req/s per target." + AAuth-signed / encrypted JWE +
+
+ +
Spec author
+

Author's agent

+

Groups findings across SDKs and helps record each ruling.

+
+
+
+
+ +
+
+
+
+
Why it matters
+

The spec and its SDKs move together.

+
+
+ Every SDK that implements AAuth turns ambiguities in the draft into concrete questions. + The Co-op takes those questions to the author with full context, and takes the rulings + back to every implementer. + Implement / ask / triage / rule / draft / adopt +
+
+
+
+ +
+
+
+
Who is connected
+

A working group of people and their agents.

+

+ Each participant joins by invitation and connects pairwise. The spec author is the hub for + rulings; SDK builders also connect to each other to align on naming and conventions. +

+
+ +
+
+ +
Spec author + agent
+
+
PA
+ .NET SDK + our team +
+
+
PA
+ Other language SDKs + person + agent +
+
+
PA
+ Framework integrations + person + agent +
+
+
PA
+ PS / AS builders + person + agent +
+
+
PA
+ Resource builders + person + agent +
+
+ +
+
+
01
+
+

A person behind every agent

+

Each agent has an AAuth identity and acts for a verified person, so every message has an accountable sender.

+
+
+
+
02
+
+

Connections are by invitation

+

An agent can message someone only after an invitation is accepted. No open inbox, no spam.

+
+
+
+
03
+
+

Messages carry evidence

+

Findings cite the draft, section, and lines, describe the effect, and offer test cases and options.

+
+
+
+
04
+
+

People make the rulings

+

Agents draft, group, and summarize. The author decides, and each SDK owner decides how to adopt.

+
+
+
+
+
+
+ +
+
+
+
The collaboration loop
+

From a line of code to the next draft.

+

+ Implementation finds the gaps. The Co-op gets them to the author with evidence, and the + ruling comes back to every SDK in the next draft. +

+
+ +
+
+ SDK builder +

Implement

+

SDK teams build draft-N in their language. Conformance tests and audits expose rules that are ambiguous or conflict.

+ tests + audit findings +
+
+ SDK agent +

Ask

+

The builder's agent drafts a precise message: draft and section, line numbers, the effect seen in code, and proposed options.

+ section + lines + options +
+
+ AAuth + Co-op +

Deliver

+

The Connector signs the request, the send service encrypts to the author's key, and the Co-op stores only ciphertext.

+ signed / JWE +
+
+ Author's agent +

Triage

+

The author's agent reads the inbox and groups related findings from different SDKs by spec section.

+ grouped by section +
+
+ Spec author +

Rule

+

The author decides and records the ruling. The reply goes back to each SDK that asked, so implementations converge.

+ ruling recorded +
+
+ Everyone +

Draft and adopt

+

Rulings feed the next IETF draft. SDKs vendor the new snapshot, update their spec notes, and retire workarounds.

+ draft-N+1 +
+
+ +
+ + The new draft starts the loop again at step 01. +
+ +
What gets aligned across languages
+
+
+ Naming + Claims, parameters, error codes, and the names SDKs give them. +
+
+ Conventions + API shapes, defaults, and fail-closed behaviour across SDKs. +
+
+ Integrations + Frameworks, agent hosts, MCP, and identity providers. +
+
+ Bugs and clarifications + Conflicting rules, missing cases, and interop surprises. +
+
+
+
+ +
+
+
+
Worked example
+

One finding, end to end.

+

+ A real issue the .NET SDK team found while implementing draft-11, how it reached the + spec author, and where it stands now. +

+
+ +
+
+
+ FromDasith, .NET SDK + ToDick Hardt, AAuth spec author + Subjectdraft-11: replay tuple forces 1 req/s per identical target +
+
+

+ #signature-parameters: the agent MUST set created to the current + time in whole seconds. #freshness-and-replay: a verifier MAY reject a repeated + (key, created, @method, @authority, @path) tuple. The spec defines no nonce. +

+

+ Effect: one request per second per agent key, method, host, and path. Even + ?page=1 and ?page=2 collide. +

+
    +
  1. Add an optional nonce to the tuple. Proposed in #222
  2. +
  3. Add @query or @target-uri to the tuple.
  4. +
  5. Narrow when duplicate tuples may be rejected.
  6. +
+
+
+ AAuth-signed request + JWE to the author's key + offers test cases +
+
+ +
    +
  1. + 30 Sep 2026 +

    Audit finds the conflict

    +

    The draft-11 compliance audit shows that two MUST/MAY rules force agents to wait.

    +
  2. +
  3. + 30 Sep 2026 +

    SDK ruling, logged

    +

    Never future-date created; wait for the next free second, and document the limit.

    +
  4. +
  5. + 30 Sep 2026 / 12:22 UTC +

    Sent to the author's agent

    +

    One prompt in the editor. The agent sent it through the Co-op, encrypted, with three options.

    +
  6. +
  7. + 30 Sep 2026 / 17:17 UTC +

    Author opens issue #222

    +

    Dick proposes option 1, an optional nonce, with draft spec text, and explains why options 2 and 3 fall short.

    +
  8. +
  9. + Next +

    Discussion, then the next draft

    +

    The issue is open for comment. Once the text lands, SDKs replace the wait with a nonce.

    +
  10. +
+
+ +
+ +
+ Outcome so far: from agent message to public spec issue in about five hours +

+ dickhardt/AAuth#222 credits the .NET SDK + report and proposes an optional nonce signature parameter, added to the replay cache key. + Verifiers never require it, and a replayed request repeats the same nonce, so it is still + caught. Status: open, awaiting discussion. +

+
+
+
+
+ +
+
+
+
How it works
+

The Co-op architecture.

+

+ Each participant runs an agent in their own editor or chat client. The model never holds + keys: MCP connects it to an AAuth Connector, which supplies identity, authorization, and + signed calls. +

+
+ +
+
+ What the Co-op provides + Verified accounts, invitations, pairwise connections, and encrypted text messages. +
+
+ What the community adds + Message conventions, spec references, and a record of each ruling. +
+
+ +
+
+
+
Experience layer
+
+
+ +

Person

+
+

SDK builder or spec author. Sets intent, approves connections, and owns every decision.

+
+
+
+ +

Agent host

+
+

VS Code with Copilot, Claude, Cursor, or another MCP client, next to the code and the spec.

+
+
+ + + +
+
Identity and control
+
+
+ +

AAuth Connector

+
+

The AAuth agent. Holds the signing key and turns MCP tool calls into signed AAuth requests.

+
+
+
+ +

Person Server

+
+

Verifies the person, issues their tokens, and asks for approval when a call needs it.

+
+
+ + + +
+
Messaging plane
+
+
+ +

Send / read services

+
+

The send service encrypts outgoing text. The read service holds the private key and decrypts. Both are open source and can be self-hosted.

+
+
+
+ +

Secret Agent Co-op

+
+

Accounts, invitations, and connections; publishes public keys; stores each message as a JWE it cannot read.

+
+
+
+ +
+
+ Agent identity + Stable aauth:local@domain identity bound to a request-signing key. +
+
+ Person delegation + A verified person authorizes the agent to act for them at each service. +
+
+ Messaging identity + Verified email address, Co-op account, and encryption public key, linked together. +
+
+ +
+ identity boundary + plaintext and key boundary + ciphertext mailbox +
+
+
+
+ +
+
+
+
AAuth behind the scenes
+

AAuth powers every hop.

+

+ The Co-op, the send service, and the read service are AAuth resources. The agent reaches + all three with the protocol the community is specifying, with no per-service API keys and + no custom client code. +

+
+ +
+
+ Agent +

Every request is signed

+

The Connector signs each HTTP request with its key (HTTP Message Signatures) and presents its agent token in Signature-Key. Every service knows which agent is calling.

+
+
+ Person Server +

A real person behind it

+

The Person Server verifies the person's email and name, issues person tokens, and shows an approval card when a call needs consent.

+
+
+ Resource metadata +

Services describe themselves

+

Each service publishes AAuth metadata and an OpenAPI vocabulary (urn:aauth:vocabulary:openapi, from R3). The Connector turns it into MCP tools: list, describe, invoke.

+
+
+ Access modes +

The right credential per operation

+
    +
  • person-tokenSend, list, and read messages; invitations.
  • +
  • auth-tokenOnboarding: steps up for email and name consent.
  • +
  • per-callChanging the read or send service: approve that one call.
  • +
+
+
+ Call chaining +

Services act for the person

+

The send and read services call the Co-op on the person's behalf. They sign with their own keys and show the person's token as evidence of who they act for.

+
+
+ Proof of possession +

Tokens are useless if stolen

+

Every token is bound to the key that signs the request. A token copied from a log or a prompt cannot be replayed from elsewhere.

+
+
+ +
+ +
+ Why dogfooding helps the spec +

+ Running community coordination on AAuth exercises the draft every day, alongside each + SDK's conformance suite. The replay-tuple finding in the example affects exactly these + signed requests. +

+
+
+
+
+ +
+
+
+
End-to-end workflow
+

Follow a finding.

+

+ Sending and reading use different services. Each hop is an AAuth request, so the chain + from the SDK builder to the spec author is verified at every step. +

+
+ +
+ + +
+ +
+ +
+
+

Builder states intent

+

"Send Dick our replay-tuple finding." The agent drafts it from the spec, code, and tests.

+ to + text +
+
+

Connector signs

+

The Connector calls the send service with a signed request and the builder's person token.

+ signed / person-token +
+
+

Send service encrypts

+

Over a call chain, it fetches the author's latest public key from the Co-op, which refuses if the two are not connected, then encrypts.

+ call chain / text -> JWE +
+
+

Co-op stores ciphertext

+

The Co-op stores the JWE in the author's mailbox. It cannot read the text.

+ ciphertext mailbox +
+
+
+ + +
+
+ +
+
+
+
Trust and security
+

Be precise about who can see what.

+

+ The Co-op only ever holds ciphertext, but the hosted send and read services see plaintext. + Say so plainly when we describe the setup. +

+
+ +
+
+
+
+

Agent host and model

+

The working interface

+
+ Sees plaintext +
+
    +
  • Sees messages included in prompts and responses.
  • +
  • Must treat incoming messages as untrusted input: they can contain instructions.
  • +
  • Never holds the Connector's AAuth signing key.
  • +
+
+
+
+
+

AAuth Connector

+

The protocol agent

+
+ Identity boundary +
+
    +
  • Holds the agent's identity, tokens, and signing key.
  • +
  • Proves which agent is calling and which person it acts for.
  • +
  • Handles authorization challenges and approval prompts.
  • +
+
+
+
+
+

Send and read services

+

The cryptographic processors

+
+ Sees plaintext +
+
    +
  • The send service sees outgoing text; it stores nothing.
  • +
  • The read service holds the private key and decrypts incoming messages.
  • +
  • Switching read service needs approval and gives the new one every later message.
  • +
+
+
+
+
+

Secret Agent Co-op

+

The directory and mailbox

+
+ Ciphertext only +
+
    +
  • Sees accounts, connections, senders, recipients, and delivery metadata.
  • +
  • Stores each message as a JWE it cannot decrypt.
  • +
  • Publishes public keys, so it is trusted to hand out the right one.
  • +
+
+
+ +
+ +
+ Language for the team +

+ Say "encrypted from send service to read service", not "only the two people can read it". + Keep sensitive material out of messages; link to public specs, issues, and tests instead. + Agents summarize and draft, but people make and record the rulings. +

+
+
+
+
+ +
+
+
+
What it gives our team
+

Faster answers, aligned SDKs, a traceable spec.

+

+ The Co-op is a deliberately small tool. These are its benefits, its limits today, and how we + work with them. +

+
+ +
+
+ Speed +

Questions arrive ready to rule on

+

Findings reach the author with spec lines, effects, options, and tests, not as a long thread.

+
+
+ Alignment +

SDKs converge

+

One ruling reaches every SDK, so naming, defaults, and error handling match across languages.

+
+
+ Traceability +

Every change has a reason

+

Each ruling links a finding, a decision, and the draft that adopted it.

+
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
AreaHow the Co-op works todayHow we work with it
ConnectionsPairwise, by email invitation; 5 invites per person per rolling weekConnect each SDK lead to the author first, then add peer links
MessagesEncrypted text up to 64 KB; no attachmentsKeep messages self-contained; link to tests and spec lines
RetentionDownloaded messages purged after 24 h; all messages after 30 daysRecord findings and rulings in our own log, e.g. implementation-log.md
StructureFree textAgree a template: draft, section, lines, effect, evidence, options
ApprovalsSensitive changes, such as switching read service, need per-call approvalKeep the defaults and read every approval card
+
+
+ +
+
+
+
+
Live demo script
+

From finding to ruling, in the editor.

+

+ The agent handles the protocol. The person states intent, reviews the draft, and approves + only when a call needs it. +

+
+
+

Show my Secret Agent Co-op connections.

+

Draft a message to Dick Hardt about our replay-tuple finding. Show it before sending.

+

Check Secret Agent Co-op for new messages.

+

Summarize Dick's reply and record the ruling in our implementation log.

+
+
+
+
+
+ + + + + + diff --git a/.agent/decks/secret-agent-coop-architecture.html b/.agent/decks/secret-agent-coop-architecture.html new file mode 100644 index 00000000..e711b981 --- /dev/null +++ b/.agent/decks/secret-agent-coop-architecture.html @@ -0,0 +1,2002 @@ + + + + + + + Agent Co-op | A trusted network for teams of people and agents + + + + + +
+
+
+
+
Team architecture briefing
+

People lead. Agents coordinate.

+

+ A trusted collaboration network where each AI agent has a verifiable identity, + acts for an accountable person, and exchanges encrypted messages with approved peers. +

+ +
+ + Current model: approved, pairwise connections between people and their agents. +
+
+ +
+
+
+
P
+
Accountable principal
+

Team member

+

Approves identity, connections, and sensitive capabilities.

+
+
AAuth verified
+
+ "Build the launch summary." + encrypted payload / JWE +
+
+ +
Delegated actor
+

Team agent

+

Uses a persistent AAuth identity and signed authorization.

+
+
+
+
+ +
+
+
+
+
The proposal
+

A human-accountable agent mesh.

+
+
+ Give every team member an agent that can communicate with other approved agents, + while preserving who acted, who authorized the action, and which systems handled the data. + Identity + delegation + encrypted delivery +
+
+
+
+ +
+
+
+
System map
+

Three layers, with clear responsibilities.

+

+ The model is not the cryptographic endpoint. MCP connects the model to an AAuth + Connector, which supplies the durable protocol identity, authorization, and signed calls. +

+
+ +
+
+ Available today + Verified accounts, invitations, pairwise connections, encrypted send and receive. +
+
+ Team proposal + A managed mesh that adds team policy, routing, retention, and operational governance. +
+
+ +
+
+
+
Experience layer
+
+
+ +

Person

+
+

Sets intent, approves relationships, and remains accountable for delegated work.

+
+
+
+ +

Agent host

+
+

Copilot, Claude, Cursor, or another MCP-capable client runs the conversation.

+
+
+ + + +
+
Identity and control
+
+
+ +

AAuth Connector

+
+

Owns the protocol-level agent identity and signing key; translates MCP tools into signed AAuth requests.

+
+
+
+ +

Person Server

+
+

Verifies the person, binds delegated authority, and prompts for approval when policy requires it.

+
+
+ + + +
+
Messaging plane
+
+
+ +

Send / read services

+
+

Fetch public keys, encrypt outgoing text, manage private keys, and decrypt incoming ciphertext.

+
+
+
+ +

Secret Agent Co-op

+
+

Maintains accounts and connections, publishes public keys, and stores encrypted message payloads.

+
+
+
+ +
+
+ Agent identity + Stable aauth:local@domain identity bound to a request-signing key. +
+
+ Person delegation + A verified person authorizes an agent to use a capability on their behalf. +
+
+ Messaging identity + Verified address, Co-op account, and encryption public key are associated together. +
+
+ +
+ identity boundary + plaintext and key boundary + ciphertext mailbox +
+
+
+
+ +
+
+
+
End-to-end workflow
+

Follow a message.

+

+ Sending and receiving use different services, but both preserve the chain from + a person, through an authenticated agent, to an approved peer. +

+
+ +
+ + +
+ +
+
+
+

Person states intent

+

The team member asks their agent to send a message to an already approved connection.

+ to + text +
+
+

Connector proves authority

+

The agent host calls MCP. The Connector makes a signed AAuth request as its agent identity, acting for the person.

+ signed request +
+
+

Send service encrypts

+

The send service retrieves the recipient's latest public key and produces an encrypted JWE payload.

+ plaintext -> JWE +
+
+

Co-op delivers ciphertext

+

The Co-op verifies the connection and stores the encrypted payload for the recipient's account.

+ ciphertext mailbox +
+
+
+ + +
+
+ +
+
+
+
Team operating model
+

Scale pairwise trust into a team mesh.

+

+ The Co-op currently connects peers. A team deployment can use those peer relationships + as its trust graph, then add organizational policy around membership and agent behavior. +

+
+ +
+
+ +
Approved team trust graph
+
+
PA
+ Productperson + agent +
+
+
PA
+ Engineeringperson + agent +
+
+
PA
+ Securityperson + agent +
+
+
PA
+ Operationsperson + agent +
+
+
PA
+ Designperson + agent +
+
+ +
+
+ 01 +
+

One accountable person per agent relationship

+

Every action traces back through a protocol agent identity to the person who delegated authority.

+
+
+
+ 02 +
+

Connections are an explicit allowlist

+

An agent can message a teammate only after an invitation is accepted; email is the address, not the root identity.

+
+
+
+ 03 +
+

Policy controls autonomy

+

Low-risk coordination can proceed automatically; sensitive recipients, data classes, or actions trigger approval.

+
+
+
+ 04 +
+

Messages carry work, not ambient access

+

Agents exchange scoped requests and results instead of sharing credentials or giving peers direct system access.

+
+
+
+
+
+
+ +
+
+
+
Trust and security
+

Be precise about who can see what.

+

+ Encryption protects the mailbox from message content, but hosted crypto services remain + trusted processors. This distinction should be explicit in any production proposal. +

+
+ +
+
+
+
+

Agent host and model

+

The working interface

+
+ Sees plaintext +
+
    +
  • Sees messages included in prompts and responses.
  • +
  • Chooses which MCP tools and operations to request.
  • +
  • Does not directly hold the Connector's AAuth signing key.
  • +
+
+ +
+
+
+

AAuth Connector

+

The protocol agent

+
+ Identity boundary +
+
    +
  • Manages the AAuth agent identity, tokens, and signing key.
  • +
  • Proves which agent is calling and which person it acts for.
  • +
  • Enforces authorization challenges and approval handoffs.
  • +
+
+ +
+
+
+

Send and read services

+

The cryptographic processors

+
+ Sees plaintext +
+
    +
  • Send service receives outgoing plaintext before encryption.
  • +
  • Read service manages the private messaging key and decrypts incoming content.
  • +
  • Self-hosting these services can reduce third-party plaintext exposure.
  • +
+
+ +
+
+
+

Secret Agent Co-op

+

The connection directory and mailbox

+
+ Ciphertext only +
+
    +
  • Sees account, connection, sender, recipient, and delivery metadata.
  • +
  • Stores encrypted message bodies and registered public keys.
  • +
  • Cannot directly decrypt message bodies without access to the read service's key.
  • +
+
+
+ + +
+
+ +
+
+
+
Adoption path
+

Start small, then add governance.

+

+ Treat the current Co-op as a secure coordination primitive. Add team controls only after + validating identity, routing, and trust assumptions with a narrow pilot. +

+
+ +
+
+ Phase 1 +

Pilot a trusted pair

+

Prove that two people can delegate routine coordination to their respective agents.

+
    +
  • Verify identities and invitation flow
  • +
  • Test send, receive, and failure cases
  • +
  • Document plaintext processing boundaries
  • +
+
+
+ Phase 2 +

Form a team mesh

+

Onboard a small cross-functional group with explicit connection and data policies.

+
    +
  • Define membership and offboarding
  • +
  • Set human-approval thresholds
  • +
  • Use structured message conventions
  • +
+
+
+ Phase 3 +

Operationalize

+

Add the controls needed for dependable, auditable use across the organization.

+
    +
  • Central policy and incident response
  • +
  • Self-hosting and key custody decisions
  • +
  • Delivery, observability, and retention SLAs
  • +
+
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
CapabilityWhat exists todayWhat the team must design
MembershipVerified email invitations and pairwise acceptanceOrganization-managed roster, roles, and offboarding
IdentityAAuth agent identity plus verified person delegationProvider policy, device posture, and agent lifecycle
MessagingEncrypted one-to-one asynchronous deliveryGroup routing, threads, schemas, priorities, and acknowledgements
Data protectionCiphertext at the Co-op; hosted send/read processorsKey custody, classification, DLP, and retention policy
GovernancePer-resource authorization and person approvalTeam-wide autonomy limits, audit, escalation, and kill switch
+
+
+ +
+
+
+
+
Live demo script
+

Show the idea in four prompts.

+

+ The agent handles protocol details. The person expresses intent and approves only when needed. +

+
+
+

Show my Secret Agent Co-op connections.

+

Send Alex: "What is blocking the release?"

+

Check Secret Agent Co-op for new messages.

+

Summarize Alex's reply and draft the next action.

+
+
+
+
+
+ + + + + + diff --git a/.agent/plans/2026-09-08-aauth-v10-spec-migration/api-surface-map.md b/.agent/plans/2026-09-08-aauth-v10-spec-migration/api-surface-map.md index acadbce6..bd280bd0 100644 --- a/.agent/plans/2026-09-08-aauth-v10-spec-migration/api-surface-map.md +++ b/.agent/plans/2026-09-08-aauth-v10-spec-migration/api-surface-map.md @@ -1879,7 +1879,7 @@ Public owners: `AAuth.AAuthFederationOptions`, `AAuth`. ### src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs -Concept/decision: [di](#di). Source: [AAuthFederationServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs). +Concept/decision: [di](#di). Source: `src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs` (since removed; federation is now `AAuthPersonServerBuilder.WithFederation()`). ```diff - Microsoft.Extensions.DependencyInjection.AAuthFederationServiceCollectionExtensions: public static IServiceCollection AddAAuthFederation ( this IServiceCollection services , AAuthKey personServerKey , string personServerIssuer , string personServerKeyId ) @@ -2970,7 +2970,7 @@ Public owners: `AAuth.Tokens.AccountBinding`, `AAuth.Tokens.AccountExpectation`, ### src/AAuth/Tokens/ActChainBuilder.cs -Concept/decision: [tokens](#tokens). Source: [ActChainBuilder.cs](../../../src/AAuth/Tokens/ActChainBuilder.cs). +Concept/decision: [tokens](#tokens). Source: [ActChainBuilder.cs](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs). ```diff - AAuth.Tokens.ActChainBuilder: public static JsonObject BuildNestedAct ( string upstreamAgentId , JsonObject ? upstreamChain = null ) @@ -2983,7 +2983,7 @@ Public owners: `AAuth.Tokens.ActChainBuilder`, `AAuth.Tokens`. ### src/AAuth/Tokens/ActChainReader.cs -Concept/decision: [tokens](#tokens). Source: [ActChainReader.cs](../../../src/AAuth/Tokens/ActChainReader.cs). +Concept/decision: [tokens](#tokens). Source: [ActChainReader.cs](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainReader.cs). ```diff - AAuth.Tokens.ActChainReader: public static IReadOnlyList < string > GetDelegationChain ( JsonObject payload , int maxDepth = 10 ) @@ -3083,7 +3083,7 @@ Public owners: `AAuth.Tokens.AuthTokenDeliveryResult`, `AAuth.Tokens.AuthTokenRe ### src/AAuth/Tokens/MissionClaim.cs -Concept/decision: [tokens](#tokens). Source: [MissionClaim.cs](../../../src/AAuth/Tokens/MissionClaim.cs). +Concept/decision: [tokens](#tokens). Source: [MissionClaim.cs](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/MissionClaim.cs). ```diff - AAuth.Tokens.MissionClaim: public static MissionClaim ? FromPayload ( JsonObject ? payload ) diff --git a/.agent/plans/2026-09-08-aauth-v10-spec-migration/conformance-ledger.md b/.agent/plans/2026-09-08-aauth-v10-spec-migration/conformance-ledger.md index 1eea6ea2..098f402b 100644 --- a/.agent/plans/2026-09-08-aauth-v10-spec-migration/conformance-ledger.md +++ b/.agent/plans/2026-09-08-aauth-v10-spec-migration/conformance-ledger.md @@ -74,7 +74,7 @@ not be mistaken for a current runtime contract. | [Reauthorization L1338](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1338), agent expiry limits and renewed consent | PS/AS minting, [AuthTokenBuilder](../../../src/AAuth/Tokens/AuthTokenBuilder.cs) | Implemented: [IssuanceBoundsTests](../../../tests/AAuth.Conformance/AuthTokens/IssuanceBoundsTests.cs); Wallet fresh-grant recovery browser cases | | [Mission creation/approval L1350](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1350), exact bytes/hash L1428 | [Mission](../../../src/AAuth/Agent/Mission.cs), governance builder/store | Implemented: [MissionS256Tests](../../../tests/AAuth.Conformance/Missions/MissionS256Tests.cs), [MissionModelTests](../../../tests/AAuth.Conformance/Missions/MissionModelTests.cs), HTTP mission approvals | | [Mission log/completion/status L1432](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1432), permanently terminated L1449/L1455 | Governance mapper and PS state gates | Implemented terminal rejection: [MissionTerminatedTests](../../../tests/AAuth.Conformance/Missions/MissionTerminatedTests.cs), new signed three-endpoint tests and deferred completion tests. Production store permanence/retention is Policy | -| [Mission presentation L1488](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1488), no dereference L1490 and exact reference echo | [Mission header](../../../src/AAuth/Agent/Mission.cs), challenge/chain handlers | Implemented reference-only data flow: [MissionReferenceValidationTests](../../../tests/AAuth.Conformance/Missions/MissionReferenceValidationTests.cs), [MissionHeaderSeamTests](../../../tests/AAuth.Conformance/Missions/MissionHeaderSeamTests.cs), [MissionSignedComponentTests](../../../tests/AAuth.Conformance/HttpSignatures/MissionSignedComponentTests.cs). Resource/AS have no mission-fetch implementation; no arbitrary application callback guarantee | +| [Mission presentation L1488](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1488), no dereference L1490 and exact reference echo | [Mission header](../../../src/AAuth/Agent/Mission.cs), challenge/chain handlers | Implemented reference-only data flow: [MissionReferenceValidationTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/Missions/MissionReferenceValidationTests.cs), [MissionHeaderSeamTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/Missions/MissionHeaderSeamTests.cs), [MissionSignedComponentTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/HttpSignatures/MissionSignedComponentTests.cs). Resource/AS have no mission-fetch implementation; no arbitrary application callback guarantee | | [PS-to-AS request L1503](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1503), child/upstream propagation and signing | [AccessServerClient](../../../src/AAuth/Access/AccessServerClient.cs), [AgentIssuanceContext](../../../src/AAuth/Tokens/AgentIssuanceContext.cs) | Implemented: [AccessServerClientTests](../../../tests/AAuth.Tests/AccessServerClientTests.cs), [DeferredFederationTests](../../../tests/AAuth.Conformance/Person/DeferredFederationTests.cs). Q2 uses normative Signature Keys jwks_uri discovery, not stale protocol example syntax | | [AS response/delivery L1531](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1531), claims composition L1581 | AS endpoints, [AuthTokenResponseValidator](../../../src/AAuth/Tokens/AuthTokenResponseValidator.cs) | Implemented: [AuthTokenDeliveryTests](../../../tests/AAuth.Conformance/AuthTokens/AuthTokenDeliveryTests.cs), [MockAccessServerTests](../../../tests/AAuth.Tests/Integration/MockAccessServerTests.cs); reserved claim requests/pushes rejected | | [Signed requested claims L1599](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1599) (#requirement-claims), [clarification action L1054](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1054) (#agent-response-to-clarification) | [TokenRequestBody](../../../src/AAuth/Server/TokenRequestBody.cs), [AS pending dispatch](../../../src/AAuth/Access/AAuthAccessServerEndpoints.cs) | Implemented, 2026-09-09 final repair: ClaimsPushPreservesRequestedCredentialNamedIdentity in [DeferredFederationTests](../../../tests/AAuth.Conformance/Person/DeferredFederationTests.cs) preserves policy-requested credential-like names and action values through signed HTTP issuance; trusted pending state controls dispatch. Raw duplicate/nested-duplicate and reserved/typed-identity failures leave policy and pending state unchanged; initial and updated-request malformed credential matrices retained | @@ -84,7 +84,7 @@ not be mistaken for a current runtime contract. | [Upstream verification L1766](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1766), AS/PS route L1784, directed sub L1800 | [UpstreamTokenValidator](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs), [CallChainingRouter](../../../src/AAuth/Server/CallChaining/CallChainingRouter.cs) | Implemented: [UpstreamTokenValidationTests](../../../tests/AAuth.Conformance/AuthTokens/UpstreamTokenValidationTests.cs), DirectAsChainingUsesAccessMetadataAndAgentCarrier / RejectsUnboundAuthorization in DeferredFederationTests; distinct intermediary key and audience are preserved | | [Interaction chaining L1819](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1819) | Concierge and shared interaction helpers | Implemented representative flows: [InteractionChainingTests](../../../tests/AAuth.Tests/Agent/InteractionChainingTests.cs), call-chain deferred browsers. Intermediary-owned pending storage requires its own ownership/retention controls; see review limits below | | [Sub-agents L1825](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1825), single depth and parent authorization L1859 | AgentIssuanceContext, agent identifiers and token builders | Implemented: [PersonServerMapperTests](../../../tests/AAuth.Conformance/Person/PersonServerMapperTests.cs), four-party [FederatedWorkerScenario](../../../samples/FederatedWorkerScenario.cs) and both sub-agent browser specs | -| [Delegation chain L1874](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1874), actor nesting/no person identifiers | [ActChainBuilder](../../../src/AAuth/Tokens/ActChainBuilder.cs), [ActChainReader](../../../src/AAuth/Tokens/ActChainReader.cs) | Implemented: [ActChainBuilderTests](../../../tests/AAuth.Conformance/AuthTokens/ActChainBuilderTests.cs), [ActChainReaderTests](../../../tests/AAuth.Conformance/AuthTokens/ActChainReaderTests.cs) | +| [Delegation chain L1874](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1874), actor nesting/no person identifiers | [ActChainBuilder](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs), [ActChainReader](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainReader.cs) | Implemented: [ActChainBuilderTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/AuthTokens/ActChainBuilderTests.cs), [ActChainReaderTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/AuthTokens/ActChainReaderTests.cs) | | [Third-party login L1928](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1928), conditional ps/start_path validation L2000 | Metadata field only | Optional unsupported by sample hosts. No login_endpoint flow is advertised/implemented by the migration; hosts enabling their own endpoint must validate PS discovery and same-origin relative start_path. Metadata serialization tests do not establish login conformance | | [Capabilities L2010](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L2010), ignore unknown/no assumed capabilities | [AAuthCapabilitiesHeader](../../../src/AAuth/Agent/AAuthCapabilitiesHeader.cs), exchange options | Implemented: [CapabilitiesHeaderTests](../../../tests/AAuth.Conformance/HttpSignatures/CapabilitiesHeaderTests.cs), client callback/capability tests | | [Scopes L2034](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L2034), identity scopes and account L2051 | Scope validation and [AccountBinding](../../../src/AAuth/Tokens/AccountBinding.cs) | Implemented: [ScopeVocabularyTests](../../../tests/AAuth.Conformance/ResourceTokens/ScopeVocabularyTests.cs), [AccountBindingTests](../../../tests/AAuth.Tests/Tokens/AccountBindingTests.cs), two-account Bookings/Events browsers | diff --git a/.agent/plans/2026-09-08-aauth-v10-spec-migration/docs-surface-map.md b/.agent/plans/2026-09-08-aauth-v10-spec-migration/docs-surface-map.md index 43eed323..1495b5d6 100644 --- a/.agent/plans/2026-09-08-aauth-v10-spec-migration/docs-surface-map.md +++ b/.agent/plans/2026-09-08-aauth-v10-spec-migration/docs-surface-map.md @@ -207,7 +207,7 @@ file even when it has zero snippets; a file hash detects prose/navigation change | [samples/GuidedTour/CodeSnippets.cs](../../../samples/GuidedTour/CodeSnippets.cs) | `ff4d96d0e9b8f5cf58beba47bb15c3ed4dfcf72651ac8c6ba740489aeed10ea3` | 42 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | | [samples/GuidedTour/Components/_Imports.razor](../../../samples/GuidedTour/Components/_Imports.razor) | `ff71bc5b618f275846e5fc70ad99cd64d493b8bf198d6b604d7105764bbd08a0` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | | [samples/GuidedTour/Components/App.razor](../../../samples/GuidedTour/Components/App.razor) | `848293d6fb5463468a75591d228c60beb0b52c8c187d2fa9882d393d77f4b143` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | -| [samples/GuidedTour/Components/CapabilityTourChrome.razor](../../../samples/GuidedTour/Components/CapabilityTourChrome.razor) | `53bb329bec371f05041a298da8d6f30bb41af8597553f04de66bcc6e6f1ec724` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| `samples/GuidedTour/Components/CapabilityTourChrome.razor` (removed; flows 12–15 now run in `/tour`) | `53bb329bec371f05041a298da8d6f30bb41af8597553f04de66bcc6e6f1ec724` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | | [samples/GuidedTour/Components/EntityHighlighter.cs](../../../samples/GuidedTour/Components/EntityHighlighter.cs) | `44dbe8b987a09db2021e280d3156ac5fb1b59a30854adc611f3f153d509ab829` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | | [samples/GuidedTour/Components/Pages/Catalog.razor](../../../samples/GuidedTour/Components/Pages/Catalog.razor) | `3d9fdad1a7512894272e75a106ba55030e8f5c8644e7d0b726b8954dd0c7c8ce` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | | [samples/GuidedTour/Components/Pages/Documents.razor](../../../samples/GuidedTour/Components/Pages/Documents.razor) | `744149b225526a8f806399051240443a71157683b6ad2551d5b756f940fdc556` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | diff --git a/.agent/plans/2026-09-08-aauth-v10-spec-migration/implementation-plan.md b/.agent/plans/2026-09-08-aauth-v10-spec-migration/implementation-plan.md index f4191a65..a768a646 100644 --- a/.agent/plans/2026-09-08-aauth-v10-spec-migration/implementation-plan.md +++ b/.agent/plans/2026-09-08-aauth-v10-spec-migration/implementation-plan.md @@ -418,7 +418,7 @@ Phase rule: preserve authenticated context end to end; no placeholder consent gr - Complete [UpstreamTokenValidator](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs) structural validation without incorrectly equating the original upstream PoP key to the intermediary's current request key. -- Tighten [ActChainBuilder](../../../src/AAuth/Tokens/ActChainBuilder.cs), readers, +- Tighten [ActChainBuilder](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs), readers, and [AuthTokenResponseValidator](../../../src/AAuth/Tokens/AuthTokenResponseValidator.cs): immediate actor, nested context, no person identifiers, independently asserted downstream sub. Extend agent delivery checks as well as PS-side checks. diff --git a/.agent/plans/2026-09-08-aauth-v10-spec-migration/research.md b/.agent/plans/2026-09-08-aauth-v10-spec-migration/research.md index 2f69e3ef..bf85cb21 100644 --- a/.agent/plans/2026-09-08-aauth-v10-spec-migration/research.md +++ b/.agent/plans/2026-09-08-aauth-v10-spec-migration/research.md @@ -341,8 +341,8 @@ P2, R; pre-existing structural gap, with a v10 actor prohibition. [UpstreamTokenValidator L219](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs#L219) uses generic JWT verification without all those checks. Trust and audience checks exist. [P1809] (`#directed-sub-chaining`) prohibits person -identifiers inside `act`; [ActChainBuilder L32](../../../src/AAuth/Tokens/ActChainBuilder.cs#L32) -clones upstream objects and [L55](../../../src/AAuth/Tokens/ActChainBuilder.cs#L55) +identifiers inside `act`; [ActChainBuilder L32](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs#L32) +clones upstream objects and [L55](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs#L55) only checks agent presence/depth. Direct top-level upstream `sub` copying was not found. [AuthTokenBuilder L211](../../../src/AAuth/Tokens/AuthTokenBuilder.cs#L211) blocks only already-populated extra claims, allowing unset reserved fields such diff --git a/.agent/plans/2026-09-11-aauth-v11-spec-migration/api-surface-map.md b/.agent/plans/2026-09-11-aauth-v11-spec-migration/api-surface-map.md new file mode 100644 index 00000000..b34fe89e --- /dev/null +++ b/.agent/plans/2026-09-11-aauth-v11-spec-migration/api-surface-map.md @@ -0,0 +1,4243 @@ +--- +description: Proposed public API changes and consumer ownership for draft-11 WIP migration. +--- + +# Public API surface map - draft-11 WIP + +Research baseline: `94576a3ebcba8cd1d167923e50c8796132057600`, 2026-09-11. +No SDK changes have been made. This is a concept/member impact inventory, not a +generated complete declaration delta or a binary compatibility report. Evidence +and requirement strengths are recorded in [research.md](research.md); F labels +refer to its findings. New names below are proposals, not implemented APIs. + +## Contract map + +| Concept | Current surface and owner | Proposed cutover | Callers and validation | +|---|---|---|---| +| Person-token type and verification, F02 | [AAuthTokenType](../../../src/AAuth/AAuthTokenType.cs), [TokenVerifier](../../../src/AAuth/Tokens/TokenVerifier.cs), [resolver](../../../src/AAuth/HttpSig/DefaultSignatureKeyResolver.cs) | Add `PersonToken` and a dedicated typed verified result; require person issuer/DWK, resource audience, key, opaque subject and lifetimes. Do not treat parsed claims as verified. | Middleware, endpoint policies, token inspector, test token factories; person/auth substitution negatives | +| Person issuance, F02 | [PS endpoints](../../../src/AAuth/Person/AAuthPersonServerEndpoints.cs), [governance](../../../src/AAuth/Server/Governance/) | Proposed `PersonTokenBuilder`, person-token endpoint/client, request/result and verified issuance context; include resource, mission, parent/upstream context and deferred consent. Forbid `scope/account` in person tokens. | Both apps, AgentConsole, MissionAgent, worker flow, PS tests | +| Resource token, F03/F04 | [ResourceTokenBuilder](../../../src/AAuth/Tokens/ResourceTokenBuilder.cs), [R3Challenge](../../../src/AAuth.R3/R3Challenge.cs) | Remove resource `Agent`; require verified `PersonServer`, `Subject`, `PresentedTokenId`, key thumbprint; replace nested mission with `MissionS256`; preserve account/tenant and request signature binding. | All custom resources and challenge middleware; raw issued-JWT assertions | +| Auth token, F01/F06 | [AuthTokenBuilder](../../../src/AAuth/Tokens/AuthTokenBuilder.cs), [AgentAuthTokenValidator](../../../src/AAuth/Tokens/AgentAuthTokenValidator.cs) | Remove `Agent/Act/Mission` wire inputs, require `PersonServer/Subject`, add `MissionS256` and explicit verified presented expiry. Update reserved claims to prevent old fields or new authority fields being injected. | PS/AS/R3 issuers, response validators, helpers; old-claim injection and scope-only output failures | +| Exchange contracts, F04 | [TokenExchangeClient](../../../src/AAuth/Agent/TokenExchangeClient.cs), [AccessServerClient](../../../src/AAuth/Access/AccessServerClient.cs), [AS endpoints](../../../src/AAuth/Access/AAuthAccessServerEndpoints.cs) | Required `PresentedToken` in agent-to-PS and PS-to-AS requests; preserve exact credential through pending/replacement paths. One paired-token verification implementation with explicit role context. | Deferred/clarification flows, R3 AS, worker and chain callers; independent AS verification and substitution tests | +| Clarification replacement, F04/Q13 | [ClarificationResponse.Update](../../../src/AAuth/Agent/ClarificationExchange.cs#L63), core PS/AS pending handlers | Add the agreed replacement presented-token input when jti changes; verify both before atomic installation. Retain old pair only for unchanged requests, not across a new resource-token binding. | Agent-to-PS and PS-to-AS clarification; refreshed person token, changed jti, failed replacement must leave pending state untouched | +| Resource identity/policy, F06 | [verification middleware](../../../src/AAuth/Server/Verification/AAuthVerificationMiddleware.cs), [authentication handler](../../../src/AAuth/Server/Verification/AAuthAuthenticationHandler.cs), [access mode](../../../src/AAuth/Server/Verification/AAuthAccessMode.cs) | Add person-identity policy; model agent identity as absent on person/auth resource requests. Keep `(issuer, subject)` person identity and explicit key/mission/account state; no inferred agent fallback. | Profile, Calendar, Trips, Wallet, Bookings, Catalog, Documents; policy and captured-response tests | +| Metadata, F05 | [ServerMetadata](../../../src/AAuth/Discovery/ServerMetadata.cs), [WellKnownEndpoints](../../../src/AAuth/Server/Metadata/WellKnownEndpoints.cs), [constants](../../../src/AAuth/AAuthConstants.cs) | Rename AAuth `TokenEndpoint` to `AuthTokenEndpoint`; PS adds required `PersonTokenEndpoint`; session mode is `session-token`. Optional exact algorithm set and validated resource-link discovery are separate features. | All metadata producers/clients, configuration and fixtures; no old-field fallback; preserve OIDC names | +| Agent composition/cache, F02/F12 | [AAuthClientBuilder](../../../src/AAuth/AAuthClientBuilder.cs), [AAuthTokenHolder](../../../src/AAuth/Agent/AAuthTokenHolder.cs), [TokenRefreshHandler](../../../src/AAuth/Agent/TokenRefreshHandler.cs) | Extend existing builder with explicit person acquisition and resource/mission/authority/key-partitioned state. Keep dedicated agent credential for PS/AP. Refresh upstream dependencies before dependent tokens. | Fluent convenience and manually composed clients; factory ownership, concurrency, cancellation, rotation and account isolation | +| Challenges and deferred completion, F03/F17 | [ChallengeHandler](../../../src/AAuth/Agent/ChallengeHandler.cs), [InteractionHandler](../../../src/AAuth/Agent/InteractionHandler.cs), [DeferredExchange](../../../src/AAuth/Agent/DeferredExchange.cs) | Add person challenge and 202 auth-token handling; capture original request token before exchange. 202 completion uses GET at pending URL; no original-body resubmission. | Non-idempotent request tests, pending-resource hosts and both apps | +| Mission approval, F07 | [Mission](../../../src/AAuth/Agent/Mission.cs), [MissionClient](../../../src/AAuth/Agent/Governance/MissionClient.cs), [governance mapper](../../../src/AAuth/DependencyInjection/AAuthGovernanceApplicationBuilderExtensions.cs) | Proposed approval result holds encoded blob/verified bytes, hash, capabilities and person-token map. Remove `AAuth-Mission` transport and optional header-driven mission propagation. | PS custom approval code, inspectors, tool session, mission fences; envelope-versus-blob hashing | +| Mission lifecycle, F08/F09 | [MissionSession](../../../src/AAuth/Agent/Governance/MissionSession.cs), [IMissionLog](../../../src/AAuth/Server/Governance/IMissionLog.cs), [InMemoryMissionStore](../../../src/AAuth/Server/Governance/InMemoryMissionStore.cs) | Add update/completion action API at mission URL, accepted-update bytes/digest, expiry and separate open termination reason. Make terminal transitions atomic; remove interaction-based completion. | MissionAgent, PS pending routes, shared UI sessions; ownership, expiry during consent and irreversible-state tests | +| Consent policy, F10 | [IMissionTokenConsent](../../../src/AAuth/Server/Governance/IMissionTokenConsent.cs), [sample asserter](../../../samples/MockPersonServer/SampleIdentityClaimsAsserter.cs) | Separate resource assertions from justification/display hints; carry accepted mission updates and fixed person identity into consent/claims hooks. Do not rename protocol OIDC `prompt` into justification. | Sample consent, AS claims negotiation, no-claims path; provenance and subject-replacement negatives | +| Chain and worker authority, F11 | [CallChainingRouter](../../../src/AAuth/Server/CallChaining/CallChainingRouter.cs), [UpstreamTokenValidator](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs), [ActChainBuilder](../../../src/AAuth/Tokens/ActChainBuilder.cs) | Route by verified upstream PS; person acquisition first; remove `ActChainBuilder` from the AAuth issuance API after consumers move to PS/AS records. Q3/Q4 settle verification/authority, not a compatibility overload. | Concierge, worker, Wallet protocol, chain tests and snippets | +| Temporal/signature policy, F12/F13 | [TokenVerifier](../../../src/AAuth/Tokens/TokenVerifier.cs), [NamingTokenVerifier](../../../src/AAuth/HttpSig/NamingTokenVerifier.cs), [AAuthVerifier](../../../src/AAuth/HttpSig/AAuthVerifier.cs), [signing handler](../../../src/AAuth/HttpSig/AAuthSigningHandler.cs) | Separate strict AAuth expiry, optional future issuance bound, live signature window and generic-profile rules. Require signed body components at PS/AS role boundaries. | Every body-bearing initial/pending request; TimeProvider boundary tests; no global delayed-verification shortcut | +| Revocation API/store, F14/F15 | [RevocationClient](../../../src/AAuth/Server/RevocationClient.cs), [RevocationEndpoint](../../../src/AAuth/Server/RevocationEndpoint.cs), [IJtiStore](../../../src/AAuth/Server/IJtiStore.cs), [InMemoryJtiStore](../../../src/AAuth/Server/InMemoryJtiStore.cs) | Body `jti/exp`, signer-derived issuer, bounded unseen-token recording; remove cross-issuer target override. Separate revocation dependency edges from expiry-bound sources; add destinations and delivery state. | Wallet, Bookings, PS/AP/AS, pending grants; races, namespace isolation, expiry and cascade tests | +| Errors and recovery, F16 | [errors](../../../src/AAuth/Errors/), [AAuthProblemDetails](../../../src/AAuth/Server/AAuthProblemDetails.cs) | Typed presented-token and revocation failures, clock-skew action, AS terminal-response versus unavailable outcome. Preserve status/carriage and never refresh indefinitely on clock skew. | All endpoint clients, deferred errors, console/UI error displays | +| R3 names and vocabulary, F18 | [R3AuthClaims](../../../src/AAuth.R3/R3AuthClaims.cs), [models](../../../src/AAuth.R3/Model/), [R3Metadata](../../../src/AAuth.R3/R3Metadata.cs) | `Conditional` protocol APIs become `PerCall`; remove R3 document/proposal `Version` and OpenAPI Gateway standard APIs. Keep raw-byte hashes and seven standard vocabularies; preserve valid format-specific qualifiers. | Bookings/Catalog, schemas, factories, policy options, tests and all examples | +| R3 execution/reader scope, F17/F19/F21 | [R3Enforcement](../../../src/AAuth.R3/R3Enforcement.cs), [R3ProposalStore](../../../src/AAuth.R3/R3ProposalStore.cs), [R3DocumentReaderPolicy](../../../src/AAuth.R3/R3DocumentReaderPolicy.cs), [R3AccessTokenEndpoint](../../../src/AAuth.R3/R3AccessTokenEndpoint.cs) | Atomic grant consumption/result retention; document-specific PS/AS entitlement; audit person/key provenance; optional `Result` must reach policy or be rejected as unsupported. | R3 resource/AS, SQLite audit, both apps; same proposal with distinct grants, concurrent retries and foreign-reader negatives | +| Protected Events tickets, F20 | [EventStores](../../../src/AAuth.Events/EventStores.cs), [BookingsEvents](../../../samples/EventSupport/BookingsEvents.cs) | Q5 gates replacement of agent-dependent ticket issuance and persisted contract. Keep subscribe-token agent IDs and `self-jwt` events unchanged. | Protected Events client/server sample and SQLite tests; do not claim unchanged package means no work | +| Optional companions, F21-F23 | [BootstrapBuilder](../../../src/AAuth/BootstrapBuilder.cs), R3 annotation/result models, no budget implementation | Reuse current provisioning; hosted child protocol, full Budgets and delayed verification require separate approval. Metadata hints cannot advertise unimplemented enforcement. | Native/platform work remains informational; no speculative new package dependencies | + +## Ownership and defaults + +- Existing injected keys, clocks, transports and stores remain caller-owned. + Factory-created clients and refreshers remain pipeline-owned; propagate + cancellation before publishing token/cache state. Repeated builds must not + share disposed resources or mutable authorization state accidentally. +- Person/auth caches cannot be keyed solely by origin or agent token text. + Account selects auth state, not person-token claims; mission, directed person, + worker key, and upstream authority distinguish otherwise similar flows. +- Preserve explicit production egress admission and development loopback opt-in. + New person endpoints and discovery links pass through the same transport rules. +- Generic signing APIs remain supported. Prefer extending established abstractions + over introducing parallel `AAuthAgentBuilder`/generic builder families without + evidence that the split reduces complexity. +- No obsolete wire aliases or backward-reading fallback in the proposed alpha + cutover. Shared tokens and old APIs move with all compiled consumers. Historical + spec files and plans remain untouched. +- Persistent mission, ticket and invocation schemas need either an explicit + migration or separate versioned sample storage. No silent clearing of user data. + +## Inventory tooling + +> **Update (2026-09):** Phase 1 parameterized the tool. It now defaults to +> this map and baseline `v0.10.0-alpha.1` (`f44587f`, the released draft-10 +> SDK merged into this branch), and accepts `--map` and `--baseline`. The v10 +> map is written only when named explicitly. Run +> `dotnet run --project tools/ApiSurface -- . --write` after reviewing a delta. + +[tools/ApiSurface/Program.cs L9](../../../tools/ApiSurface/Program.cs#L9) hardcodes +the v10 map and defaults to `ba768f1`. Parameterize the destination and choose +this research baseline before generating an implementation delta. Its source +scanner is useful for declared public/protected C# members, not synthesized or +inherited APIs, binary compatibility, Razor-generated code, or all runtime call +sites. The writing mode must not update the historical v10 evidence by accident. + +After the contract freezes, the new map must include declarations, defaults, +required inputs, nullable states, disposal/ownership, behavior-only changes, +obsolete-member removal, and every compiled caller. This research map is not a +substitute for that future gate. See [docs-surface-map.md](docs-surface-map.md) +for non-compiled content and [conformance-ledger.md](conformance-ledger.md) for tests. + + + +## Complete declaration delta + +Baseline `v0.10.0-alpha.1`; 244 changed public-source files, 1195 added/replacement declarations, 461 removed/replaced declarations. + +Generated from all current SDK source files, including untracked additions, and the baseline tree. Public/protected declarations include containing namespaces/types, overload parameters, required members, attributes, optional defaults, primary constructors and interface members. Compiler-synthesized/inherited members are represented by their source declarations, not expanded. Unchanged signatures in changed files are listed by containing type as behavior-review entries; the concept table above supplies their entry point, ownership, callers and tests. No source file is excluded by guessed file role. + +### samples/CapabilitySupport/CatalogDemoSession.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [CatalogDemoSession.cs](../../../samples/CapabilitySupport/CatalogDemoSession.cs). + +```diff +- AAuth.Samples.Capabilities.CatalogDemoSession: public static string [ ] Steps { get ; } = [ "Discover catalog services" , "Authorize selected service" , "Read selected catalog" , "Reject a sibling-service grant" , "Authorize sibling and recover" ] +- AAuth.Samples.Capabilities.CatalogDemoSession: public string ? ConsentUrl { get ; private set ; } ++ AAuth.Samples.Capabilities.CatalogDemoSession: public Interaction ? Consent { get ; private set ; } ++ AAuth.Samples.Capabilities.CatalogDemoSession: public static string [ ] Steps { get ; } = [ "Discover catalog definition" , "Authorize selected operation" , "Read selected catalog" , "Reject a sibling-operation grant" , "Authorize sibling and recover" ] ++ AAuth.Samples.Capabilities.CatalogDemoSession: public string ? ConsentUrl +``` + +Public owners: `AAuth.Samples.Capabilities.CatalogDemoSession`, `AAuth.Samples.Capabilities`. + +### samples/CapabilitySupport/DocumentDemoSession.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [DocumentDemoSession.cs](../../../samples/CapabilitySupport/DocumentDemoSession.cs). + +```diff +- AAuth.Samples.Capabilities.DocumentDemoSession: public string ? ConsentUrl { get ; private set ; } +- AAuth.Samples.Capabilities: public sealed class DocumentDemoSession ( string provider , string person , string resource ) : IDisposable ++ AAuth.Samples.Capabilities.DocumentDemoSession: public Interaction ? Consent { get ; private set ; } ++ AAuth.Samples.Capabilities.DocumentDemoSession: public string ? ConsentUrl ++ AAuth.Samples.Capabilities: public sealed class DocumentDemoSession ( IAAuthAgentFactory agents , string provider , string person , string resource ) : IDisposable +``` + +Public owners: `AAuth.Samples.Capabilities.DocumentDemoSession`, `AAuth.Samples.Capabilities`. + +### samples/CapabilitySupport/WalletDemoSession.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [WalletDemoSession.cs](../../../samples/CapabilitySupport/WalletDemoSession.cs). + +```diff +- AAuth.Samples.Capabilities.WalletDemoSession: public string ? ConsentUrl { get ; private set ; } +- AAuth.Samples.Capabilities.WalletFlow: DirectAs +- AAuth.Samples.Capabilities: public sealed class WalletDemoSession ( string provider , string person , string wallet , string concierge ) : IDisposable ++ AAuth.Samples.Capabilities.WalletDemoSession: public Interaction ? Consent { get ; private set ; } ++ AAuth.Samples.Capabilities.WalletDemoSession: public string ? ConsentUrl ++ AAuth.Samples.Capabilities.WalletFlow: AsGrantChaining ++ AAuth.Samples.Capabilities: public sealed class WalletDemoSession ( IAAuthAgentFactory agents , string provider , string person , string wallet , string concierge ) : IDisposable +``` + +Public owners: `AAuth.Samples.Capabilities.WalletDemoSession`, `AAuth.Samples.Capabilities.WalletFlow`, `AAuth.Samples.Capabilities`. + +### samples/CapabilitySupport/WalletScenarioCode.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [WalletScenarioCode.cs](../../../samples/CapabilitySupport/WalletScenarioCode.cs). + +```diff +- AAuth.Samples.Capabilities.WalletScenarioCode: public const string Clarification = """ + public static Task ClarifyAsync(HttpClient signedAgent, MetadataClient metadata, + string personServer, string resourceToken, + Func consent, + Func> answer, + CancellationToken cancellationToken) + => new TokenExchangeClient(signedAgent, metadata).ExchangeAsync(personServer, resourceToken, + new TokenExchangeRequest { OnInteractionRequired = consent, OnClarificationRequired = answer }, + cancellationToken); + + public static ClarificationResponse Answer(string justification) + => ClarificationResponse.Respond(justification); + + public static ClarificationResponse Cancel() => ClarificationResponse.Cancel(); + """ ; +- AAuth.Samples.Capabilities.WalletScenarioCode: public const string DirectAs = """ + public static async Task ReadWalletAsync(IAAuthKey key, string issuer, string agent, + string kid, string upstreamToken, string wallet, AAuthEgressPolicy egress, + CancellationToken cancellationToken) + { + using var client = AAuthClientBuilder.SelfIssuing(key).As(issuer, agent).WithKid(kid) + .WithEgressPolicy(egress).WithCallChaining(upstreamToken) + .WithChallengeHandling(options => options.Capabilities = Array.Empty()).Build(); + using var response = await client.GetAsync(wallet + "/wallet", cancellationToken); + response.EnsureSuccessStatusCode(); + return await response.Content.ReadAsStringAsync(cancellationToken); + } + """ ; +- AAuth.Samples.Capabilities.WalletScenarioCode: public const string Revocation = """ + public static Task RevokeAsync(HttpClient signedPersonServer, + Uri resourceRevocationEndpoint, string issuer, string tokenId, CancellationToken cancellationToken) + => new RevocationClient(signedPersonServer).RevokeAsync(resourceRevocationEndpoint, + new TokenKey(issuer, tokenId), cancellationToken); + + public static Task RecoverAsync(HttpClient signedAgent, MetadataClient metadata, + string personServer, string freshResourceToken, + Func consent, CancellationToken cancellationToken) + => new TokenExchangeClient(signedAgent, metadata).ExchangeAsync(personServer, freshResourceToken, + new TokenExchangeRequest { OnInteractionRequired = consent }, cancellationToken); + """ ; ++ AAuth.Samples.Capabilities.WalletScenarioCode: public const string AsGrantChaining = """ + public static async Task ReadWalletAsync(IAAuthSigner key, string issuer, string agent, + string kid, string upstreamToken, string wallet, AAuthEgressPolicy egress, + CancellationToken cancellationToken) + { + using var client = AAuthClientBuilder.SelfIssuing(key).As(issuer, agent).WithKid(kid) + .WithEgressPolicy(egress).WithCallChaining(upstreamToken) + .WithChallengeHandling(options => options.Capabilities = Array.Empty()).Build(); + using var response = await client.GetAsync(wallet + "/wallet", cancellationToken); + response.EnsureSuccessStatusCode(); + return await response.Content.ReadAsStringAsync(cancellationToken); + } + """ ; ++ AAuth.Samples.Capabilities.WalletScenarioCode: public const string Clarification = """ + public static Task ClarifyAsync(AAuthAgent agent, + string personServer, string resourceToken, string personToken, + Func consent, + Func> answer, + CancellationToken cancellationToken) + // The agent's TokenExchange client is signed as the agent, never with a carrier token. + => agent.TokenExchange.ExchangeAsync(personServer, resourceToken, + new TokenExchangeRequest + { + PresentedToken = personToken, OnInteractionRequired = consent, OnClarificationRequired = answer, + }, + cancellationToken); + + public static ClarificationResponse Answer(string justification) + => ClarificationResponse.Respond(justification); + + public static ClarificationResponse Cancel() => ClarificationResponse.Cancel(); + """ ; ++ AAuth.Samples.Capabilities.WalletScenarioCode: public const string Revocation = """ + public static Task RevokePersonTokenAsync(IServiceProvider services, + string personTokenJti, CancellationToken cancellationToken) + { + // The PS revokes its person token by its jti; the stored {jti, exp} + // record lets it notify the resource and every AS it presented it to. + // Each AS cascades to the auth tokens it issued against that person token. + var revocation = services.GetRequiredKeyedService(AAuthPersonServerBuilder.DefaultName); + return revocation.RevokeTokenAsync(personTokenJti, cancellationToken); + } + + public static Task RecoverAsync(AAuthAgent agent, + string personServer, string freshResourceToken, string personToken, + Func consent, CancellationToken cancellationToken) + => agent.TokenExchange.ExchangeAsync(personServer, freshResourceToken, + new TokenExchangeRequest { PresentedToken = personToken, OnInteractionRequired = consent }, cancellationToken); + """ ; +``` + +Public owners: `AAuth.Samples.Capabilities.WalletScenarioCode`, `AAuth.Samples.Capabilities`. + +### samples/Concierge/ChainCaptureHandler.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [ChainCaptureHandler.cs](../../../samples/Concierge/ChainCaptureHandler.cs). + +```diff +- Concierge.ChainCaptureHandler: public List < ChainExchange > Exchanges { get ; } = [ ] ++ Concierge.ChainCaptureHandler: public static List < ChainExchange > Begin ( ) +``` + +Public owners: `Concierge.ChainCaptureHandler`, `Concierge`. + +### samples/Concierge/PendingStore.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [PendingStore.cs](../../../samples/Concierge/PendingStore.cs). + +```diff +- Concierge.PendingStore: public Entry Add ( string upstreamToken , string interactionUrl , string interactionCode , string downstreamBase = "http://localhost:5001" , string downstreamPath = "/events" , string pendingPrefix = "/pending" ) +- Concierge.PendingStore: public sealed record Entry ( string Id , string UpstreamToken , string InteractionUrl , string InteractionCode , string DownstreamBase , string DownstreamPath , string PendingPrefix ) ++ Concierge.PendingStore: public Entry Add ( string upstreamToken , ChainedInteractionEntry interaction , string downstreamBase = "http://localhost:5001" , string downstreamPath = "/events" , string pendingPrefix = "/pending" ) ++ Concierge.PendingStore: public sealed record Entry ( string Id , string UpstreamToken , ChainedInteractionEntry Interaction , string DownstreamBase , string DownstreamPath , string PendingPrefix ) +``` + +Public owners: `Concierge.PendingStore.Entry`, `Concierge.PendingStore`, `Concierge`. + +### samples/Concierge/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/Concierge/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Concierge`. + +### samples/ConsentSupport/PersonServerConsent.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [PersonServerConsent.cs](../../../samples/ConsentSupport/PersonServerConsent.cs). + +```diff ++ ConsentSupport.PersonServerConsent: public static Interaction FromUserUrl ( string userUrl , string code ) ++ ConsentSupport.PersonServerConsent: public static bool IsPersonServerHosted ( string ? personServer , Interaction interaction ) ++ ConsentSupport.PersonServerConsent: public static string DashboardUrl ( string personServer , string ? code = null ) ++ ConsentSupport: public static class PersonServerConsent +``` + +Public owners: `ConsentSupport.PersonServerConsent`, `ConsentSupport`. + +### samples/EventSupport/BookingsEvents.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [BookingsEvents.cs](../../../samples/EventSupport/BookingsEvents.cs). + +```diff +- AAuth.Samples.Events: public sealed class BookingsEvents ( string issuer , IAAuthKey key , string keyId , EventsProtocol protocol , SqliteEventStore store ) ++ AAuth.Samples.Events: public sealed class BookingsEvents ( string issuer , IAAuthSigner key , string keyId , EventsProtocol protocol , SqliteEventStore store ) +``` + +Public owners: `AAuth.Samples.Events.BookingsEvents`, `AAuth.Samples.Events`. + +### samples/EventSupport/EventDemoCode.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [EventDemoCode.cs](../../../samples/EventSupport/EventDemoCode.cs). + +```diff +- AAuth.Samples.Events.EventDemoCode: public const string Delivery = """ + public static async Task TriggerSampleEventAsync(EventsProtocol protocol, string resource, + string eid, IAAuthKey agentKey, string agentToken, string? account, CancellationToken cancellationToken) + { + using var response = await protocol.SendAsync(HttpMethod.Post, + new Uri(resource + "/local/events/" + eid + "/notify" + + (account is null ? "" : "?account=" + Uri.EscapeDataString(account))), agentKey, agentToken, + selfIssued: false, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + } + + public static async Task DeliverResourceEventAsync(EventsProtocol protocol, string resource, + string provider, string agent, string eid, IAAuthKey resourceKey, string resourceKid, + byte[] payload, CancellationToken cancellationToken) + { + var token = new EventTokenBuilder + { + Issuer = resource, Audience = agent, Eid = eid, Key = resourceKey, + KeyId = resourceKid, Verifier = protocol.TokenVerifier, + }.Build(); + var endpoint = await protocol.ResolveEventEndpointAsync(provider, cancellationToken); + using var response = await protocol.SendAsync(HttpMethod.Post, endpoint, + resourceKey, token, selfIssued: true, body: payload, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + } + """ ; +- AAuth.Samples.Events.EventDemoCode: public const string Discover = """ + public static async Task DiscoverChannelsAsync(HttpClient http, + EventsProtocol protocol, string resource, string provider, CancellationToken cancellationToken) + { + using var metadata = new MetadataClient(http); + var resourceMetadata = await metadata.FetchAsync( + new Uri(resource + "/.well-known/aauth-resource.json"), cancellationToken); + var documentUrl = resourceMetadata["r3_vocabularies"]!["urn:aauth:vocabulary:asyncapi"]!.GetValue(); + var channels = await http.GetFromJsonAsync( + new Uri(new Uri(resource), documentUrl), cancellationToken); + var eventEndpoint = await protocol.ResolveEventEndpointAsync(provider, cancellationToken); + return channels!; + } + """ ; +- AAuth.Samples.Events.EventDemoCode: public const string Example = """ + builder.Services.AddAAuthEvents(); + var app = builder.Build(); + using var http = AAuthHttpTransport.CreateClient(egressPolicy); + var protocol = new EventsProtocol(http, + app.Services.GetServices()); + + // Public registration uses an AsyncAPI channel URL; protected + // registration uses the ticket from an authorized Bookings response. + using var registration = await protocol.SendAsync(HttpMethod.Post, + subscriptionUrl, agentKey, subscribeToken, selfIssued: false, + body: subscriptionParameters); + + // Resource signs both JWT and HTTP with the same discoverable key. + var eventToken = new EventTokenBuilder + { + Issuer = resource, Audience = agent, Eid = subscription.Eid, + Key = resourceKey, KeyId = resourceKid, + Verifier = protocol.TokenVerifier + }.Build(); + var endpoint = await protocol.ResolveEventEndpointAsync(subscription.Provider); + using var delivery = await protocol.SendAsync(HttpMethod.Post, + endpoint, resourceKey, eventToken, selfIssued: true, body: payloadBytes); + + // AP endpoint requires a durable transactional quota/outbox store. + app.MapAAuthEventEndpoint("/events", protocol, providerStore); + + // Agent verifies the issuer JWT and context before persisting receipt. + var receiver = new EventReceiver(protocol, agentStore, agent); + var firstReceipt = await receiver.ReceiveAsync(eventToken, payloadBytes); + """ ; +- AAuth.Samples.Events.EventDemoCode: public const string Receipt = """ + public static async Task VerifyInboxAsync(EventsProtocol protocol, IAgentEventStore store, + string provider, string agent, string eid, IAAuthKey key, string agentToken, + CancellationToken cancellationToken) + { + using var response = await protocol.SendAsync(HttpMethod.Get, + new Uri(provider + "/local/events/inbox"), key, agentToken, + selfIssued: false, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + var pending = (await response.Content.ReadFromJsonAsync(cancellationToken))!; + var item = pending.Single(delivery => delivery.Event.Eid == eid); + var receiver = new EventReceiver(protocol, store, agent); + await receiver.ReceiveAsync(item.Event.Token, item.Event.Body, cancellationToken); + var duplicate = await receiver.ReceiveAsync(item.Event.Token, item.Event.Body, cancellationToken); + if (duplicate) throw new InvalidOperationException("Duplicate event was not suppressed."); + using var acknowledged = await protocol.SendAsync(HttpMethod.Post, + new Uri(provider + "/local/events/inbox/" + item.Receipt + "/ack"), key, agentToken, + selfIssued: false, cancellationToken: cancellationToken); + acknowledged.EnsureSuccessStatusCode(); + } + """ ; +- AAuth.Samples.Events.EventDemoCode: public const string Registration = """ + public static async Task RegisterSubscriptionAsync(EventsProtocol protocol, + Uri subscriptionUrl, IAAuthKey key, string subscribeToken, CancellationToken cancellationToken) + { + using var response = await protocol.SendAsync(HttpMethod.Post, subscriptionUrl, + key, subscribeToken, selfIssued: false, + body: "{\"event_types\":[\"reservation.available\"]}"u8.ToArray(), + cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + } + """ ; +- AAuth.Samples.Events.EventDemoCode: public const string SubscribeToken = """ + public static async Task AcquireSubscribeTokenAsync(EventsProtocol protocol, + IAgentEventStore store, IAAuthKey key, string agentToken, string agent, + string provider, string resource, string context, CancellationToken cancellationToken) + { + var body = System.Text.Encoding.UTF8.GetBytes(new JsonObject + { ["resource"] = resource, ["max_uses"] = 1 }.ToJsonString()); + using var response = await protocol.SendAsync(HttpMethod.Post, + new Uri(provider + "/local/events/subscribe"), key, agentToken, + selfIssued: false, body: body, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + var result = (await response.Content.ReadFromJsonAsync(cancellationToken))!; + store.Remember(new(result["eid"]!.GetValue(), resource, agent, context)); + return result; + } + """ ; +- AAuth.Samples.Events.EventDemoCode: public const string SubscriptionUrl = """ + public static async Task<(string Agent, string AgentToken, string SubscriptionUrl)> ObtainSubscriptionUrlAsync(AAuthKey key, + string provider, string person, string resource, string account, bool protectedChannel, + string publicSubscriptionUrl, AAuthEgressPolicy policy, + Func showConsent, CancellationToken cancellationToken) + { + var enrolled = await AAuthClientBuilder.Bootstrap(provider + "/enrol") + .WithKey(key).WithKeyStore(new InMemoryKeyStore()).WithPersonServer(person) + .WithEgressPolicy(policy).EnrolAsync(cancellationToken); + if (!protectedChannel) return (enrolled.AgentId!, enrolled.AgentToken!, publicSubscriptionUrl); + using var agent = new AAuthClientBuilder(key).UseJwt(enrolled.AgentToken!) + .WithEgressPolicy(policy).WithChallengeHandling(person, + options => options.OnInteractionRequired = showConsent).Build(); + using var request = new HttpRequestMessage(HttpMethod.Get, + resource + "/search_availability?account=" + Uri.EscapeDataString(account)); + request.Options.Set(AAuthRequestOptions.Account, account); + using var response = await agent.SendAsync(request, cancellationToken); + response.EnsureSuccessStatusCode(); + var result = await response.Content.ReadFromJsonAsync(cancellationToken); + return (enrolled.AgentId!, enrolled.AgentToken!, result!["notifications"]!["subscribe_url"]!.GetValue()); + } + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string Delivery = """ + public static async Task TriggerSampleEventAsync(EventsProtocol protocol, string resource, + string eid, IAAuthSigner agentKey, string agentToken, string? account, CancellationToken cancellationToken) + { + using var response = await protocol.SendAsync(HttpMethod.Post, + new Uri(resource + "/local/events/" + eid + "/notify" + + (account is null ? "" : "?account=" + Uri.EscapeDataString(account))), agentKey, agentToken, + selfIssued: false, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + } + + public static async Task DeliverResourceEventAsync(EventsProtocol protocol, string resource, + string provider, string agent, string eid, IAAuthSigner resourceKey, string resourceKid, + byte[] payload, CancellationToken cancellationToken) + { + var token = await new EventTokenBuilder + { + Issuer = resource, Audience = agent, Eid = eid, Key = resourceKey, + KeyId = resourceKid, Verifier = protocol.TokenVerifier, + }.BuildAsync(cancellationToken); + var endpoint = await protocol.ResolveEventEndpointAsync(provider, cancellationToken); + using var response = await protocol.SendAsync(HttpMethod.Post, endpoint, + resourceKey, token, selfIssued: true, body: payload, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + } + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string Discover = """ + public static async Task DiscoverChannelsAsync(HttpClient http, + EventsProtocol protocol, string resource, string provider, CancellationToken cancellationToken) + { + using var metadata = new MetadataClient(http); + var resourceMetadata = await metadata.FetchAsync( + new Uri(resource + "/.well-known/aauth-resource.json"), cancellationToken); + var documentUrl = resourceMetadata["r3_vocabularies"]!["urn:aauth:vocabulary:asyncapi"]!.GetValue(); + var channels = await http.GetFromJsonAsync( + new Uri(new Uri(resource), documentUrl), cancellationToken); + _ = await protocol.ResolveEventEndpointAsync(provider, cancellationToken); + return channels!; + } + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string Example = """ + builder.Services.AddAAuthEvents(options => options.EgressPolicy = egressPolicy); + // AP endpoint requires a durable transactional quota/outbox store. + builder.Services.AddSingleton(providerStore); + var app = builder.Build(); + var protocol = app.Services.GetRequiredService(); + + // Public registration uses an AsyncAPI channel URL; protected + // registration uses the ticket from an authorized Bookings response. + using var registration = await protocol.SendAsync(HttpMethod.Post, + subscriptionUrl, agentKey, subscribeToken, selfIssued: false, + body: subscriptionParameters); + + // Resource signs both JWT and HTTP with the same discoverable key. + var eventToken = await new EventTokenBuilder + { + Issuer = resource, Audience = agent, Eid = subscription.Eid, + Key = resourceKey, KeyId = resourceKid, + Verifier = protocol.TokenVerifier + }.BuildAsync(); + var endpoint = await protocol.ResolveEventEndpointAsync(subscription.Provider); + using var delivery = await protocol.SendAsync(HttpMethod.Post, + endpoint, resourceKey, eventToken, selfIssued: true, body: payloadBytes); + + // The AP event endpoint resolves the protocol and store from DI. + app.MapAAuthEventEndpoint("/events"); + + // Agent verifies the issuer JWT and context before persisting receipt. + var receiver = new EventReceiver(protocol, agentStore, agent); + var firstReceipt = await receiver.ReceiveAsync(eventToken, payloadBytes); + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string Receipt = """ + public static async Task VerifyInboxAsync(EventsProtocol protocol, IAgentEventStore store, + string provider, string agent, string eid, IAAuthSigner key, string agentToken, + CancellationToken cancellationToken) + { + using var response = await protocol.SendAsync(HttpMethod.Get, + new Uri(provider + "/local/events/inbox"), key, agentToken, + selfIssued: false, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + var pending = (await response.Content.ReadFromJsonAsync(cancellationToken))!; + var item = pending.Single(delivery => delivery.Event.Eid == eid); + var receiver = new EventReceiver(protocol, store, agent); + await receiver.ReceiveAsync(item.Event.Token, item.Event.Body, cancellationToken); + var duplicate = await receiver.ReceiveAsync(item.Event.Token, item.Event.Body, cancellationToken); + if (duplicate) throw new InvalidOperationException("Duplicate event was not suppressed."); + using var acknowledged = await protocol.SendAsync(HttpMethod.Post, + new Uri(provider + "/local/events/inbox/" + item.Receipt + "/ack"), key, agentToken, + selfIssued: false, cancellationToken: cancellationToken); + acknowledged.EnsureSuccessStatusCode(); + } + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string Registration = """ + public static async Task RegisterSubscriptionAsync(EventsProtocol protocol, + Uri subscriptionUrl, IAAuthSigner key, string subscribeToken, CancellationToken cancellationToken) + { + using var response = await protocol.SendAsync(HttpMethod.Post, subscriptionUrl, + key, subscribeToken, selfIssued: false, + body: "{\"event_types\":[\"reservation.available\"]}"u8.ToArray(), + cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + } + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string SubscribeToken = """ + public static async Task AcquireSubscribeTokenAsync(EventsProtocol protocol, + IAgentEventStore store, IAAuthSigner key, string agentToken, string agent, + string provider, string resource, string context, CancellationToken cancellationToken) + { + var body = System.Text.Encoding.UTF8.GetBytes(new JsonObject + { ["resource"] = resource, ["max_uses"] = 1 }.ToJsonString()); + using var response = await protocol.SendAsync(HttpMethod.Post, + new Uri(provider + "/local/events/subscribe"), key, agentToken, + selfIssued: false, body: body, cancellationToken: cancellationToken); + response.EnsureSuccessStatusCode(); + var result = (await response.Content.ReadFromJsonAsync(cancellationToken))!; + store.Remember(new(result["eid"]!.GetValue(), resource, agent, context)); + return result; + } + """ ; ++ AAuth.Samples.Events.EventDemoCode: public const string SubscriptionUrl = """ + public static async Task<(string Agent, string AgentToken, string SubscriptionUrl)> ObtainSubscriptionUrlAsync( + IAAuthAgentFactory agents, AAuthKey key, + string provider, string person, string resource, string account, bool protectedChannel, + string publicSubscriptionUrl, AAuthEgressPolicy policy, + Func showConsent, CancellationToken cancellationToken) + { + var enrolled = await AAuthClientBuilder.Bootstrap(provider + "/enrol") + .WithKey(key).WithKeyStore(new InMemoryKeyStore()).WithPersonServer(person) + .WithEgressPolicy(policy).EnrolAsync(cancellationToken); + if (!protectedChannel) return (enrolled.AgentId!, enrolled.AgentToken!, publicSubscriptionUrl); + // One agent for the enrolled identity, created once and reused for the session. + using var agent = agents.Create("event-agent", key, builder => builder.UseJwt(enrolled.AgentToken!) + .WithEgressPolicy(policy).WithChallengeHandling(person, + options => options.OnInteractionRequired = showConsent)); + using var request = new HttpRequestMessage(HttpMethod.Get, + resource + "/search_availability?account=" + Uri.EscapeDataString(account)); + request.Options.Set(AAuthRequestOptions.Account, account); + using var response = await agent.HttpClient.SendAsync(request, cancellationToken); + response.EnsureSuccessStatusCode(); + var result = await response.Content.ReadFromJsonAsync(cancellationToken); + return (enrolled.AgentId!, enrolled.AgentToken!, result!["notifications"]!["subscribe_url"]!.GetValue()); + } + """ ; +``` + +Public owners: `AAuth.Samples.Events.EventDemoCode`, `AAuth.Samples.Events`. + +### samples/EventSupport/EventDemoSession.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [EventDemoSession.cs](../../../samples/EventSupport/EventDemoSession.cs). + +```diff +- AAuth.Samples.Events.EventDemoSession: public EventDemoSession ( string directory , string provider = "http://localhost:5301" , string resource = "http://localhost:5005" , string person = "http://localhost:5100" , HttpClient ? http = null ) +- AAuth.Samples.Events.EventDemoSession: public string ? ConsentUrl { get ; private set ; } ++ AAuth.Samples.Events.EventDemoSession: public AAuth . Headers . Interaction ? Consent { get ; private set ; } ++ AAuth.Samples.Events.EventDemoSession: public EventDemoSession ( IAAuthAgentFactory agents , string directory , string provider = "http://localhost:5301" , string resource = "http://localhost:5005" , string person = "http://localhost:5100" , HttpClient ? http = null ) ++ AAuth.Samples.Events.EventDemoSession: public string ? ConsentUrl +``` + +Public owners: `AAuth.Samples.Events.EventDemoSession`, `AAuth.Samples.Events`. + +### samples/EventSupport/LocalEventProvider.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [LocalEventProvider.cs](../../../samples/EventSupport/LocalEventProvider.cs). + +```diff +- AAuth.Samples.Events.LocalEventProvider: public static void MapLocalEventProvider ( this IEndpointRouteBuilder routes , string issuer , IAAuthKey key , string keyId , EventsProtocol protocol , IAgentProviderEventStore store ) ++ AAuth.Samples.Events.LocalEventProvider: public static void MapLocalEventProvider ( this IEndpointRouteBuilder routes , string issuer , IAAuthSigner key , string keyId ) +``` + +Public owners: `AAuth.Samples.Events.LocalEventProvider`, `AAuth.Samples.Events`. + +### samples/EventSupport/SampleAgentEnrollment.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [SampleAgentEnrollment.cs](../../../samples/EventSupport/SampleAgentEnrollment.cs). + +```diff +- AAuth.Samples.Events.SampleAgentEnrollment: public static void MapSampleAgentEnrollment ( this IEndpointRouteBuilder routes , string issuer , IAAuthKey key , string keyId , AAuthEgressPolicy policy , SampleAgentRegistry registry ) ++ AAuth.Samples.Events.SampleAgentEnrollment: public static void MapSampleAgentEnrollment ( this IEndpointRouteBuilder routes , string issuer , IAAuthSigner key , string keyId , AAuthEgressPolicy policy , SampleAgentRegistry registry ) +``` + +Public owners: `AAuth.Samples.Events.SampleAgentEnrollment`, `AAuth.Samples.Events`. + +### samples/EventSupport/SqliteEventStore.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [SqliteEventStore.cs](../../../samples/EventSupport/SqliteEventStore.cs). + +```diff +- AAuth.Samples.Events.SqliteEventStore: public EventEnvelope PrepareDelivery ( string provider , string eid , Func < EventEnvelope > create ) ++ AAuth.Samples.Events.SqliteEventStore: public async Task < EventEnvelope > PrepareDeliveryAsync ( string provider , string eid , Func < Task < EventEnvelope > > create ) +``` + +Public owners: `AAuth.Samples.Events.SqliteEventStore`, `AAuth.Samples.Events`. + +### samples/FederatedWorkerScenario.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [FederatedWorkerScenario.cs](../../../samples/FederatedWorkerScenario.cs). + +```diff +- AAuth.Samples.FederatedWorkerScenario: public void IssueParent ( ) +- AAuth.Samples.FederatedWorkerScenario: public void IssueWorker ( ) +- AAuth.Samples: public sealed class FederatedWorkerScenario ( IAAuthKey providerKey , string providerKid , string provider , string personServer , string wallet ) : IDisposable ++ AAuth.Samples.FederatedWorkerScenario: public async Task IssueParentAsync ( CancellationToken ct = default ) ++ AAuth.Samples.FederatedWorkerScenario: public async Task IssueWorkerAsync ( CancellationToken ct = default ) ++ AAuth.Samples.FederatedWorkerScenario: public async Task ObtainWorkerPersonTokenAsync ( CancellationToken ct = default ) ++ AAuth.Samples.FederatedWorkerScenario: public async Task PresentWorkerPersonTokenAsync ( CancellationToken ct = default ) ++ AAuth.Samples.FederatedWorkerScenario: public string ? WorkerPersonToken { get ; private set ; } ++ AAuth.Samples: public sealed class FederatedWorkerScenario ( IAAuthSigner providerKey , string providerKid , string provider , string personServer , string wallet ) : IDisposable +``` + +Public owners: `AAuth.Samples.FederatedWorkerScenario`, `AAuth.Samples`. + +### samples/GuidedTour/CapturingMessageHandler.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [CapturingMessageHandler.cs](../../../samples/GuidedTour/CapturingMessageHandler.cs). + +```diff +- GuidedTour: public sealed record CapturedExchange ( string RequestLine , string RequestHeaders , string ? RequestBody , string StatusLine , string ResponseHeaders , string ResponseBody ) ++ GuidedTour: public sealed record CapturedExchange ( string RequestLine , string RequestHeaders , string RawRequestHeaders , string ? RequestBody , string StatusLine , string ResponseHeaders , string RawResponseHeaders , string ResponseBody , string RawResponseBody ) +``` + +Public owners: `GuidedTour.CapturingMessageHandler`, `GuidedTour`. + +### samples/GuidedTour/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/GuidedTour/Program.cs). + +Public signatures unchanged (2); behavior reviewed under sample-runtime. + +Public owners: `GuidedTour`. + +### samples/GuidedTour/StepRecord.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [StepRecord.cs](../../../samples/GuidedTour/StepRecord.cs). + +Public signatures unchanged (34); behavior reviewed under sample-runtime. + +Public owners: `GuidedTour.Actor`, `GuidedTour.StepRecord`, `GuidedTour`. + +### samples/GuidedTour/TourOptions.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [TourOptions.cs](../../../samples/GuidedTour/TourOptions.cs). + +```diff ++ GuidedTour.TourMode: Catalog ++ GuidedTour.TourMode: Documents ++ GuidedTour.TourMode: Events ++ GuidedTour.TourMode: WalletProtocol ++ GuidedTour.TourOptions: public bool ShowSensitiveProtocolArtifacts { get ; set ; } ++ GuidedTour.TourOptions: public string CatalogUrl { get ; set ; } = "http://localhost:5006" ++ GuidedTour.TourOptions: public string DocumentsUrl { get ; set ; } = "http://localhost:5007" +``` + +Public owners: `GuidedTour.SigningMode`, `GuidedTour.TourMode`, `GuidedTour.TourOptions`, `GuidedTour`. + +### samples/GuidedTour/TourSession.Capabilities.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [TourSession.Capabilities.cs](../../../samples/GuidedTour/TourSession.Capabilities.cs). + +```diff ++ GuidedTour.TourSession: public WalletFlow WalletScenario { get ; set ; } ++ GuidedTour.TourSession: public bool EventsProtected { get ; set ; } ++ GuidedTour.TourSession: public bool IsCapabilityMode ++ GuidedTour.TourSession: public bool IsCatalogMode ++ GuidedTour.TourSession: public bool IsDocumentsMode ++ GuidedTour.TourSession: public bool IsEventsMode ++ GuidedTour.TourSession: public bool IsWalletProtocolMode ++ GuidedTour.TourSession: public string ? EventsPayload { get ; private set ; } ++ GuidedTour.TourSession: public string CatalogService { get ; set ; } ++ GuidedTour.TourSession: public string EventsAccount { get ; set ; } ++ GuidedTour: public sealed partial class TourSession +``` + +Public owners: `GuidedTour.TourSession`, `GuidedTour`. + +### samples/GuidedTour/TourSession.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [TourSession.cs](../../../samples/GuidedTour/TourSession.cs). + +```diff +- GuidedTour.TourSession: public Task RecordUserApprovalOpenedAsync ( CancellationToken ct = default ) +- GuidedTour.TourSession: public bool CanSwitchMode +- GuidedTour.TourSession: public string ? WorkerConsentUrl { get ; private set ; } +- GuidedTour: public sealed class TourSession : IAsyncDisposable ++ GuidedTour.TourSession: public Interaction ? ConsentInteraction ++ GuidedTour.TourSession: public Interaction ? CurrentInteraction ++ GuidedTour.TourSession: public Interaction ? WorkerConsent { get ; private set ; } ++ GuidedTour.TourSession: public bool ConsentDecidedAtPersonServer ++ GuidedTour.TourSession: public bool IsPersonServerConsent ++ GuidedTour.TourSession: public string ? PersonServer ++ GuidedTour.TourSession: public string ? WorkerConsentUrl ++ GuidedTour: public sealed partial class TourSession : IAsyncDisposable +``` + +Public owners: `GuidedTour.TourSession`, `GuidedTour`. + +### samples/LiveWhoAmITest/LiveInteropValidation.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [LiveInteropValidation.cs](../../../samples/LiveWhoAmITest/LiveInteropValidation.cs). + +Public signatures unchanged (5); behavior reviewed under sample-runtime. + +Public owners: `LiveWhoAmITest.LiveInteropValidation`, `LiveWhoAmITest`. + +### samples/MockAccessServers/Federated/Policy/KeycloakAccessPolicy.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [KeycloakAccessPolicy.cs](../../../samples/MockAccessServers/Federated/Policy/KeycloakAccessPolicy.cs). + +Public signatures unchanged (5); behavior reviewed under sample-runtime. + +Public owners: `MockAccessServer.Policy.KeycloakAccessPolicy`, `MockAccessServer.Policy`. + +### samples/MockAccessServers/Federated/Policy/WalletPolicyRules.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [WalletPolicyRules.cs](../../../samples/MockAccessServers/Federated/Policy/WalletPolicyRules.cs). + +Public signatures unchanged (3); behavior reviewed under sample-runtime. + +Public owners: `MockAccessServer.Policy.WalletPolicyRules`, `MockAccessServer.Policy`. + +### samples/MockAccessServers/Federated/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockAccessServers/Federated/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Federated`. + +### samples/MockAccessServers/R3/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockAccessServers/R3/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `R3AccessServer`. + +### samples/MockAccessServers/R3/SqliteR3AuditSink.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [SqliteR3AuditSink.cs](../../../samples/MockAccessServers/R3/SqliteR3AuditSink.cs). + +Public signatures unchanged (4); behavior reviewed under sample-runtime. + +Public owners: `R3AccessServer.SqliteR3AuditSink`, `R3AccessServer`. + +### samples/MockAgentProvider/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockAgentProvider/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `MockAgentProvider`. + +### samples/MockPersonServer/ConsentBridgePersonPendingStore.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [ConsentBridgePersonPendingStore.cs](../../../samples/MockPersonServer/ConsentBridgePersonPendingStore.cs). + +```diff +- MockPersonServer.ConsentBridgePersonPendingStore: public ConsentBridgePersonPendingStore ( ConsentStore consent , IReadOnlyList < string > demoRoles , IReadOnlyList < string > demoGroups ) +- MockPersonServer.ConsentBridgePersonPendingStore: public PersonPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey ? agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? upstreamAct = null , MissionClaim ? mission = null , DateTimeOffset ? authorizationExpiresAt = null ) +- MockPersonServer.ConsentBridgePersonPendingStore: public void MarkAllowed ( string id , string subject , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) ++ MockPersonServer.ConsentBridgePersonPendingStore: public ConsentBridgePersonPendingStore ( ConsentStore consent , ConsentRegistry registry , IReadOnlyList < string > demoRoles , IReadOnlyList < string > demoGroups ) ++ MockPersonServer.ConsentBridgePersonPendingStore: public PersonPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey ? agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , string ? missionS256 = null , DateTimeOffset ? authorizationExpiresAt = null ) ++ MockPersonServer.ConsentBridgePersonPendingStore: public void MarkAllowed ( string id , AAuthPersonKey personKey , string ? subject = null , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) +``` + +Public owners: `MockPersonServer.ConsentBridgePersonPendingStore`, `MockPersonServer`. + +### samples/MockPersonServer/ConsentDashboard.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [ConsentDashboard.cs](../../../samples/MockPersonServer/ConsentDashboard.cs). + +```diff ++ MockPersonServer.ConsentDashboard: public static void MapConsentDashboard ( this WebApplication app ) ++ MockPersonServer.ConsentDashboardSessions.Session: public DateTimeOffset ExpiresAt { get ; } = DateTimeOffset . UtcNow . AddHours ( 8 ) ++ MockPersonServer.ConsentDashboardSessions.Session: public string ? Person { get ; set ; } ++ MockPersonServer.ConsentDashboardSessions.Session: public string Csrf { get ; } = Secret ( ) ++ MockPersonServer.ConsentDashboardSessions: public IResult ? Refusal ( HttpContext context ) ++ MockPersonServer.ConsentDashboardSessions: public Session Current ( HttpContext context , bool create ) ++ MockPersonServer.ConsentDashboardSessions: public const string CookieName = "AAuth.Person.Dashboard" ; ++ MockPersonServer.ConsentDashboardSessions: public const string CsrfHeader = "X-CSRF-Token" ; ++ MockPersonServer.ConsentDashboardSessions: public sealed class Session ++ MockPersonServer.ConsentDashboardSessions: public static IResult Problem ( string error , string ? detail , int status ) ++ MockPersonServer.ConsentDashboardSessions: public static bool CsrfMatches ( Session session , string ? supplied ) ++ MockPersonServer.ConsentDashboardSessions: public string ? DemoIdentity { get ; } = configuration . GetValue < bool > ( "AAuth:EnableIsolatedDemoConsent" ) ? "isolated-person-demo" : null ++ MockPersonServer: public sealed class ConsentDashboardSessions ( IConfiguration configuration ) ++ MockPersonServer: public static class ConsentDashboard +``` + +Public owners: `MockPersonServer.ConsentDashboardSessions.Session`, `MockPersonServer.ConsentDashboardSessions`, `MockPersonServer.ConsentDashboard`, `MockPersonServer`. + +### samples/MockPersonServer/ConsentRegistry.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [ConsentRegistry.cs](../../../samples/MockPersonServer/ConsentRegistry.cs). + +```diff ++ MockPersonServer.ConsentDecider: Admin ++ MockPersonServer.ConsentDecider: Dashboard ++ MockPersonServer.ConsentDecider: Link ++ MockPersonServer.ConsentDecider: Policy ++ MockPersonServer.ConsentDecider: Script ++ MockPersonServer.ConsentKind: AccessServerInteraction ++ MockPersonServer.ConsentKind: FederatedConsent ++ MockPersonServer.ConsentKind: MissionCreation ++ MockPersonServer.ConsentKind: MissionToken ++ MockPersonServer.ConsentKind: Permission ++ MockPersonServer.ConsentKind: PersonToken ++ MockPersonServer.ConsentKind: Token ++ MockPersonServer.ConsentRecord: public BrowserInteraction Browser ++ MockPersonServer.ConsentRecord: public ConsentDecider ? DecidedBy { get ; private set ; } ++ MockPersonServer.ConsentRecord: public ConsentDecider ? Decider ++ MockPersonServer.ConsentRecord: public ConsentKind Kind ++ MockPersonServer.ConsentRecord: public ConsentStatus Status { get ; } ++ MockPersonServer.ConsentRecord: public DateTimeOffset ? DecidedAt { get ; private set ; } ++ MockPersonServer.ConsentRecord: public DateTimeOffset CreatedAt { get ; } ++ MockPersonServer.ConsentRecord: public DateTimeOffset ExpiresAt ++ MockPersonServer.ConsentRecord: public DeferredState Lifecycle ++ MockPersonServer.ConsentRecord: public IReadOnlyList < string > ProposedTools ++ MockPersonServer.ConsentRecord: public MissionPendingEntry ? MissionEntry { get ; } ++ MockPersonServer.ConsentRecord: public PersonPendingEntry ? PersonEntry { get ; } ++ MockPersonServer.ConsentRecord: public bool IsDecidable ++ MockPersonServer.ConsentRecord: public bool IsListed ++ MockPersonServer.ConsentRecord: public string ? Account ++ MockPersonServer.ConsentRecord: public string ? Action ++ MockPersonServer.ConsentRecord: public string ? ExternalInteractionUrl ++ MockPersonServer.ConsentRecord: public string ? MissionDescription ++ MockPersonServer.ConsentRecord: public string ? MissionS256 ++ MockPersonServer.ConsentRecord: public string ? Resource ++ MockPersonServer.ConsentRecord: public string ? Scope ++ MockPersonServer.ConsentRecord: public string AgentId ++ MockPersonServer.ConsentRecord: public string Id ++ MockPersonServer.ConsentRegistry: public ConsentRecord ? Find ( string id ) ++ MockPersonServer.ConsentRegistry: public ConsentRecord ? FindByCode ( string code ) ++ MockPersonServer.ConsentRegistry: public ConsentRecord ? FindPendingByCode ( string code ) ++ MockPersonServer.ConsentRegistry: public IReadOnlyList < ConsentRecord > Snapshot ( ) ++ MockPersonServer.ConsentRegistry: public const int Capacity = 500 ; ++ MockPersonServer.ConsentRegistry: public void DropPending ( ) ++ MockPersonServer.ConsentRegistry: public void MarkDecided ( string id , ConsentDecider by ) ++ MockPersonServer.ConsentRegistry: public void OnParked ( PersonPendingEntry entry ) ++ MockPersonServer.ConsentRegistry: public void Register ( MissionPendingEntry entry ) ++ MockPersonServer.ConsentRegistry: public void Register ( PersonPendingEntry entry ) ++ MockPersonServer.ConsentStatus: Approved ++ MockPersonServer.ConsentStatus: Delivered ++ MockPersonServer.ConsentStatus: Denied ++ MockPersonServer.ConsentStatus: Expired ++ MockPersonServer.ConsentStatus: Pending ++ MockPersonServer.ConsentStatus: Withdrawn ++ MockPersonServer: public enum ConsentDecider ++ MockPersonServer: public enum ConsentKind ++ MockPersonServer: public enum ConsentStatus ++ MockPersonServer: public sealed class ConsentRecord ++ MockPersonServer: public sealed class ConsentRegistry ( MissionPolicyStore policy ) : IPersonPendingObserver +``` + +Public owners: `MockPersonServer.ConsentDecider`, `MockPersonServer.ConsentKind`, `MockPersonServer.ConsentRecord`, `MockPersonServer.ConsentRegistry`, `MockPersonServer.ConsentStatus`, `MockPersonServer`. + +### samples/MockPersonServer/MissionGovernance.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [MissionGovernance.cs](../../../samples/MockPersonServer/MissionGovernance.cs). + +```diff +- MockPersonServer.MissionPendingEntry: public DateTimeOffset ExpiresAt { get ; } = DateTimeOffset . UtcNow . AddMinutes ( 10 ) +- MockPersonServer.MissionPendingEntry: public JsonObject ? UpstreamAct { get ; init ; } +- MockPersonServer.MissionPendingEntry: public MissionClaim MissionClaim +- MockPersonServer.MissionPendingEntry: public required string Approver { get ; init ; } +- MockPersonServer.MissionPendingEntry: public required string S256 { get ; init ; } +- MockPersonServer: public sealed class MissionPendingStore ++ MockPersonServer.MissionPendingEntry: public DateTimeOffset CreatedAt { get ; } = DateTimeOffset . UtcNow ++ MockPersonServer.MissionPendingEntry: public DateTimeOffset ExpiresAt ++ MockPersonServer.MissionPendingEntry: public required string PersonServer { get ; init ; } ++ MockPersonServer.MissionPendingEntry: public required string S256 { get ; set ; } ++ MockPersonServer: public sealed class MissionPendingStore ( ConsentRegistry registry ) +``` + +Public owners: `MockPersonServer.MissionConsentScript`, `MockPersonServer.MissionPendingEntry`, `MockPersonServer.MissionPendingKind`, `MockPersonServer.MissionPendingState`, `MockPersonServer.MissionPendingStore`, `MockPersonServer.MissionPolicyStore`, `MockPersonServer.SampleAuditSink`, `MockPersonServer.SampleInteractionRelay`, `MockPersonServer.SamplePermissionDecider`, `MockPersonServer`. + +### samples/MockPersonServer/PersonConsentDecisions.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [PersonConsentDecisions.cs](../../../samples/MockPersonServer/PersonConsentDecisions.cs). + +```diff ++ MockPersonServer.ConsentOutcome: AlreadyDecided ++ MockPersonServer.ConsentOutcome: Applied ++ MockPersonServer.ConsentOutcome: Expired ++ MockPersonServer.ConsentOutcome: NotDecidable ++ MockPersonServer.ConsentOutcome: Refused ++ MockPersonServer.ConsentOutcome: Unknown ++ MockPersonServer.PersonConsentDecisions: public ConsentOutcome ApplyHeld ( MissionPendingEntry entry , bool approve , ConsentDecider by ) ++ MockPersonServer.PersonConsentDecisions: public async Task < ConsentOutcome > ApplyHeldAsync ( PersonPendingEntry entry , bool approve , ConsentDecider by , CancellationToken cancellationToken ) ++ MockPersonServer.PersonConsentDecisions: public async Task < ConsentOutcome > DecideAsync ( string id , bool approve , ConsentDecider by , CancellationToken cancellationToken ) ++ MockPersonServer: public enum ConsentOutcome ++ MockPersonServer: public sealed class PersonConsentDecisions ( ConsentStore consent , [ FromKeyedServices ( AAuthPersonServerBuilder . DefaultName ) ] IIdentityClaimsAsserter asserter , ConsentRegistry registry ) +``` + +Public owners: `MockPersonServer.ConsentOutcome`, `MockPersonServer.PersonConsentDecisions`, `MockPersonServer`. + +### samples/MockPersonServer/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockPersonServer/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `MockPersonServer`. + +### samples/MockPersonServer/SampleIdentityClaimsAsserter.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [SampleIdentityClaimsAsserter.cs](../../../samples/MockPersonServer/SampleIdentityClaimsAsserter.cs). + +```diff +- MockPersonServer.SampleIdentityClaimsAsserter: public static bool IsAdminAgent ( string agentId ) ++ MockPersonServer.SampleIdentityClaimsAsserter: public static IReadOnlySet < ( string Issuer , string AgentId ) > AdminAgents { get ; } = new HashSet < ( string , string ) > { ( "https://ap.example" , "aauth:demo@ap.example" ) } ++ MockPersonServer.SampleIdentityClaimsAsserter: public static bool IsAdminAgent ( string agentIssuer , string agentId ) ++ MockPersonServer.SampleIdentityClaimsAsserter: public static readonly AAuthPersonKey DemoPersonKey = new ( "isolated-demo-person" ) ; +``` + +Public owners: `MockPersonServer.SampleIdentityClaimsAsserter`, `MockPersonServer`. + +### samples/MockPersonServer/ScriptMissionTokenConsent.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [ScriptMissionTokenConsent.cs](../../../samples/MockPersonServer/ScriptMissionTokenConsent.cs). + +Public signatures unchanged (3); behavior reviewed under sample-runtime. + +Public owners: `MockPersonServer.ScriptMissionTokenConsent`, `MockPersonServer`. + +### samples/MockResourceServers/Bookings/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Bookings/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Bookings`. + +### samples/MockResourceServers/Calendar/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Calendar/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Calendar`. + +### samples/MockResourceServers/Catalog/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Catalog/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Catalog`. + +### samples/MockResourceServers/Inbox/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Inbox/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Inbox`. + +### samples/MockResourceServers/Profile/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Profile/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Profile`. + +### samples/MockResourceServers/Trips/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Trips/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Trips`. + +### samples/MockResourceServers/Wallet/Program.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [Program.cs](../../../samples/MockResourceServers/Wallet/Program.cs). + +Public signatures unchanged (1); behavior reviewed under sample-runtime. + +Public owners: `Wallet`. + +### samples/SampleApp/EnrollmentService.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [EnrollmentService.cs](../../../samples/SampleApp/EnrollmentService.cs). + +```diff +- SampleApp.EnrollmentService: public EnrollmentService ( IConfiguration config ) +- SampleApp.EnrollmentService: public IAAuthKey Key +- SampleApp: public sealed class EnrollmentService ++ SampleApp.EnrollmentService: public AAuthAgent Agent ++ SampleApp.EnrollmentService: public EnrollmentService ( IConfiguration config , SampleAgents agents , IAAuthAgentFactory factory ) ++ SampleApp.EnrollmentService: public IAAuthSigner Key ++ SampleApp.EnrollmentService: public void Dispose ( ) ++ SampleApp.EnrollmentService: public void StartOver ( string resource ) ++ SampleApp: public sealed class EnrollmentService : IDisposable +``` + +Public owners: `SampleApp.EnrollmentService`, `SampleApp`. + +### samples/SampleApp/SampleAgents.cs + +Concept/decision: [sample-runtime](#sample-runtime). Source: [SampleAgents.cs](../../../samples/SampleApp/SampleAgents.cs). + +```diff ++ SampleApp.SampleAgents: public DeferredPollerOptions PollerOptions { get ; } ++ SampleApp.SampleAgents: public HttpClient AriaClient ++ SampleApp.SampleAgents: public const string Aria = "aria" ; ++ SampleApp.SampleAgents: public string PersonServer ++ SampleApp.SampleAgents: public void StartOver ( ) ++ SampleApp: public sealed class SampleAgents ( IHttpClientFactory clients , IOptionsMonitor < AAuthAgentOptions > options , IServiceProvider services ) +``` + +Public owners: `SampleApp.SampleAgents`, `SampleApp`. + +### src/AAuth.Events/EventReceiver.cs + +Concept/decision: [events](#events). Source: [EventReceiver.cs](../../../src/AAuth.Events/EventReceiver.cs). + +Public signatures unchanged (2); behavior reviewed under events. + +Public owners: `AAuth.Events.EventReceiver`, `AAuth.Events`. + +### src/AAuth.Events/EventStores.cs + +Concept/decision: [events](#events). Source: [EventStores.cs](../../../src/AAuth.Events/EventStores.cs). + +```diff +- AAuth.Events: public sealed record EventAcceptance ( int StatusCode , long ? RemainingUses = null ) +- AAuth.Events: public sealed record EventEnvelope ( string Token , string Eid , string Issuer , string Agent , DateTimeOffset ExpiresAt , byte [ ] Body ) +- AAuth.Events: public sealed record ResourceSubscription ( string Eid , string Provider , string Agent , string Operation , string ? Account , string State , DateTimeOffset ExpiresAt ) +- AAuth.Events: public sealed record SubscriptionTicket ( string Ticket , string Agent , string Operation , string ? Account , string State , DateTimeOffset ExpiresAt ) ++ AAuth.Events.EventAcceptanceOutcome: Accepted ++ AAuth.Events.EventAcceptanceOutcome: Duplicate ++ AAuth.Events.EventAcceptanceOutcome: Exhausted ++ AAuth.Events.EventAcceptanceOutcome: Expired ++ AAuth.Events.EventAcceptanceOutcome: Forbidden ++ AAuth.Events.EventAcceptanceOutcome: Unknown ++ AAuth.Events: public enum EventAcceptanceOutcome ++ AAuth.Events: public sealed record EventAcceptance ( EventAcceptanceOutcome Outcome , long ? RemainingUses = null ) ++ AAuth.Events: public sealed record EventEnvelope ( string Token , string Eid , string Jti , string Issuer , string Agent , DateTimeOffset ExpiresAt , byte [ ] Body ) ++ AAuth.Events: public sealed record ResourceSubscription ( string Eid , string Provider , string Agent , string Operation , string ? Account , string State , DateTimeOffset ExpiresAt , string ? KeyThumbprint = null ) ++ AAuth.Events: public sealed record SubscriptionTicket ( string Ticket , string KeyThumbprint , string Operation , string ? Account , string State , DateTimeOffset ExpiresAt ) +``` + +Public owners: `AAuth.Events.EventAcceptanceOutcome`, `AAuth.Events.IAgentEventStore`, `AAuth.Events.IAgentProviderEventStore`, `AAuth.Events.IResourceEventStore`, `AAuth.Events`. + +### src/AAuth.Events/EventTokenBuilders.cs + +Concept/decision: [events](#events). Source: [EventTokenBuilders.cs](../../../src/AAuth.Events/EventTokenBuilders.cs). + +```diff +- AAuth.Events.EventTokenBuilder: public required IAAuthKey Key { get ; init ; } +- AAuth.Events.EventTokenBuilder: public string Build ( ) +- AAuth.Events.SubscribeTokenBuilder: public required IAAuthKey Key { get ; init ; } +- AAuth.Events.SubscribeTokenBuilder: public string Build ( ) ++ AAuth.Events.EventTokenBuilder: public ValueTask < string > BuildAsync ( CancellationToken cancellationToken = default ) ++ AAuth.Events.EventTokenBuilder: public required IAAuthSigner Key { get ; init ; } ++ AAuth.Events.EventTokenBuilder: public string Jti { get ; init ; } = Guid . NewGuid ( ) . ToString ( "N" ) ++ AAuth.Events.SubscribeTokenBuilder: public ValueTask < string > BuildAsync ( CancellationToken cancellationToken = default ) ++ AAuth.Events.SubscribeTokenBuilder: public required IAAuthSigner Key { get ; init ; } +``` + +Public owners: `AAuth.Events.EventTokenBuilder`, `AAuth.Events.SubscribeTokenBuilder`, `AAuth.Events`. + +### src/AAuth.Events/EventsEndpoints.cs + +Concept/decision: [events](#events). Source: [EventsEndpoints.cs](../../../src/AAuth.Events/EventsEndpoints.cs). + +```diff +- AAuth.Events.EventsEndpoints: public static IEndpointConventionBuilder MapAAuthEventEndpoint ( this IEndpointRouteBuilder routes , string path , EventsProtocol protocol , IAgentProviderEventStore store ) +- AAuth.Events.EventsEndpoints: public static IEndpointConventionBuilder MapAAuthSubscriptionEndpoint ( this IEndpointRouteBuilder routes , string path , string resource , string operation , bool protectedChannel , EventsProtocol protocol , IResourceEventStore store , Func < JsonObject , bool > validateParameters , TimeSpan ? subscriptionLifetime = null ) ++ AAuth.Events.AAuthSubscriptionEndpointOptions: public Func < JsonObject , bool > ? ValidateParameters { get ; set ; } ++ AAuth.Events.AAuthSubscriptionEndpointOptions: public TimeSpan ? SubscriptionLifetime { get ; set ; } ++ AAuth.Events.AAuthSubscriptionEndpointOptions: public bool ProtectedChannel { get ; set ; } ++ AAuth.Events.AAuthSubscriptionEndpointOptions: public string ? Resource { get ; set ; } ++ AAuth.Events.AAuthSubscriptionEndpointOptions: public string Operation { get ; set ; } = "" ++ AAuth.Events.EventsEndpoints: public static IEndpointConventionBuilder MapAAuthEventEndpoint ( this IEndpointRouteBuilder routes , string path ) ++ AAuth.Events.EventsEndpoints: public static IEndpointConventionBuilder MapAAuthSubscriptionEndpoint ( this IEndpointRouteBuilder routes , string path , Action < AAuthSubscriptionEndpointOptions > configure ) ++ AAuth.Events: public sealed class AAuthSubscriptionEndpointOptions +``` + +Public owners: `AAuth.Events.AAuthSubscriptionEndpointOptions`, `AAuth.Events.EventsEndpoints`, `AAuth.Events`. + +### src/AAuth.Events/EventsProtocol.cs + +Concept/decision: [events](#events). Source: [EventsProtocol.cs](../../../src/AAuth.Events/EventsProtocol.cs). + +```diff +- AAuth.Events.EventsProtocol: public EventsProtocol ( HttpClient http , IEnumerable < ISignatureTokenVerifier > tokenVerifiers , Func < DateTimeOffset > ? clock = null ) +- AAuth.Events.EventsProtocol: public async Task < HttpResponseMessage > SendAsync ( HttpMethod method , Uri url , IAAuthKey key , string jwt , bool selfIssued , byte [ ] ? body = null , CancellationToken cancellationToken = default ) ++ AAuth.Events.EventsProtocol: public EventsProtocol ( HttpClient http , IEnumerable < ISignatureTokenVerifier > tokenVerifiers , TimeProvider ? timeProvider = null ) ++ AAuth.Events.EventsProtocol: public async Task < HttpResponseMessage > SendAsync ( HttpMethod method , Uri url , IAAuthSigner key , string jwt , bool selfIssued , byte [ ] ? body = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Events.EventsProtocol`, `AAuth.Events`. + +### src/AAuth.Events/EventsSignatureTokenVerifier.cs + +Concept/decision: [events](#events). Source: [EventsSignatureTokenVerifier.cs](../../../src/AAuth.Events/EventsSignatureTokenVerifier.cs). + +```diff +- AAuth.Events.EventsServiceExtensions: public static IServiceCollection AddAAuthEvents ( this IServiceCollection services ) +- AAuth.Events.EventsSignatureTokenVerifier: public Task < TokenVerifier . VerifiedToken > VerifyAsync ( string jwt , IAAuthKey issuerKey , TokenVerifier verifier , CancellationToken cancellationToken ) ++ AAuth.Events.AAuthEventsOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.Events.AAuthEventsOptions: public AAuth . Discovery . AAuthTransportContract ? TransportContract { get ; set ; } ++ AAuth.Events.AAuthEventsOptions: public HttpMessageHandler ? InnerHandler { get ; set ; } ++ AAuth.Events.AAuthEventsOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Events.EventsServiceExtensions: public static IServiceCollection AddAAuthEvents ( this IServiceCollection services , Action < AAuthEventsOptions > ? configure = null ) ++ AAuth.Events.EventsSignatureTokenVerifier: public Task < TokenVerifier . VerifiedToken > VerifyAsync ( SignatureTokenVerificationContext context , CancellationToken cancellationToken ) ++ AAuth.Events.EventsSignatureTokenVerifier: public ValueTask < IAAuthKey ? > ResolveIssuerKeyAsync ( SignatureTokenIssuerKeyContext context , CancellationToken cancellationToken ) ++ AAuth.Events: public sealed class AAuthEventsOptions +``` + +Public owners: `AAuth.Events.AAuthEventsOptions`, `AAuth.Events.EventsServiceExtensions`, `AAuth.Events.EventsSignatureTokenVerifier`, `AAuth.Events`. + +### src/AAuth.Events/EventsTokens.cs + +Concept/decision: [events](#events). Source: [EventsTokens.cs](../../../src/AAuth.Events/EventsTokens.cs). + +```diff +- AAuth.Events.EventsTokens: public static string Create ( IAAuthKey key , string keyId , JsonObject payload , bool subscribe , TokenVerifier ? verifier = null ) ++ AAuth.Events.EventsTokens: public static async ValueTask < string > CreateAsync ( IAAuthSigner key , string keyId , JsonObject payload , bool subscribe , TokenVerifier ? verifier = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Events.EventsTokens`, `AAuth.Events`. + +### src/AAuth.R3/Model/R3Document.cs + +Concept/decision: [r3](#r3). Source: [R3Document.cs](../../../src/AAuth.R3/Model/R3Document.cs). + +```diff +- AAuth.R3.Model.R3Document: [ JsonPropertyName ( "version" ) ] [ JsonPropertyOrder ( 1 ) ] [ JsonIgnore ( Condition = JsonIgnoreCondition . WhenWritingNull ) ] public string ? Version { get ; init ; } +``` + +Public owners: `AAuth.R3.Model.R3Document`, `AAuth.R3.Model`. + +### src/AAuth.R3/Model/R3Grant.cs + +Concept/decision: [r3](#r3). Source: [R3Grant.cs](../../../src/AAuth.R3/Model/R3Grant.cs). + +Public signatures unchanged (7); behavior reviewed under r3. + +Public owners: `AAuth.R3.Model.R3Grant`, `AAuth.R3.Model`. + +### src/AAuth.R3/Model/R3Operation.cs + +Concept/decision: [r3](#r3). Source: [R3Operation.cs](../../../src/AAuth.R3/Model/R3Operation.cs). + +```diff +- AAuth.R3.Model.R3Operation: public static R3Operation OpenApiGateway ( string service , string operationId ) +``` + +Public owners: `AAuth.R3.Model.R3OperationConverter`, `AAuth.R3.Model.R3Operation`, `AAuth.R3.Model`. + +### src/AAuth.R3/Model/R3Parameter.cs + +Concept/decision: [r3](#r3). Source: [R3Parameter.cs](../../../src/AAuth.R3/Model/R3Parameter.cs). + +Public signatures unchanged (15); behavior reviewed under r3. + +Public owners: `AAuth.R3.Model.R3Parameter`, `AAuth.R3.Model.R3PresentedParameters`, `AAuth.R3.Model`. + +### src/AAuth.R3/Model/R3ProposalDocument.cs + +Concept/decision: [r3](#r3). Source: [R3ProposalDocument.cs](../../../src/AAuth.R3/Model/R3ProposalDocument.cs). + +```diff +- AAuth.R3.Model.R3ProposalDocument: [ JsonPropertyName ( "version" ) ] [ JsonPropertyOrder ( 1 ) ] [ JsonIgnore ( Condition = JsonIgnoreCondition . WhenWritingNull ) ] public string ? Version { get ; init ; } +``` + +Public owners: `AAuth.R3.Model.R3ProposalDocument`, `AAuth.R3.Model`. + +### src/AAuth.R3/Model/R3VocabularySchemas.cs + +Concept/decision: [r3](#r3). Source: [R3VocabularySchemas.cs](../../../src/AAuth.R3/Model/R3VocabularySchemas.cs). + +Public signatures unchanged (8); behavior reviewed under r3. + +Public owners: `AAuth.R3.Model.R3VocabularySchemas`, `AAuth.R3.Model`. + +### src/AAuth.R3/Model/Vocabulary.cs + +Concept/decision: [r3](#r3). Source: [Vocabulary.cs](../../../src/AAuth.R3/Model/Vocabulary.cs). + +```diff +- AAuth.R3.Model.Vocabulary: public const string OpenApiGateway = "urn:aauth:vocabulary:openapi-gateway" ; +``` + +Public owners: `AAuth.R3.Model.Vocabulary`, `AAuth.R3.Model`. + +### src/AAuth.R3/R3AccessAnnotations.cs + +Concept/decision: [r3](#r3). Source: [R3AccessAnnotations.cs](../../../src/AAuth.R3/R3AccessAnnotations.cs). + +```diff ++ AAuth.R3.R3AccessAnnotations: public const string McpAccessMode = "aauth.dev/access-mode" ; ++ AAuth.R3.R3AccessAnnotations: public const string McpBudget = "aauth.dev/budget" ; ++ AAuth.R3.R3AccessAnnotations: public const string McpMeta = "_meta" ; ++ AAuth.R3.R3AccessAnnotations: public const string ODataAccessMode = "AAuth.AccessMode" ; ++ AAuth.R3.R3AccessAnnotations: public const string ODataBudget = "AAuth.Budget" ; ++ AAuth.R3.R3AccessAnnotations: public const string OpenApiAccessMode = "x-aauth-access-mode" ; ++ AAuth.R3.R3AccessAnnotations: public const string OpenApiBudget = "x-aauth-budget" ; ++ AAuth.R3.R3AccessAnnotations: public static JsonObject Annotate ( JsonObject definition , string vocabulary , R3OperationAccess access ) ++ AAuth.R3.R3AccessAnnotations: public static R3OperationAccess ? Read ( JsonObject definition , string vocabulary ) ++ AAuth.R3.R3AccessAnnotations: public static string EffectiveAccessMode ( R3OperationAccess ? annotation , string ? resourceAccessMode ) ++ AAuth.R3: public sealed record R3OperationAccess ( string ? AccessMode , bool Budget = false ) ++ AAuth.R3: public static class R3AccessAnnotations +``` + +Public owners: `AAuth.R3.R3AccessAnnotations`, `AAuth.R3`. + +### src/AAuth.R3/R3AccessTokenEndpoint.cs + +Concept/decision: [r3](#r3). Source: [R3AccessTokenEndpoint.cs](../../../src/AAuth.R3/R3AccessTokenEndpoint.cs). + +```diff +- AAuth.R3.R3AccessTokenEndpoint: public static WebApplication MapR3AccessTokenEndpoint ( this WebApplication app , R3AccessTokenEndpointOptions options ) +- AAuth.R3.R3AccessTokenEndpointOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuth . Discovery . AAuthEgressPolicy . Production +- AAuth.R3.R3AccessTokenEndpointOptions: public AAuth . Discovery . AAuthTransportContract ? FetchTransportContract { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public BrowserConsentSessions ? BrowserConsent { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public Func < HttpContext , string , string , string , CancellationToken , Task < byte [ ] > > ? FetchAndVerifyAsync { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public Func < R3OperationIdentity , bool > ? IsConditionalOperation { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public Func < R3OperationIdentity , bool > ? IsOperationAllowed { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public Func < R3ProposalDocument , bool > ? IsProposalAllowed { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public Func < string , bool > ? IsTrustedPersonServer { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public Func < string , string , bool > ? IsScopeAllowed { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public HttpMessageHandler ? FetchHttpMessageHandler { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public IReadOnlyCollection < string > ? TrustedPersonServers { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public R3VocabularySchemas VocabularySchemas { get ; init ; } = R3VocabularySchemas . Standard +- AAuth.R3.R3AccessTokenEndpointOptions: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System +- AAuth.R3.R3AccessTokenEndpointOptions: public bool RequireProposalConsent { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public required IR3AuditSink AuditSink { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public required IReadOnlyDictionary < string , IAAuthKey > SigningKeys { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public required string Issuer { get ; init ; } +- AAuth.R3.R3AccessTokenEndpointOptions: public string ConsentPath { get ; init ; } = "/interaction/consent" +- AAuth.R3.R3AccessTokenEndpointOptions: public string PendingPath { get ; init ; } = "/pending" +- AAuth.R3.R3AccessTokenEndpointOptions: public string Subject { get ; init ; } = "pairwise-sub" +- AAuth.R3.R3AccessTokenEndpointOptions: public string TokenPath { get ; init ; } = "/token" ++ AAuth.R3.R3AccessTokenEndpoint: public static IServiceCollection AddR3AccessTokenEndpoint ( this IServiceCollection services , Action < R3AccessTokenEndpointOptions > configure ) ++ AAuth.R3.R3AccessTokenEndpoint: public static WebApplication MapR3AccessTokenEndpoint ( this WebApplication app ) ++ AAuth.R3.R3AccessTokenEndpointOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.R3.R3AccessTokenEndpointOptions: public AAuth . Discovery . AAuthTransportContract ? FetchTransportContract { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public AAuthSigningKeySet SigningKeys { get ; set ; } = new ( ) ++ AAuth.R3.R3AccessTokenEndpointOptions: public AAuthTrustOptions Trust { get ; set ; } = new ( ) ++ AAuth.R3.R3AccessTokenEndpointOptions: public BrowserConsentSessions ? BrowserConsent { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public Func < HttpContext , string , string , string , CancellationToken , Task < byte [ ] > > ? FetchAndVerifyAsync { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public Func < R3OperationIdentity , bool > ? IsOperationAllowed { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public Func < R3OperationIdentity , bool > ? IsPerCallOperation { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public Func < R3ProposalDocument , bool > ? IsProposalAllowed { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public Func < string , string , bool > ? IsScopeAllowed { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public HttpMessageHandler ? FetchHttpMessageHandler { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public IR3AuditSink AuditSink { get ; set ; } = null ! ++ AAuth.R3.R3AccessTokenEndpointOptions: public IR3AuthoritativeDefinitionProvider ? AuthoritativeDefinitions { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public IR3OperationValidator ? OperationValidator { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public R3VocabularySchemas VocabularySchemas { get ; set ; } = R3VocabularySchemas . Standard ++ AAuth.R3.R3AccessTokenEndpointOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.R3.R3AccessTokenEndpointOptions: public bool RequireProposalConsent { get ; set ; } ++ AAuth.R3.R3AccessTokenEndpointOptions: public string ConsentPath { get ; set ; } = "/interaction/consent" ++ AAuth.R3.R3AccessTokenEndpointOptions: public string Issuer { get ; set ; } = "" ++ AAuth.R3.R3AccessTokenEndpointOptions: public string PendingPath { get ; set ; } = "/pending" ++ AAuth.R3.R3AccessTokenEndpointOptions: public string TokenPath { get ; set ; } = "/token" +``` + +Public owners: `AAuth.R3.R3AccessTokenEndpointOptions`, `AAuth.R3.R3AccessTokenEndpoint`, `AAuth.R3`. + +### src/AAuth.R3/R3Audit.cs + +Concept/decision: [r3](#r3). Source: [R3Audit.cs](../../../src/AAuth.R3/R3Audit.cs). + +```diff +- AAuth.R3: public sealed record R3TokenIssuanceAuditRecord ( string R3Uri , string R3S256 , string AgentId , string ResourceIssuer , string AccessServerIssuer , DateTimeOffset IssuedAt , R3TokenIssuanceKind IssuanceKind ) ++ AAuth.R3: public sealed record R3TokenIssuanceAuditRecord ( string R3Uri , string R3S256 , string AgentId , string ResourceIssuer , string AccessServerIssuer , string PersonServer , string Subject , string AgentJkt , DateTimeOffset IssuedAt , R3TokenIssuanceKind IssuanceKind ) +``` + +Public owners: `AAuth.R3.IR3AuditSink`, `AAuth.R3.InMemoryR3AuditSink`, `AAuth.R3.R3TokenIssuanceAuditRecord`, `AAuth.R3.R3TokenIssuanceKind`, `AAuth.R3`. + +### src/AAuth.R3/R3AuthClaims.cs + +Concept/decision: [r3](#r3). Source: [R3AuthClaims.cs](../../../src/AAuth.R3/R3AuthClaims.cs). + +```diff +- AAuth.R3.R3AuthClaims: public const string ConditionalClaim = "r3_conditional" ; +- AAuth.R3.R3AuthClaims: public static IReadOnlyDictionary < string , JsonNode ? > AuthToken ( string r3Uri , string r3S256 , R3Grant granted , R3Grant ? conditional = null , R3VocabularySchemas ? schemas = null ) ++ AAuth.R3.R3AuthClaims: public const string PerCallClaim = "r3_per_call" ; ++ AAuth.R3.R3AuthClaims: public static IReadOnlyDictionary < string , JsonNode ? > AuthToken ( string r3Uri , string r3S256 , R3Grant granted , R3Grant ? perCall = null , R3VocabularySchemas ? schemas = null ) +``` + +Public owners: `AAuth.R3.R3AuthClaims`, `AAuth.R3`. + +### src/AAuth.R3/R3AuthorizationEndpointExtensions.cs + +Concept/decision: [r3](#r3). Source: [R3AuthorizationEndpointExtensions.cs](../../../src/AAuth.R3/R3AuthorizationEndpointExtensions.cs). + +```diff ++ AAuth.R3.R3AuthorizationEndpointExtensions: public static IServiceCollection AddAAuthR3AuthorizationEndpoint ( this IServiceCollection services ) ++ AAuth.R3.R3AuthorizationEndpointExtensions: public static R3Operations ? GetR3Operations ( this AAuthAuthorizationRequest request ) ++ AAuth.R3: public static class R3AuthorizationEndpointExtensions +``` + +Public owners: `AAuth.R3.R3AuthorizationEndpointExtensions`, `AAuth.R3`. + +### src/AAuth.R3/R3Challenge.cs + +Concept/decision: [r3](#r3). Source: [R3Challenge.cs](../../../src/AAuth.R3/R3Challenge.cs). + +```diff +- AAuth.R3.R3Challenge: public Func < DateTimeOffset > Clock { get ; init ; } = ( ) => DateTimeOffset . UtcNow +- AAuth.R3.R3Challenge: public IResult Challenge ( HttpContext context , string agent , string agentJkt , string r3Uri , string r3S256 , string ? scope = null , string ? account = null ) +- AAuth.R3.R3Challenge: public required IAAuthKey Key { get ; init ; } +- AAuth.R3.R3Challenge: public string BuildResourceToken ( TokenVerifier . VerifiedToken verifiedAuthToken , string r3Uri , string r3S256 , string ? scope = null ) +- AAuth.R3.R3Challenge: public string BuildResourceToken ( string agent , string agentJkt , string r3Uri , string r3S256 , string ? scope = null , string ? account = null ) ++ AAuth.R3.R3Challenge: public IR3DocumentEntitlements ? Entitlements { get ; init ; } ++ AAuth.R3.R3Challenge: public IR3OperationValidator ? OperationValidator { get ; init ; } ++ AAuth.R3.R3Challenge: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System ++ AAuth.R3.R3Challenge: public ValueTask < string > BuildResourceTokenAsync ( TokenVerifier . VerifiedToken presented , string agentJkt , string r3Uri , string r3S256 , string ? scope = null , string ? account = null , CancellationToken cancellationToken = default ) ++ AAuth.R3.R3Challenge: public ValueTask < string > BuildResourceTokenAsync ( TokenVerifier . VerifiedToken verifiedAuthToken , string r3Uri , string r3S256 , string ? scope = null , CancellationToken cancellationToken = default ) ++ AAuth.R3.R3Challenge: public async Task < IResult > ChallengeAsync ( HttpContext context , string r3Uri , string r3S256 , string ? scope = null , string ? account = null ) ++ AAuth.R3.R3Challenge: public required IAAuthSigner Key { get ; init ; } +``` + +Public owners: `AAuth.R3.R3Challenge`, `AAuth.R3`. + +### src/AAuth.R3/R3ClaimReader.cs + +Concept/decision: [r3](#r3). Source: [R3ClaimReader.cs](../../../src/AAuth.R3/R3ClaimReader.cs). + +```diff +- AAuth.R3.R3ClaimReader: public sealed record AuthTokenClaims ( string Uri , string S256 , R3Grant Granted , R3Grant ? Conditional ) +- AAuth.R3.R3ClaimReader: public static AuthTokenClaims ReadAuthToken ( JsonObject payload , R3VocabularySchemas ? schemas = null ) ++ AAuth.R3.R3ClaimReader.AuthTokenClaims: public DateTimeOffset ? ExpiresAt { get ; init ; } ++ AAuth.R3.R3ClaimReader.AuthTokenClaims: public string ? Issuer { get ; init ; } ++ AAuth.R3.R3ClaimReader.AuthTokenClaims: public string ? Jti { get ; init ; } ++ AAuth.R3.R3ClaimReader: public sealed record AuthTokenClaims ( string Uri , string S256 , R3Grant Granted , R3Grant ? PerCall ) ++ AAuth.R3.R3ClaimReader: public static AuthTokenClaims ReadAuthToken ( JsonObject payload , R3VocabularySchemas ? schemas = null , AAuthEgressPolicy ? egressPolicy = null ) +``` + +Public owners: `AAuth.R3.R3ClaimReader.AuthTokenClaims`, `AAuth.R3.R3ClaimReader.ResourceDocumentClaims`, `AAuth.R3.R3ClaimReader`, `AAuth.R3`. + +### src/AAuth.R3/R3DocumentEndpoint.cs + +Concept/decision: [r3](#r3). Source: [R3DocumentEndpoint.cs](../../../src/AAuth.R3/R3DocumentEndpoint.cs). + +```diff +- AAuth.R3.R3DocumentEndpoint: public static IEndpointRouteBuilder MapR3Document ( this IEndpointRouteBuilder endpoints , string pattern , Func < HttpContext , byte [ ] ? > getBytes , R3DocumentReaderPolicy readerPolicy ) ++ AAuth.R3.R3DocumentEndpoint: public static IEndpointRouteBuilder MapR3Document ( this IEndpointRouteBuilder endpoints , string pattern , Func < HttpContext , byte [ ] ? > getBytes ) ++ AAuth.R3.R3DocumentEndpoint: public static IServiceCollection AddAAuthR3Documents ( this IServiceCollection services , Func < IServiceProvider , R3DocumentReaderPolicy > readerPolicy ) +``` + +Public owners: `AAuth.R3.R3DocumentEndpoint`, `AAuth.R3.R3FetchVerificationException`, `AAuth.R3.R3UntrustedJwksUriException`, `AAuth.R3`. + +### src/AAuth.R3/R3DocumentEntitlements.cs + +Concept/decision: [r3](#r3). Source: [R3DocumentEntitlements.cs](../../../src/AAuth.R3/R3DocumentEntitlements.cs). + +```diff ++ AAuth.R3.IR3DocumentEntitlements: ValueTask < bool > IsEntitledAsync ( string uri , string s256 , string reader , CancellationToken cancellationToken = default ) ++ AAuth.R3.IR3DocumentEntitlements: ValueTask EntitleAsync ( string uri , string s256 , string reader , string resourceTokenId , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) ++ AAuth.R3.InMemoryR3DocumentEntitlements: public ValueTask < bool > IsEntitledAsync ( string uri , string s256 , string reader , CancellationToken cancellationToken = default ) ++ AAuth.R3.InMemoryR3DocumentEntitlements: public ValueTask EntitleAsync ( string uri , string s256 , string reader , string resourceTokenId , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) ++ AAuth.R3: public interface IR3DocumentEntitlements ++ AAuth.R3: public sealed class InMemoryR3DocumentEntitlements ( TimeProvider ? timeProvider = null ) : IR3DocumentEntitlements +``` + +Public owners: `AAuth.R3.IR3DocumentEntitlements`, `AAuth.R3.InMemoryR3DocumentEntitlements`, `AAuth.R3`. + +### src/AAuth.R3/R3Enforcement.cs + +Concept/decision: [r3](#r3). Source: [R3Enforcement.cs](../../../src/AAuth.R3/R3Enforcement.cs). + +```diff +- AAuth.R3.R3Enforcement: public R3Enforcement ( R3ProposalStore proposalStore , Uri resourceBaseUri , string proposalPathPrefix = "/r3/proposals" , R3VocabularySchemas ? schemas = null ) +- AAuth.R3.R3EnforcementDecision: public IResult ToResult ( HttpContext context , R3Challenge challenge , TokenVerifier . VerifiedToken verifiedAuthToken , string ? scope = null ) +- AAuth.R3.R3EnforcementDecision: public IResult ToResult ( HttpContext context , R3Challenge challenge , string agent , string agentJkt , string ? scope = null ) +- AAuth.R3.R3EnforcementDecision: public static R3EnforcementDecision Conditional ( string proposalUri , string proposalS256 ) +- AAuth.R3.R3EnforcementDecisionKind: Conditional ++ AAuth.R3.R3Enforcement: public R3Enforcement ( R3ProposalStore proposalStore , Uri resourceBaseUri , string proposalPathPrefix = "/r3/proposals" , R3VocabularySchemas ? schemas = null , IAAuthSingleUseGate ? singleUseGate = null , AAuthEgressPolicy ? egressPolicy = null ) ++ AAuth.R3.R3EnforcementDecision: public R3SingleUse ? SingleUseGrant { get ; init ; } ++ AAuth.R3.R3EnforcementDecision: public async Task < IResult > ToResultAsync ( HttpContext context , R3Challenge challenge , TokenVerifier . VerifiedToken verifiedAuthToken , string ? scope = null ) ++ AAuth.R3.R3EnforcementDecision: public static R3EnforcementDecision PerCall ( string proposalUri , string proposalS256 ) ++ AAuth.R3.R3EnforcementDecision: public static R3EnforcementDecision SingleUse ( R3SingleUse singleUse ) ++ AAuth.R3.R3EnforcementDecisionKind: PerCall ++ AAuth.R3.R3EnforcementDecisionKind: SingleUse ++ AAuth.R3.R3SingleUse: public DateTimeOffset ExpiresAt { get ; } ++ AAuth.R3.R3SingleUse: public Task < HeldInvocationResult > ExecuteOnceAsync ( Func < CancellationToken , Task < HeldInvocationResult > > execute , CancellationToken cancellationToken = default ) ++ AAuth.R3.R3SingleUse: public string Key { get ; } ++ AAuth.R3: public sealed class R3SingleUse +``` + +Public owners: `AAuth.R3.R3EnforcementDecisionKind`, `AAuth.R3.R3EnforcementDecision`, `AAuth.R3.R3Enforcement`, `AAuth.R3.R3SingleUse`, `AAuth.R3`. + +### src/AAuth.R3/R3FetchClient.cs + +Concept/decision: [r3](#r3). Source: [R3FetchClient.cs](../../../src/AAuth.R3/R3FetchClient.cs). + +```diff +- AAuth.R3.R3FetchClient: public static R3FetchClient Create ( IAAuthKey signingKey , string identifier , string dwk , string kid , HttpMessageHandler ? innerHandler = null , AAuthEgressPolicy ? policy = null , AAuthTransportContract ? transportContract = null ) ++ AAuth.R3.R3FetchClient: public static R3FetchClient Create ( IAAuthSigner signingKey , string identifier , string dwk , string kid , HttpMessageHandler ? innerHandler = null , AAuthEgressPolicy ? policy = null , AAuthTransportContract ? transportContract = null ) +``` + +Public owners: `AAuth.R3.R3FetchClient`, `AAuth.R3`. + +### src/AAuth.R3/R3Metadata.cs + +Concept/decision: [r3](#r3). Source: [R3Metadata.cs](../../../src/AAuth.R3/R3Metadata.cs). + +Public signatures unchanged (6); behavior reviewed under r3. + +Public owners: `AAuth.R3.R3Metadata`, `AAuth.R3`. + +### src/AAuth.R3/R3OperationValidation.cs + +Concept/decision: [r3](#r3). Source: [R3OperationValidation.cs](../../../src/AAuth.R3/R3OperationValidation.cs). + +```diff ++ AAuth.R3.IR3AuthoritativeDefinitionProvider: ValueTask < IReadOnlyList < R3OperationIdentity > > GetOperationsAsync ( string vocabulary , CancellationToken cancellationToken = default ) ++ AAuth.R3.IR3OperationValidator: ValueTask ValidateDocumentAsync ( R3Document document , CancellationToken cancellationToken = default ) ++ AAuth.R3.IR3OperationValidator: ValueTask ValidateProposalAsync ( R3ProposalDocument proposal , CancellationToken cancellationToken = default ) ++ AAuth.R3.IR3OperationValidator: ValueTask ValidateReferenceAsync ( string r3Uri , string r3S256 , CancellationToken cancellationToken = default ) ++ AAuth.R3.R3OperationValidation: public static void RejectAmbiguousBareIdentifiers ( string vocabulary , IEnumerable < R3OperationIdentity > authoritativeOperations ) ++ AAuth.R3.R3OperationValidation: public static void ValidateGrant ( R3Grant grant , IEnumerable < R3OperationIdentity > authoritativeOperations , R3VocabularySchemas ? schemas = null ) ++ AAuth.R3.R3OperationValidator: public ValueTask ValidateReferenceAsync ( string r3Uri , string r3S256 , CancellationToken cancellationToken = default ) ++ AAuth.R3.R3OperationValidator: public async ValueTask ValidateDocumentAsync ( R3Document document , CancellationToken cancellationToken = default ) ++ AAuth.R3.R3OperationValidator: public async ValueTask ValidateProposalAsync ( R3ProposalDocument proposal , CancellationToken cancellationToken = default ) ++ AAuth.R3.StaticR3AuthoritativeDefinitionProvider: public ValueTask < IReadOnlyList < R3OperationIdentity > > GetOperationsAsync ( string vocabulary , CancellationToken cancellationToken = default ) ++ AAuth.R3: public interface IR3AuthoritativeDefinitionProvider ++ AAuth.R3: public interface IR3OperationValidator ++ AAuth.R3: public sealed class R3OperationValidator ( R3ProposalStore store , IR3AuthoritativeDefinitionProvider provider , R3VocabularySchemas ? schemas = null ) : IR3OperationValidator ++ AAuth.R3: public sealed class StaticR3AuthoritativeDefinitionProvider ( IEnumerable < R3OperationIdentity > operations ) : IR3AuthoritativeDefinitionProvider ++ AAuth.R3: public static class R3OperationValidation +``` + +Public owners: `AAuth.R3.IR3AuthoritativeDefinitionProvider`, `AAuth.R3.IR3OperationValidator`, `AAuth.R3.R3OperationValidation`, `AAuth.R3.R3OperationValidator`, `AAuth.R3.StaticR3AuthoritativeDefinitionProvider`, `AAuth.R3`. + +### src/AAuth/AAuthClientBuilder.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthClientBuilder.cs](../../../src/AAuth/AAuthClientBuilder.cs). + +```diff +- AAuth.AAuthClientBuilder: public AAuthClientBuilder ( IAAuthKey key ) +- AAuth.AAuthClientBuilder: public static EnrolledBuilder Enrolled ( IAAuthKey key ) +- AAuth.AAuthClientBuilder: public static SelfIssuingBuilder SelfIssuing ( IAAuthKey key ) ++ AAuth.AAuthClientBuilder: public AAuthClientBuilder ( IAAuthSigner key ) ++ AAuth.AAuthClientBuilder: public AAuthClientBuilder WithTokenCache ( IAAuthTokenCache cache ) ++ AAuth.AAuthClientBuilder: public static EnrolledBuilder Enrolled ( IAAuthSigner key ) ++ AAuth.AAuthClientBuilder: public static SelfIssuingBuilder SelfIssuing ( IAAuthSigner key ) +``` + +Public owners: `AAuth.AAuthClientBuilder`, `AAuth`. + +### src/AAuth/AAuthConstants.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthConstants.cs](../../../src/AAuth/AAuthConstants.cs). + +```diff +- AAuth.AAuthConstants.AccessModes: public const string AAuthAccessToken = "aauth-access-token" ; +- AAuth.AAuthConstants.Headers: public const string AAuthMission = "AAuth-Mission" ; ++ AAuth.AAuthConstants.AccessModes: public const string PerCall = "per-call" ; ++ AAuth.AAuthConstants.AccessModes: public const string PersonToken = "person-token" ; ++ AAuth.AAuthConstants.AccessModes: public const string SessionToken = "session-token" ; ++ AAuth.AAuthConstants.Capabilities: public const string Clarification = "clarification" ; ++ AAuth.AAuthConstants.Capabilities: public const string Interaction = "interaction" ; ++ AAuth.AAuthConstants.Capabilities: public const string Payment = "payment" ; ++ AAuth.AAuthConstants.Claims: public const string Subject = "sub" ; ++ AAuth.AAuthConstants.Governance.ErrorCodes: public const string InteractionUnavailable = "interaction_unavailable" ; ++ AAuth.AAuthConstants.Governance.InteractionTypes: public const string Interaction = "interaction" ; ++ AAuth.AAuthConstants.Governance.InteractionTypes: public const string Payment = "payment" ; ++ AAuth.AAuthConstants.Governance.InteractionTypes: public const string Question = "question" ; ++ AAuth.AAuthConstants.Governance.Status: public const string Interacting = "interacting" ; ++ AAuth.AAuthConstants.Governance.Status: public const string Ok = "ok" ; ++ AAuth.AAuthConstants.Governance.Status: public const string Pending = "pending" ; ++ AAuth.AAuthConstants.Governance: public static class ErrorCodes ++ AAuth.AAuthConstants.Governance: public static class InteractionTypes ++ AAuth.AAuthConstants.Governance: public static class Status ++ AAuth.AAuthConstants.MetadataFields: public const string AdditionalSignatureComponents = "additional_signature_components" ; ++ AAuth.AAuthConstants.MissionTerminationReasons: public const string Administrative = "administrative" ; ++ AAuth.AAuthConstants.MissionTerminationReasons: public const string Completed = "completed" ; ++ AAuth.AAuthConstants.MissionTerminationReasons: public const string Expired = "expired" ; ++ AAuth.AAuthConstants.MissionTerminationReasons: public const string Revoked = "revoked" ; ++ AAuth.AAuthConstants.MissionTerminationReasons: public const string Superseded = "superseded" ; ++ AAuth.AAuthConstants.Platforms: public const string Desktop = "desktop" ; ++ AAuth.AAuthConstants.Platforms: public const string Mobile = "mobile" ; ++ AAuth.AAuthConstants.Platforms: public const string SelfHosted = "self-hosted" ; ++ AAuth.AAuthConstants.Platforms: public const string Web = "web" ; ++ AAuth.AAuthConstants.Platforms: public const string Workload = "workload" ; ++ AAuth.AAuthConstants.TokenTypes: public const string PersonToken = "aa-person+jwt" ; ++ AAuth.AAuthConstants: public static class Capabilities ++ AAuth.AAuthConstants: public static class Claims ++ AAuth.AAuthConstants: public static class Governance ++ AAuth.AAuthConstants: public static class MetadataFields ++ AAuth.AAuthConstants: public static class MissionTerminationReasons ++ AAuth.AAuthConstants: public static class Platforms +``` + +Public owners: `AAuth.AAuthConstants.AccessModes`, `AAuth.AAuthConstants.Capabilities`, `AAuth.AAuthConstants.Claims`, `AAuth.AAuthConstants.DwkFiles`, `AAuth.AAuthConstants.Governance.ErrorCodes`, `AAuth.AAuthConstants.Governance.InteractionTypes`, `AAuth.AAuthConstants.Governance.Status`, `AAuth.AAuthConstants.Governance`, `AAuth.AAuthConstants.Headers`, `AAuth.AAuthConstants.MetadataFields`, `AAuth.AAuthConstants.MissionTerminationReasons`, `AAuth.AAuthConstants.Platforms`, `AAuth.AAuthConstants.Schemes`, `AAuth.AAuthConstants.TokenTypes`, `AAuth.AAuthConstants`, `AAuth`. + +### src/AAuth/AAuthDiagnostics.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthDiagnostics.cs](../../../src/AAuth/AAuthDiagnostics.cs). + +```diff ++ AAuth.AAuthDiagnostics: public const string TagAuthority = "aauth.authority" ; ++ AAuth.AAuthDiagnostics: public const string TagHttpMethod = "http.request.method" ; ++ AAuth.AAuthDiagnostics: public const string TagPath = "aauth.path" ; ++ AAuth.AAuthDiagnostics: public static readonly Counter < double > SigningCreatedWait = Meter . CreateCounter < double > ( "aauth.signing.created_wait" , unit : "s" , description : "Total seconds spent waiting for the next free AAuth signature created timestamp." ) ; ++ AAuth.AAuthDiagnostics: public static readonly Meter Meter = new ( SourceName , "1.0.0" ) ; +``` + +Public owners: `AAuth.AAuthDiagnostics`, `AAuth`. + +### src/AAuth/AAuthTokenType.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthTokenType.cs](../../../src/AAuth/AAuthTokenType.cs). + +```diff ++ AAuth.AAuthTokenType: PersonToken +``` + +Public owners: `AAuth.AAuthTokenTypeExtensions`, `AAuth.AAuthTokenType`, `AAuth`. + +### src/AAuth/Access/AAuthAccessServerEndpoints.cs + +Concept/decision: [consent](#consent). Source: [AAuthAccessServerEndpoints.cs](../../../src/AAuth/Access/AAuthAccessServerEndpoints.cs). + +```diff +- AAuth.Access.AAuthAccessServerEndpoints: public static WebApplication MapAAuthAccessServer ( this WebApplication app , AAuthAccessServerOptions options ) +- AAuth.Access.AAuthAccessServerOptions: public AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuthEgressPolicy . Production +- AAuth.Access.AAuthAccessServerOptions: public Action < AAuthRevocationOptions > ? ConfigureRevocation { get ; init ; } +- AAuth.Access.AAuthAccessServerOptions: public Func < string , JsonObject ? > ? DeriveAgentClaims { get ; init ; } +- AAuth.Access.AAuthAccessServerOptions: public Func < string , bool > ? IsTrustedPersonServer { get ; init ; } +- AAuth.Access.AAuthAccessServerOptions: public IReadOnlyCollection < string > ? TrustedPersonServers { get ; init ; } +- AAuth.Access.AAuthAccessServerOptions: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System +- AAuth.Access.AAuthAccessServerOptions: public required IReadOnlyDictionary < string , IAAuthKey > SigningKeys { get ; init ; } +- AAuth.Access.AAuthAccessServerOptions: public required string Issuer { get ; init ; } +- AAuth.Access.AAuthAccessServerOptions: public string DefaultScope { get ; init ; } = "" +- AAuth.Access.AAuthAccessServerOptions: public string InteractionLoginPath { get ; init ; } = "/interaction/login" +- AAuth.Access.AAuthAccessServerOptions: public string PendingPathPrefix { get ; init ; } = "/pending" +- AAuth.Access.AAuthAccessServerOptions: public string RevocationPath { get ; init ; } = "/revoke" +- AAuth.Access.AAuthAccessServerOptions: public string TokenPath { get ; init ; } = "/token" ++ AAuth.Access.AAuthAccessServerEndpoints: public static WebApplication MapAAuthAccessServer ( this WebApplication app , string ? name = null ) ++ AAuth.Access.AAuthAccessServerOptions: public AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuthEgressPolicy . Production ++ AAuth.Access.AAuthAccessServerOptions: public AAuthSigningKeySet SigningKeys { get ; set ; } = new ( ) ++ AAuth.Access.AAuthAccessServerOptions: public AAuthTrustOptions Trust { get ; set ; } = new ( ) ++ AAuth.Access.AAuthAccessServerOptions: public Action < AAuthRevocationOptions > ? ConfigureRevocation { get ; set ; } ++ AAuth.Access.AAuthAccessServerOptions: public Func < string , JsonObject ? > ? DeriveAgentClaims { get ; set ; } ++ AAuth.Access.AAuthAccessServerOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Access.AAuthAccessServerOptions: public bool MatchIssuerHost { get ; set ; } ++ AAuth.Access.AAuthAccessServerOptions: public string ? KeyHandle { get ; set ; } ++ AAuth.Access.AAuthAccessServerOptions: public string ? KeyId { get ; set ; } ++ AAuth.Access.AAuthAccessServerOptions: public string DefaultScope { get ; set ; } = "" ++ AAuth.Access.AAuthAccessServerOptions: public string InteractionLoginPath { get ; set ; } = "/interaction/login" ++ AAuth.Access.AAuthAccessServerOptions: public string Issuer { get ; set ; } = "" ++ AAuth.Access.AAuthAccessServerOptions: public string PendingPathPrefix { get ; set ; } = "/pending" ++ AAuth.Access.AAuthAccessServerOptions: public string RevocationPath { get ; set ; } = "/revoke" ++ AAuth.Access.AAuthAccessServerOptions: public string TokenPath { get ; set ; } = "/token" +``` + +Public owners: `AAuth.Access.AAuthAccessServerEndpoints`, `AAuth.Access.AAuthAccessServerOptions`, `AAuth.Access`. + +### src/AAuth/Access/AAuthPayment.cs + +Concept/decision: [consent](#consent). Source: [AAuthPayment.cs](../../../src/AAuth/Access/AAuthPayment.cs). + +```diff ++ AAuth.Access.AAuthPaymentChallenge: public IReadOnlyList < string > WwwAuthenticate { get ; init ; } = [ ] ++ AAuth.Access.AAuthPaymentChallenge: public JsonObject ? Body { get ; init ; } ++ AAuth.Access.AAuthPaymentChallenge: public string Scheme { get ; init ; } = AAuthConstants . Governance . InteractionTypes . Payment ++ AAuth.Access.AAuthPaymentSettlementContext: public required AAuthPaymentChallenge Challenge { get ; init ; } ++ AAuth.Access.AAuthPaymentSettlementContext: public required Uri PendingUrl { get ; init ; } ++ AAuth.Access.AAuthPaymentSettlementContext: public required string AccessServerOrigin { get ; init ; } ++ AAuth.Access.AAuthPaymentSettlementResult: public bool Settled { get ; } ++ AAuth.Access.AAuthPaymentSettlementResult: public static AAuthPaymentSettlementResult Declined { get ; } = new ( false ) ++ AAuth.Access.AAuthPaymentSettlementResult: public static AAuthPaymentSettlementResult Success { get ; } = new ( true ) ++ AAuth.Access.IAAuthBillingRelationshipCache: Task < bool > IsEstablishedAsync ( string accessServerIssuer , string scheme , CancellationToken cancellationToken = default ) ++ AAuth.Access.IAAuthBillingRelationshipCache: Task MarkEstablishedAsync ( string accessServerIssuer , string scheme , CancellationToken cancellationToken = default ) ++ AAuth.Access.IAAuthPaymentSettler: Task < AAuthPaymentSettlementResult > SettleAsync ( AAuthPaymentSettlementContext context , CancellationToken cancellationToken = default ) ++ AAuth.Access.InMemoryAAuthBillingRelationshipCache: public Task < bool > IsEstablishedAsync ( string accessServerIssuer , string scheme , CancellationToken cancellationToken = default ) ++ AAuth.Access.InMemoryAAuthBillingRelationshipCache: public Task MarkEstablishedAsync ( string accessServerIssuer , string scheme , CancellationToken cancellationToken = default ) ++ AAuth.Access: public interface IAAuthBillingRelationshipCache ++ AAuth.Access: public interface IAAuthPaymentSettler ++ AAuth.Access: public sealed class AAuthPaymentChallenge ++ AAuth.Access: public sealed class AAuthPaymentSettlementContext ++ AAuth.Access: public sealed class AAuthPaymentSettlementResult ++ AAuth.Access: public sealed class InMemoryAAuthBillingRelationshipCache : IAAuthBillingRelationshipCache +``` + +Public owners: `AAuth.Access.AAuthPaymentChallenge`, `AAuth.Access.AAuthPaymentSettlementContext`, `AAuth.Access.AAuthPaymentSettlementResult`, `AAuth.Access.IAAuthBillingRelationshipCache`, `AAuth.Access.IAAuthPaymentSettler`, `AAuth.Access.InMemoryAAuthBillingRelationshipCache`, `AAuth.Access`. + +### src/AAuth/Access/AccessServerClient.cs + +Concept/decision: [consent](#consent). Source: [AccessServerClient.cs](../../../src/AAuth/Access/AccessServerClient.cs). + +Public signatures unchanged (3); behavior reviewed under consent. + +Public owners: `AAuth.Access.AccessServerClient`, `AAuth.Access`. + +### src/AAuth/Access/AccessServerRequest.cs + +Concept/decision: [consent](#consent). Source: [AccessServerRequest.cs](../../../src/AAuth/Access/AccessServerRequest.cs). + +```diff +- AAuth.Access.AccessServerRequest: public JsonObject ? ExpectedActContext { get ; init ; } +- AAuth.Access.AccessServerRequest: public MissionClaim ? ExpectedMission { get ; set ; } +- AAuth.Access.AccessServerRequest: public required DateTimeOffset AuthorizationExpiresAt { get ; init ; } +- AAuth.Access.AccessServerRequest: public required string ExpectedAgentId { get ; init ; } ++ AAuth.Access.AccessServerRequest: public Func < AAuthPaymentSettlementContext , CancellationToken , Task < AAuthPaymentSettlementResult > > ? OnPaymentRequired { get ; init ; } ++ AAuth.Access.AccessServerRequest: public required DateTimeOffset AuthorizationExpiresAt { get ; set ; } ++ AAuth.Access.AccessServerRequest: public required DateTimeOffset PresentedTokenExpiresAt { get ; set ; } ++ AAuth.Access.AccessServerRequest: public required string ExpectedPersonServer { get ; init ; } ++ AAuth.Access.AccessServerRequest: public required string ExpectedSubject { get ; init ; } ++ AAuth.Access.AccessServerRequest: public required string PresentedToken { get ; init ; } ++ AAuth.Access.AccessServerRequest: public string ? ExpectedMissionS256 { get ; set ; } +``` + +Public owners: `AAuth.Access.AccessServerRequest`, `AAuth.Access`. + +### src/AAuth/Access/IAccessPendingStore.cs + +Concept/decision: [consent](#consent). Source: [IAccessPendingStore.cs](../../../src/AAuth/Access/IAccessPendingStore.cs). + +```diff +- AAuth.Access.AccessPendingEntry: public IReadOnlyList < AAuth . Server . TokenKey > SourceTokens { get ; set ; } = [ ] +- AAuth.Access.AccessPendingEntry: public JsonObject ? UpstreamAct { get ; init ; } +- AAuth.Access.AccessPendingEntry: public string ? OwnerAgentIssuer { get ; set ; } +- AAuth.Access.AccessPendingEntry: public string ? OwnerAgentSubject { get ; set ; } +- AAuth.Access.AccessPendingEntry: public string ? SuppliedSubject { get ; set ; } +- AAuth.Access.IAccessPendingStore: AccessPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? claims , IReadOnlyList < string > ? requiredClaims = null , DateTimeOffset ? authorizationExpiresAt = null , JsonObject ? upstreamAct = null ) +- AAuth.Access.InMemoryAccessPendingStore: public AccessPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? claims , IReadOnlyList < string > ? requiredClaims = null , DateTimeOffset ? authorizationExpiresAt = null , JsonObject ? upstreamAct = null ) ++ AAuth.Access.AccessPendingEntry: public AAuthPaymentChallenge ? PaymentChallenge { get ; set ; } ++ AAuth.Access.AccessPendingEntry: public IReadOnlyList < AAuth . Server . TokenRegistration > SourceTokens { get ; set ; } = [ ] ++ AAuth.Access.AccessPendingStatus: PaymentRequired ++ AAuth.Access.IAccessPendingStore: AccessPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? claims , IReadOnlyList < string > ? requiredClaims = null , DateTimeOffset ? authorizationExpiresAt = null ) ++ AAuth.Access.InMemoryAccessPendingStore: public AccessPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? claims , IReadOnlyList < string > ? requiredClaims = null , DateTimeOffset ? authorizationExpiresAt = null ) +``` + +Public owners: `AAuth.Access.AccessPendingEntry`, `AAuth.Access.AccessPendingStatus`, `AAuth.Access.IAccessPendingStore`, `AAuth.Access.InMemoryAccessPendingStore`, `AAuth.Access`. + +### src/AAuth/Access/IAccessPolicy.cs + +Concept/decision: [consent](#consent). Source: [IAccessPolicy.cs](../../../src/AAuth/Access/IAccessPolicy.cs). + +```diff +- AAuth.Access.AccessDecision: public static AccessDecision Allow ( string ? subject = null , string ? tenant = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) +- AAuth.Access.AccessDecision: public static AccessDecision NeedsPayment ( string paymentUrl ) +- AAuth.Access.AccessDecision: public string ? PaymentUrl { get ; } +- AAuth.Access.AccessDecision: public string ? Subject { get ; } ++ AAuth.Access.AccessDecision: public AAuthPaymentChallenge ? PaymentChallenge { get ; } ++ AAuth.Access.AccessDecision: public static AccessDecision Allow ( string ? tenant = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) ++ AAuth.Access.AccessDecision: public static AccessDecision NeedsPayment ( AAuthPaymentChallenge challenge ) +``` + +Public owners: `AAuth.Access.AccessDecisionKind`, `AAuth.Access.AccessDecision`, `AAuth.Access.AccessPolicyRequest`, `AAuth.Access.IAccessPolicy`, `AAuth.Access.IInteractiveAccessPolicy`, `AAuth.Access`. + +### src/AAuth/Agent/AAuthAccessHandler.cs + +Concept/decision: [resource-managed](#resource-managed). Source: [AAuthAccessHandler.cs](../../../src/AAuth/Agent/AAuthAccessHandler.cs). + +Public signatures unchanged (3); behavior reviewed under resource-managed. + +Public owners: `AAuth.Agent.AAuthAccessHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthAgentFactory.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthAgentFactory.cs](../../../src/AAuth/Agent/AAuthAgentFactory.cs). + +```diff ++ AAuth.Agent.AAuthAgent: public AAuth . Server . RevocationClient Revocation ++ AAuth.Agent.AAuthAgent: public Governance . AAuthGovernanceClient Governance ++ AAuth.Agent.AAuthAgent: public HttpClient HttpClient { get ; } ++ AAuth.Agent.AAuthAgent: public TokenExchangeClient TokenExchange ++ AAuth.Agent.AAuthAgent: public string Name { get ; } ++ AAuth.Agent.AAuthAgent: public void Dispose ( ) ++ AAuth.Agent.AAuthAgentDescriptor: public AAuthAgentDescriptor ( string name ) ++ AAuth.Agent.AAuthAgentDescriptor: public string Name { get ; } ++ AAuth.Agent.IAAuthAgentFactory: AAuthAgent Create ( AAuthAgentDescriptor descriptor ) ++ AAuth.Agent.IAAuthAgentFactory: AAuthAgent Create ( string name , IAAuthSigner signer , Action < AAuthClientBuilder > configure ) ++ AAuth.Agent.IAAuthAgentFactory: AAuthAgent Get ( string name ) ++ AAuth.Agent: public interface IAAuthAgentFactory ++ AAuth.Agent: public sealed class AAuthAgent : IDisposable ++ AAuth.Agent: public sealed class AAuthAgentDescriptor : AAuthAgentOptions +``` + +Public owners: `AAuth.Agent.AAuthAgentDescriptor`, `AAuth.Agent.AAuthAgent`, `AAuth.Agent.IAAuthAgentFactory`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthCallbackHandlers.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthCallbackHandlers.cs](../../../src/AAuth/Agent/AAuthCallbackHandlers.cs). + +```diff ++ AAuth.Agent.IAAuthClarificationHandler: Task < ClarificationResponse > OnClarificationRequiredAsync ( ClarificationRequirement clarification , CancellationToken cancellationToken ) ++ AAuth.Agent.IAAuthDeferredObserver: Task OnApprovalPendingAsync ( CancellationToken cancellationToken ) ++ AAuth.Agent.IAAuthDeferredObserver: void OnPoll ( HttpResponseMessage response ) ++ AAuth.Agent.IAAuthInteractionHandler: Task OnInteractionRequiredAsync ( Interaction interaction , CancellationToken cancellationToken ) ++ AAuth.Agent: public interface IAAuthClarificationHandler ++ AAuth.Agent: public interface IAAuthDeferredObserver ++ AAuth.Agent: public interface IAAuthInteractionHandler +``` + +Public owners: `AAuth.Agent.IAAuthClarificationHandler`, `AAuth.Agent.IAAuthDeferredObserver`, `AAuth.Agent.IAAuthInteractionHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthCapabilitiesHeader.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthCapabilitiesHeader.cs](../../../src/AAuth/Agent/AAuthCapabilitiesHeader.cs). + +```diff +- AAuth.Agent.AAuthCapabilitiesHeader.Capabilities: public const string Clarification = "clarification" ; +- AAuth.Agent.AAuthCapabilitiesHeader.Capabilities: public const string Interaction = "interaction" ; +- AAuth.Agent.AAuthCapabilitiesHeader.Capabilities: public const string Payment = "payment" ; +- AAuth.Agent.AAuthCapabilitiesHeader: public const string Name = "AAuth-Capabilities" ; +- AAuth.Agent.AAuthCapabilitiesHeader: public static class Capabilities ++ AAuth.Agent.AAuthCapabilitiesHeader: public const string Name = AAuthConstants . Headers . AAuthCapabilities ; +``` + +Public owners: `AAuth.Agent.AAuthCapabilitiesHeader.Capabilities`, `AAuth.Agent.AAuthCapabilitiesHeader`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthInteractionExceptions.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthInteractionExceptions.cs](../../../src/AAuth/Agent/AAuthInteractionExceptions.cs). + +```diff +- AAuth.Agent.AAuthInteractionChainedException: public Interaction Interaction { get ; } ++ AAuth.Agent.AAuthInteractionChainedException: public Interaction DownstreamInteraction { get ; } +``` + +Public owners: `AAuth.Agent.AAuthClarificationCancelledException`, `AAuth.Agent.AAuthClarificationLimitException`, `AAuth.Agent.AAuthInteractionChainedException`, `AAuth.Agent.AAuthInteractionDeniedException`, `AAuth.Agent.AAuthInteractionTimeoutException`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthRequestOptions.cs + +Concept/decision: [resource-managed](#resource-managed). Source: [AAuthRequestOptions.cs](../../../src/AAuth/Agent/AAuthRequestOptions.cs). + +```diff ++ AAuth.Agent.AAuthRequestOptions: public static readonly HttpRequestOptionsKey < IAAuthClarificationHandler > ClarificationHandler = new ( "AAuth.ClarificationHandler" ) ; ++ AAuth.Agent.AAuthRequestOptions: public static readonly HttpRequestOptionsKey < IAAuthDeferredObserver > DeferredObserver = new ( "AAuth.DeferredObserver" ) ; ++ AAuth.Agent.AAuthRequestOptions: public static readonly HttpRequestOptionsKey < IAAuthInteractionHandler > InteractionHandler = new ( "AAuth.InteractionHandler" ) ; ++ AAuth.Agent.AAuthRequestOptions: public static readonly HttpRequestOptionsKey < System . Collections . Generic . IReadOnlyDictionary < string , string > > MissionPersonTokens = new ( "AAuth.MissionPersonTokens" ) ; ++ AAuth.Agent.AAuthRequestOptions: public static readonly HttpRequestOptionsKey < string > MissionS256 = new ( "AAuth.MissionS256" ) ; ++ AAuth.Agent.AAuthRequestOptions: public static string ? GetMissionS256 ( HttpRequestMessage request ) +``` + +Public owners: `AAuth.Agent.AAuthRequestOptions`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthTokenCache.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthTokenCache.cs](../../../src/AAuth/Agent/AAuthTokenCache.cs). + +```diff ++ AAuth.Agent.IAAuthTokenCache: Task < string > AcquireAsync ( AAuthTokenCacheKey key , string ? presented , Func < CancellationToken , Task < string > > acquire , CancellationToken cancellationToken ) ++ AAuth.Agent.IAAuthTokenCache: string ? Get ( AAuthTokenCacheKey key ) ++ AAuth.Agent.IAAuthTokenCache: void Clear ( ) ++ AAuth.Agent.IAAuthTokenCache: void Set ( AAuthTokenCacheKey key , string token , DateTimeOffset expiresAt ) ++ AAuth.Agent.InMemoryAAuthTokenCache: public InMemoryAAuthTokenCache ( TimeProvider ? timeProvider = null ) ++ AAuth.Agent.InMemoryAAuthTokenCache: public async Task < string > AcquireAsync ( AAuthTokenCacheKey key , string ? presented , Func < CancellationToken , Task < string > > acquire , CancellationToken cancellationToken ) ++ AAuth.Agent.InMemoryAAuthTokenCache: public string ? Get ( AAuthTokenCacheKey key ) ++ AAuth.Agent.InMemoryAAuthTokenCache: public void Clear ( ) ++ AAuth.Agent.InMemoryAAuthTokenCache: public void Set ( AAuthTokenCacheKey key , string token , DateTimeOffset expiresAt ) ++ AAuth.Agent: public interface IAAuthTokenCache ++ AAuth.Agent: public sealed class InMemoryAAuthTokenCache : IAAuthTokenCache ++ AAuth.Agent: public sealed record AAuthTokenCacheKey ( string AgentToken , string ? Upstream , string ? MissionS256 , string Audience , string ? Account , string KeyThumbprint ) +``` + +Public owners: `AAuth.Agent.IAAuthTokenCache`, `AAuth.Agent.InMemoryAAuthTokenCache`, `AAuth.Agent`. + +### src/AAuth/Agent/AAuthTokenHolder.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AAuthTokenHolder.cs](../../../src/AAuth/Agent/AAuthTokenHolder.cs). + +```diff ++ AAuth.Agent.AAuthTokenHolder: public AAuthTokenHolder ( IAAuthTokenCache ? cache ) +``` + +Public owners: `AAuth.Agent.AAuthTokenHolder`, `AAuth.Agent`. + +### src/AAuth/Agent/AgentProviderClient.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AgentProviderClient.cs](../../../src/AAuth/Agent/AgentProviderClient.cs). + +Public signatures unchanged (16); behavior reviewed under agent-clients. + +Public owners: `AAuth.Agent.AgentProviderClient`, `AAuth.Agent.EnrollResult`, `AAuth.Agent.TwoKeyRefreshResult`, `AAuth.Agent`. + +### src/AAuth/Agent/AgentProviderTokenRefresher.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [AgentProviderTokenRefresher.cs](../../../src/AAuth/Agent/AgentProviderTokenRefresher.cs). + +```diff +- AAuth.Agent.AgentProviderTokenRefresher.RefresherBuilder: public RefresherBuilder WithRefreshMode ( RefreshMode mode ) +- AAuth.Agent.AgentProviderTokenRefresher: public AAuthKey ? LatestEphemeralKey { get ; private set ; } +- AAuth.Agent.AgentProviderTokenRefresher: public AgentProviderTokenRefresher ( HttpClient http , IKeyStore keyStore , string refreshEndpoint , string localKeyHandle , RefreshMode mode = RefreshMode . SingleKey ) +- AAuth.Agent.RefreshMode: SingleKey +- AAuth.Agent.RefreshMode: TwoKey +- AAuth.Agent: public enum RefreshMode ++ AAuth.Agent.AgentProviderTokenRefresher: public AgentProviderTokenRefresher ( HttpClient http , IKeyStore keyStore , string refreshEndpoint , string localKeyHandle ) +``` + +Public owners: `AAuth.Agent.AgentProviderTokenRefresher.RefresherBuilder`, `AAuth.Agent.AgentProviderTokenRefresher`, `AAuth.Agent.RefreshMode`, `AAuth.Agent`. + +### src/AAuth/Agent/ChallengeHandler.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [ChallengeHandler.cs](../../../src/AAuth/Agent/ChallengeHandler.cs). + +```diff +- AAuth.Agent.ChallengeHandler: public ChallengeHandler ( TokenExchangeClient exchange , AAuthTokenHolder holder , TokenVerifier verifier , MetadataClient metadata , JwksClient jwks , string ? personServer , Func < Interaction , CancellationToken , Task > ? onInteractionRequired , DeferredPollerOptions ? pollerOptions , Func < string ? > ? upstreamTokenProvider ) +- AAuth.Agent.ChallengeHandler: public ChallengeHandler ( TokenExchangeClient exchange , AAuthTokenHolder holder , TokenVerifier verifier , MetadataClient metadata , JwksClient jwks , string personServer , Func < Interaction , CancellationToken , Task > ? onInteractionRequired = null , DeferredPollerOptions ? pollerOptions = null ) ++ AAuth.Agent.ChallengeHandler: public ChallengeHandler ( TokenExchangeClient exchange , AAuthTokenHolder holder , TokenVerifier verifier , MetadataClient metadata , JwksClient jwks , string ? personServer , Func < Interaction , CancellationToken , Task > ? onInteractionRequired = null , DeferredPollerOptions ? pollerOptions = null , Func < string ? > ? upstreamTokenProvider = null ) +``` + +Public owners: `AAuth.Agent.ChallengeHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/ClarificationExchange.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [ClarificationExchange.cs](../../../src/AAuth/Agent/ClarificationExchange.cs). + +```diff +- AAuth.Agent.ClarificationExchange: public async Task UpdateRequestAsync ( string resourceToken , string ? justification = null , CancellationToken cancellationToken = default ) +- AAuth.Agent.ClarificationResponse: public static ClarificationResponse Update ( string resourceToken , string ? justification = null ) ++ AAuth.Agent.ClarificationExchange: public async Task UpdateRequestAsync ( string resourceToken , string presentedToken , string ? justification = null , CancellationToken cancellationToken = default ) ++ AAuth.Agent.ClarificationResponse: public static ClarificationResponse Update ( string resourceToken , string presentedToken , string ? justification = null ) ++ AAuth.Agent.ClarificationResponse: public string ? PresentedToken { get ; } +``` + +Public owners: `AAuth.Agent.ClarificationExchange`, `AAuth.Agent.ClarificationResponse.Kind`, `AAuth.Agent.ClarificationResponse`, `AAuth.Agent`. + +### src/AAuth/Agent/DeferredPoller.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [DeferredPoller.cs](../../../src/AAuth/Agent/DeferredPoller.cs). + +```diff +- AAuth.Agent.DeferredPollerOptions: public Action < HttpResponseMessage > ? OnPoll { get ; init ; } +- AAuth.Agent.DeferredPollerOptions: public Func < HttpResponseMessage , bool > ? StopWhenAccepted { get ; init ; } +- AAuth.Agent.DeferredPollerOptions: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System +- AAuth.Agent.DeferredPollerOptions: public TimeSpan DefaultPollInterval { get ; init ; } = TimeSpan . FromSeconds ( 5 ) +- AAuth.Agent.DeferredPollerOptions: public TimeSpan MaxTotalWait { get ; init ; } = TimeSpan . FromMinutes ( 5 ) +- AAuth.Agent.DeferredPollerOptions: public TimeSpan MinPollInterval { get ; init ; } = TimeSpan . FromMilliseconds ( 100 ) +- AAuth.Agent.DeferredPollerOptions: public int ? PreferWaitSeconds { get ; init ; } ++ AAuth.Agent.DeferredPollerOptions: public Action < HttpResponseMessage > ? OnPoll { get ; set ; } ++ AAuth.Agent.DeferredPollerOptions: public Func < HttpResponseMessage , bool > ? StopWhenAccepted { get ; set ; } ++ AAuth.Agent.DeferredPollerOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Agent.DeferredPollerOptions: public TimeSpan DefaultPollInterval { get ; set ; } = TimeSpan . FromSeconds ( 5 ) ++ AAuth.Agent.DeferredPollerOptions: public TimeSpan MaxTotalWait { get ; set ; } = TimeSpan . FromMinutes ( 5 ) ++ AAuth.Agent.DeferredPollerOptions: public TimeSpan MinPollInterval { get ; set ; } = TimeSpan . Zero ++ AAuth.Agent.DeferredPollerOptions: public int ? PreferWaitSeconds { get ; set ; } +``` + +Public owners: `AAuth.Agent.DeferredPollerOptions`, `AAuth.Agent.DeferredPoller`, `AAuth.Agent`. + +### src/AAuth/Agent/Governance/AuditRecord.cs + +Concept/decision: [governance](#governance). Source: [AuditRecord.cs](../../../src/AAuth/Agent/Governance/AuditRecord.cs). + +```diff +- AAuth.Agent.Governance: public sealed record AuditRecord ( MissionClaim Mission , MissionAction Action ) ++ AAuth.Agent.Governance: public sealed record AuditRecord ( string MissionS256 , MissionAction Action ) +``` + +Public owners: `AAuth.Agent.Governance.AuditRecord`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/GovernanceOptions.cs + +Concept/decision: [governance](#governance). Source: [GovernanceOptions.cs](../../../src/AAuth/Agent/Governance/GovernanceOptions.cs). + +```diff +- AAuth.Agent.Governance.GovernanceOptions: public DeferredPollerOptions ? PollerOptions { get ; init ; } +- AAuth.Agent.Governance.GovernanceOptions: public Func < ClarificationRequirement , CancellationToken , Task < ClarificationResponse > > ? OnClarificationRequired { get ; init ; } +- AAuth.Agent.Governance.GovernanceOptions: public Func < Interaction , CancellationToken , Task > ? OnInteractionRequired { get ; init ; } +- AAuth.Agent.Governance.GovernanceOptions: public int MaxClarificationRounds { get ; init ; } = ClarificationExchange . DefaultMaxRounds ++ AAuth.Agent.Governance.GovernanceOptions: public DeferredPollerOptions ? PollerOptions { get ; set ; } ++ AAuth.Agent.Governance.GovernanceOptions: public Func < ClarificationRequirement , CancellationToken , Task < ClarificationResponse > > ? OnClarificationRequired { get ; set ; } ++ AAuth.Agent.Governance.GovernanceOptions: public Func < Interaction , CancellationToken , Task > ? OnInteractionRequired { get ; set ; } ++ AAuth.Agent.Governance.GovernanceOptions: public int MaxClarificationRounds { get ; set ; } = ClarificationExchange . DefaultMaxRounds +``` + +Public owners: `AAuth.Agent.Governance.GovernanceOptions`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/InteractionClient.cs + +Concept/decision: [governance](#governance). Source: [InteractionClient.cs](../../../src/AAuth/Agent/Governance/InteractionClient.cs). + +```diff +- AAuth.Agent.Governance.InteractionClient: public Task < InteractionResult > RelayInteractionAsync ( string url , string code , string ? description = null , MissionClaim ? mission = null , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) +- AAuth.Agent.Governance.InteractionClient: public Task < InteractionResult > RelayPaymentAsync ( string url , string code , string ? description = null , MissionClaim ? mission = null , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) +- AAuth.Agent.Governance.InteractionClient: public async Task < bool > ProposeCompletionAsync ( string summary , MissionClaim mission , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) +- AAuth.Agent.Governance.InteractionClient: public async Task < string ? > AskQuestionAsync ( string question , string ? description = null , MissionClaim ? mission = null , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) ++ AAuth.Agent.Governance.InteractionClient: public Task < InteractionResult > RelayInteractionAsync ( string url , string code , string ? description = null , string ? missionS256 = null , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) ++ AAuth.Agent.Governance.InteractionClient: public Task < InteractionResult > RelayPaymentAsync ( string url , string code , string ? description = null , string ? missionS256 = null , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) ++ AAuth.Agent.Governance.InteractionClient: public async Task < string ? > AskQuestionAsync ( string question , string ? description = null , string ? missionS256 = null , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Agent.Governance.InteractionClient`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/InteractionRequest.cs + +Concept/decision: [governance](#governance). Source: [InteractionRequest.cs](../../../src/AAuth/Agent/Governance/InteractionRequest.cs). + +```diff +- AAuth.Agent.Governance.InteractionRequest: public MissionClaim ? Mission { get ; init ; } ++ AAuth.Agent.Governance.InteractionRequest: public string ? MissionS256 { get ; init ; } +``` + +Public owners: `AAuth.Agent.Governance.InteractionRequest`, `AAuth.Agent.Governance.InteractionType`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/InteractionResult.cs + +Concept/decision: [governance](#governance). Source: [InteractionResult.cs](../../../src/AAuth/Agent/Governance/InteractionResult.cs). + +Public signatures unchanged (6); behavior reviewed under governance. + +Public owners: `AAuth.Agent.Governance.InteractionResult`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/MissionClient.cs + +Concept/decision: [governance](#governance). Source: [MissionClient.cs](../../../src/AAuth/Agent/Governance/MissionClient.cs). + +```diff ++ AAuth.Agent.Governance.MissionClient: public async Task < bool > CompleteAsync ( Mission mission , string summary , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) ++ AAuth.Agent.Governance.MissionClient: public async Task < string > UpdateAsync ( Mission mission , string description , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Agent.Governance.MissionClient`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/MissionProposal.cs + +Concept/decision: [governance](#governance). Source: [MissionProposal.cs](../../../src/AAuth/Agent/Governance/MissionProposal.cs). + +```diff ++ AAuth.Agent.Governance.MissionProposal: public IReadOnlyList < string > Resources { get ; init ; } = Array . Empty < string > ( ) +``` + +Public owners: `AAuth.Agent.Governance.MissionProposal`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/MissionSession.cs + +Concept/decision: [governance](#governance). Source: [MissionSession.cs](../../../src/AAuth/Agent/Governance/MissionSession.cs). + +```diff ++ AAuth.Agent.Governance.MissionSession: public Task < string > UpdateAsync ( string description , GovernanceOptions ? options = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Agent.Governance.MissionSession`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/PermissionClient.cs + +Concept/decision: [governance](#governance). Source: [PermissionClient.cs](../../../src/AAuth/Agent/Governance/PermissionClient.cs). + +Public signatures unchanged (4); behavior reviewed under governance. + +Public owners: `AAuth.Agent.Governance.PermissionClient`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/Governance/PermissionRequest.cs + +Concept/decision: [governance](#governance). Source: [PermissionRequest.cs](../../../src/AAuth/Agent/Governance/PermissionRequest.cs). + +```diff +- AAuth.Agent.Governance.PermissionRequest: public MissionClaim ? Mission { get ; init ; } ++ AAuth.Agent.Governance.PermissionRequest: public string ? MissionS256 { get ; init ; } +``` + +Public owners: `AAuth.Agent.Governance.PermissionRequest`, `AAuth.Agent.Governance`. + +### src/AAuth/Agent/InteractionHandler.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [InteractionHandler.cs](../../../src/AAuth/Agent/InteractionHandler.cs). + +```diff +- AAuth.Agent.InteractionHandler: public InteractionHandler ( Func < string , string , CancellationToken , Task > ? onInteractionRequired = null , Func < CancellationToken , Task > ? onApprovalPending = null , TimeSpan ? pollingTimeout = null , TimeSpan ? defaultPollInterval = null , TimeSpan ? minPollInterval = null , int ? preferWaitSeconds = null , Action < HttpResponseMessage > ? onPoll = null ) ++ AAuth.Agent.InteractionHandler: public InteractionHandler ( Func < Interaction , CancellationToken , Task > ? onInteractionRequired = null , Func < CancellationToken , Task > ? onApprovalPending = null , TimeSpan ? pollingTimeout = null , TimeSpan ? defaultPollInterval = null , TimeSpan ? minPollInterval = null , int ? preferWaitSeconds = null , Action < HttpResponseMessage > ? onPoll = null ) ++ AAuth.Agent.InteractionHandler: public InteractionHandler ( IAAuthInteractionHandler ? interactionHandler , IAAuthDeferredObserver ? observer , TimeSpan ? pollingTimeout = null , TimeSpan ? defaultPollInterval = null , TimeSpan ? minPollInterval = null , int ? preferWaitSeconds = null ) +``` + +Public owners: `AAuth.Agent.InteractionHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/Mission.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [Mission.cs](../../../src/AAuth/Agent/Mission.cs). + +```diff +- AAuth.Agent.AAuthMissionHeader: public const string Name = "AAuth-Mission" ; +- AAuth.Agent.AAuthMissionHeader: public static bool TryParseStructured ( string ? value , out string ? approver , out string ? s256 , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Agent.AAuthMissionHeader: public static string FormatStructured ( string approver , string s256 ) +- AAuth.Agent.Mission: public required string Approver { get ; init ; } +- AAuth.Agent.Mission: public static Mission FromApprovalBytes ( ReadOnlySpan < byte > body ) +- AAuth.Agent: public static class AAuthMissionHeader ++ AAuth.Agent.Mission: public DateTimeOffset ? ExpiresAt { get ; init ; } ++ AAuth.Agent.Mission: public IReadOnlyDictionary < string , string > PersonTokens { get ; init ; } = new Dictionary < string , string > ( ) ++ AAuth.Agent.Mission: public IReadOnlyList < string > ApprovedResources { get ; init ; } = Array . Empty < string > ( ) ++ AAuth.Agent.Mission: public required string PersonServer { get ; init ; } ++ AAuth.Agent.Mission: public static Mission FromApprovalResponse ( ReadOnlySpan < byte > body , string personServer ) ++ AAuth.Agent.Mission: public static Mission FromBlob ( ReadOnlySpan < byte > blob , string personServer , IReadOnlyList < string > ? capabilities = null , IReadOnlyDictionary < string , string > ? personTokens = null ) +``` + +Public owners: `AAuth.Agent.AAuthMissionHeader`, `AAuth.Agent.Mission`, `AAuth.Agent`. + +### src/AAuth/Agent/MissionContextHandler.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [MissionContextHandler.cs](../../../src/AAuth/Agent/MissionContextHandler.cs). + +```diff ++ AAuth.Agent.MissionContextHandler: protected override Task < HttpResponseMessage > SendAsync ( HttpRequestMessage request , CancellationToken cancellationToken ) ++ AAuth.Agent.MissionContextHandler: public MissionContextHandler ( Mission mission ) ++ AAuth.Agent: public sealed class MissionContextHandler : DelegatingHandler +``` + +Public owners: `AAuth.Agent.MissionContextHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/MissionForwardingHandler.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [MissionForwardingHandler.cs](../../../src/AAuth/Agent/MissionForwardingHandler.cs). + +```diff +- AAuth.Agent.MissionForwardingHandler: public MissionForwardingHandler ( Func < string ? > upstreamTokenProvider ) ++ AAuth.Agent.MissionForwardingHandler: public MissionForwardingHandler ( System . Func < string ? > upstreamTokenProvider ) +``` + +Public owners: `AAuth.Agent.MissionForwardingHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/MissionHeaderHandler.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [MissionHeaderHandler.cs](../../../src/AAuth/Agent/MissionHeaderHandler.cs). + +```diff +- AAuth.Agent.MissionHeaderHandler: protected override Task < HttpResponseMessage > SendAsync ( HttpRequestMessage request , CancellationToken cancellationToken ) +- AAuth.Agent.MissionHeaderHandler: public MissionHeaderHandler ( Mission mission ) +- AAuth.Agent: public sealed class MissionHeaderHandler : DelegatingHandler +``` + +Public owners: `AAuth.Agent.MissionHeaderHandler`, `AAuth.Agent`. + +### src/AAuth/Agent/NamingJwtBuilder.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [NamingJwtBuilder.cs](../../../src/AAuth/Agent/NamingJwtBuilder.cs). + +```diff +- AAuth.Agent.NamingJwtBuilder: public static string Build ( IAAuthKey durableKey , IAAuthKey ephemeralKey ) ++ AAuth.Agent.NamingJwtBuilder: public static ValueTask < string > BuildAsync ( IAAuthSigner durableKey , IAAuthKey ephemeralKey , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Agent.NamingJwtBuilder`, `AAuth.Agent`. + +### src/AAuth/Agent/SelfIssuedTokenRefresher.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [SelfIssuedTokenRefresher.cs](../../../src/AAuth/Agent/SelfIssuedTokenRefresher.cs). + +```diff +- AAuth.Agent.SelfIssuedTokenRefresher: public SelfIssuedTokenRefresher ( IAAuthKey key , string issuer , string subject , string kid , string ? personServer = null , TimeSpan ? lifetime = null , AAuth . Discovery . AAuthEgressPolicy ? egressPolicy = null ) +- AAuth.Agent.SelfIssuedTokenRefresher: public static RefresherBuilder Create ( IAAuthKey key , string issuer , string subject ) ++ AAuth.Agent.SelfIssuedTokenRefresher: public SelfIssuedTokenRefresher ( IAAuthSigner key , string issuer , string subject , string kid , string ? personServer = null , TimeSpan ? lifetime = null , AAuth . Discovery . AAuthEgressPolicy ? egressPolicy = null ) ++ AAuth.Agent.SelfIssuedTokenRefresher: public static RefresherBuilder Create ( IAAuthSigner key , string issuer , string subject ) +``` + +Public owners: `AAuth.Agent.SelfIssuedTokenRefresher.RefresherBuilder`, `AAuth.Agent.SelfIssuedTokenRefresher`, `AAuth.Agent`. + +### src/AAuth/Agent/TokenExchangeClient.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [TokenExchangeClient.cs](../../../src/AAuth/Agent/TokenExchangeClient.cs). + +```diff +- AAuth.Agent.TokenExchangeClient: public Task < string > ExchangeAsync ( string personServer , string resourceToken , CancellationToken cancellationToken = default ) +- AAuth.Agent.TokenExchangeClient: public TokenExchangeClient ( HttpClient signedClient , MetadataClient metadata ) ++ AAuth.Agent.TokenExchangeClient: public Task < string > ExchangeAsync ( string personServer , string resourceToken , string presentedToken , CancellationToken cancellationToken = default ) ++ AAuth.Agent.TokenExchangeClient: public Task < string > RequestPersonTokenAsync ( string personServer , string resource , CancellationToken cancellationToken = default ) ++ AAuth.Agent.TokenExchangeClient: public TokenExchangeClient ( HttpClient signedClient , MetadataClient metadata , TokenExchangeClientOptions ? options = null ) ++ AAuth.Agent.TokenExchangeClient: public async Task < string > RequestPersonTokenAsync ( string personServer , string resource , TokenExchangeRequest options , CancellationToken cancellationToken = default ) ++ AAuth.Agent.TokenExchangeClientOptions: public JwksClient ? JwksClient { get ; init ; } ++ AAuth.Agent.TokenExchangeClientOptions: public bool VerifyAuthTokenSignature { get ; init ; } = true ++ AAuth.Agent: public sealed class TokenExchangeClientOptions +``` + +Public owners: `AAuth.Agent.TokenExchangeClientOptions`, `AAuth.Agent.TokenExchangeClient`, `AAuth.Agent`. + +### src/AAuth/Agent/TokenExchangeRequest.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [TokenExchangeRequest.cs](../../../src/AAuth/Agent/TokenExchangeRequest.cs). + +```diff ++ AAuth.Agent.TokenExchangeRequest: public string ? MissionS256 { get ; init ; } ++ AAuth.Agent.TokenExchangeRequest: public string ? PresentedToken { get ; init ; } +``` + +Public owners: `AAuth.Agent.TokenExchangeRequest`, `AAuth.Agent`. + +### src/AAuth/Crypto/AAuthKey.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthKey.cs](../../../src/AAuth/Crypto/AAuthKey.cs). + +```diff +- AAuth.Crypto: public sealed class AAuthKey : IAAuthKey ++ AAuth.Crypto.AAuthKey: public ValueTask < byte [ ] > SignAsync ( ReadOnlyMemory < byte > data , CancellationToken cancellationToken = default ) ++ AAuth.Crypto: public sealed class AAuthKey : IAAuthExportableKey +``` + +Public owners: `AAuth.Crypto.AAuthKey`, `AAuth.Crypto`. + +### src/AAuth/Crypto/AAuthSigningKeySet.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthSigningKeySet.cs](../../../src/AAuth/Crypto/AAuthSigningKeySet.cs). + +```diff ++ AAuth.Crypto.AAuthSigningKeySet: public ( string KeyId , IAAuthSigner Signer ) Active ++ AAuth.Crypto.AAuthSigningKeySet: public AAuthSigningKeySet ( string ? active = null ) ++ AAuth.Crypto.AAuthSigningKeySet: public AAuthSigningKeySet ( string keyId , IAAuthSigner signer ) ++ AAuth.Crypto.AAuthSigningKeySet: public AAuthSigningKeySet Activate ( string keyId ) ++ AAuth.Crypto.AAuthSigningKeySet: public AAuthSigningKeySet Add ( string keyId , IAAuthSigner signer ) ++ AAuth.Crypto.AAuthSigningKeySet: public IAAuthSigner this [ string keyId ] { get ; set ; } ++ AAuth.Crypto.AAuthSigningKeySet: public IEnumerator < KeyValuePair < string , IAAuthSigner > > GetEnumerator ( ) ++ AAuth.Crypto.AAuthSigningKeySet: public IReadOnlyList < string > KeyIds ++ AAuth.Crypto.AAuthSigningKeySet: public bool Remove ( string keyId ) ++ AAuth.Crypto.AAuthSigningKeySet: public bool TryGetSigner ( string keyId , [ NotNullWhen ( true ) ] out IAAuthSigner ? signer ) ++ AAuth.Crypto.AAuthSigningKeySet: public int Count ++ AAuth.Crypto.AAuthSigningKeySet: public string ActiveKeyId ++ AAuth.Crypto: public sealed class AAuthSigningKeySet : IReadOnlyCollection < KeyValuePair < string , IAAuthSigner > > +``` + +Public owners: `AAuth.Crypto.AAuthSigningKeySet`, `AAuth.Crypto`. + +### src/AAuth/Crypto/EcdsaAAuthKey.cs + +Concept/decision: [signatures](#signatures). Source: [EcdsaAAuthKey.cs](../../../src/AAuth/Crypto/EcdsaAAuthKey.cs). + +```diff +- AAuth.Crypto: public sealed class EcdsaAAuthKey : IAAuthKey ++ AAuth.Crypto.EcdsaAAuthKey: public ValueTask < byte [ ] > SignAsync ( ReadOnlyMemory < byte > data , CancellationToken cancellationToken = default ) ++ AAuth.Crypto: public sealed class EcdsaAAuthKey : IAAuthExportableKey +``` + +Public owners: `AAuth.Crypto.EcdsaAAuthKey`, `AAuth.Crypto`. + +### src/AAuth/Crypto/FileKeyStore.cs + +Concept/decision: [signatures](#signatures). Source: [FileKeyStore.cs](../../../src/AAuth/Crypto/FileKeyStore.cs). + +Public signatures unchanged (8); behavior reviewed under signatures. + +Public owners: `AAuth.Crypto.FileKeyStore`, `AAuth.Crypto`. + +### src/AAuth/Crypto/IAAuthKey.cs + +Concept/decision: [signatures](#signatures). Source: [IAAuthKey.cs](../../../src/AAuth/Crypto/IAAuthKey.cs). + +```diff +- AAuth.Crypto.IAAuthKey: JsonObject ToPrivateJwk ( ) +- AAuth.Crypto.IAAuthKey: byte [ ] Sign ( byte [ ] data ) +``` + +Public owners: `AAuth.Crypto.IAAuthKey`, `AAuth.Crypto`. + +### src/AAuth/Crypto/IAAuthSigner.cs + +Concept/decision: [signatures](#signatures). Source: [IAAuthSigner.cs](../../../src/AAuth/Crypto/IAAuthSigner.cs). + +```diff ++ AAuth.Crypto.IAAuthExportableKey: JsonObject ToPrivateJwk ( ) ++ AAuth.Crypto.IAAuthSigner: ValueTask < byte [ ] > SignAsync ( ReadOnlyMemory < byte > data , CancellationToken cancellationToken = default ) ++ AAuth.Crypto: public interface IAAuthExportableKey : IAAuthSigner ++ AAuth.Crypto: public interface IAAuthSigner : IAAuthKey +``` + +Public owners: `AAuth.Crypto.IAAuthExportableKey`, `AAuth.Crypto.IAAuthSigner`, `AAuth.Crypto`. + +### src/AAuth/Crypto/IKeyStore.cs + +Concept/decision: [signatures](#signatures). Source: [IKeyStore.cs](../../../src/AAuth/Crypto/IKeyStore.cs). + +```diff +- AAuth.Crypto.IKeyStore: Task < IAAuthKey ? > LoadAsync ( string handle , CancellationToken ct = default ) +- AAuth.Crypto.IKeyStore: Task StoreAsync ( string handle , IAAuthKey key , CancellationToken ct = default ) ++ AAuth.Crypto.IKeyStore: Task < IAAuthSigner ? > LoadAsync ( string handle , CancellationToken ct = default ) ++ AAuth.Crypto.IKeyStore: Task StoreAsync ( string handle , IAAuthSigner key , CancellationToken ct = default ) +``` + +Public owners: `AAuth.Crypto.IKeyStore`, `AAuth.Crypto`. + +### src/AAuth/Crypto/InMemoryKeyStore.cs + +Concept/decision: [signatures](#signatures). Source: [InMemoryKeyStore.cs](../../../src/AAuth/Crypto/InMemoryKeyStore.cs). + +```diff +- AAuth.Crypto.InMemoryKeyStore: public Task < IAAuthKey ? > LoadAsync ( string handle , CancellationToken ct = default ) +- AAuth.Crypto.InMemoryKeyStore: public Task StoreAsync ( string handle , IAAuthKey key , CancellationToken ct = default ) ++ AAuth.Crypto.InMemoryKeyStore: public Task < IAAuthSigner ? > LoadAsync ( string handle , CancellationToken ct = default ) ++ AAuth.Crypto.InMemoryKeyStore: public Task StoreAsync ( string handle , IAAuthSigner key , CancellationToken ct = default ) +``` + +Public owners: `AAuth.Crypto.InMemoryKeyStore`, `AAuth.Crypto`. + +### src/AAuth/Crypto/KeyFactory.cs + +Concept/decision: [signatures](#signatures). Source: [KeyFactory.cs](../../../src/AAuth/Crypto/KeyFactory.cs). + +```diff +- AAuth.Crypto.KeyFactory: public static IAAuthKey FromJwk ( JsonObject jwk ) ++ AAuth.Crypto.KeyFactory: public static IAAuthExportableKey FromJwk ( JsonObject jwk ) +``` + +Public owners: `AAuth.Crypto.KeyFactory`, `AAuth.Crypto`. + +### src/AAuth/DependencyInjection/AAuthAccessServerServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthAccessServerServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthAccessServerServiceCollectionExtensions.cs). + +```diff ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder Configure ( Action < AAuthAccessServerOptions > configure ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UsePendingStore ( Func < IServiceProvider , IAccessPendingStore > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UsePendingStore ( IAccessPendingStore store ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UsePendingStore < T > ( ) where T : class , IAccessPendingStore ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UsePolicy ( Func < IServiceProvider , IAccessPolicy > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UsePolicy ( IAccessPolicy policy ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UsePolicy < T > ( ) where T : class , IAccessPolicy ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UseTokenInventory ( IJtiStore inventory ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UseTokenInventory < T > ( ) where T : class , IJtiStore ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder UseTokenVerifier ( TokenVerifier verifier ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public AAuthAccessServerBuilder WithTrust ( Action < AAuthTrustOptions > configure ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public IServiceCollection Services { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public const string DefaultName = "AccessServer" ; ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder: public string Name { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerServiceCollectionExtensions: public const string ConfigurationSection = "AAuth:AccessServer" ; ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerServiceCollectionExtensions: public static AAuthAccessServerBuilder AddAAuthAccessServer ( this IServiceCollection services , IConfiguration configuration , string ? name = null , Action < AAuthAccessServerOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthAccessServerServiceCollectionExtensions: public static AAuthAccessServerBuilder AddAAuthAccessServer ( this IServiceCollection services , string ? name = null , Action < AAuthAccessServerOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection: public sealed class AAuthAccessServerBuilder ++ Microsoft.Extensions.DependencyInjection: public static class AAuthAccessServerServiceCollectionExtensions +``` + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthAccessServerBuilder`, `Microsoft.Extensions.DependencyInjection.AAuthAccessServerServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthAgentOptions.cs + +Concept/decision: [di](#di). Source: [AAuthAgentOptions.cs](../../../src/AAuth/DependencyInjection/AAuthAgentOptions.cs). + +```diff +- AAuth.AAuthAgentOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production +- AAuth.AAuthAgentOptions: public AAuth . HttpSig . ISignatureKeyProvider ? SignatureKeyProvider { get ; set ; } +- AAuth.AAuthAgentOptions: public Func < CancellationToken , Task > ? OnApprovalPending { get ; set ; } +- AAuth.AAuthAgentOptions: public Func < Interaction , CancellationToken , Task > ? OnInteractionRequired { get ; set ; } +- AAuth.AAuthAgentOptions: public Func < string , string , CancellationToken , Task > ? OnResourceInteraction { get ; set ; } +- AAuth.AAuthAgentOptions: public IAAuthKey Key { get ; set ; } = null ! +- AAuth.AAuthAgentOptions: public TimeSpan PollingTimeout { get ; set ; } = TimeSpan . FromMinutes ( 5 ) +- AAuth: public sealed class AAuthAgentOptions ++ AAuth.AAuthAgentOptions: public AAuthAgentProviderOptions AgentProvider { get ; set ; } = new ( ) ++ AAuth.AAuthAgentOptions: public AAuthEgressPolicy ? EgressPolicy { get ; set ; } ++ AAuth.AAuthAgentOptions: public AAuthJwksUriIdentityOptions JwksUri { get ; set ; } = new ( ) ++ AAuth.AAuthAgentOptions: public AAuthSelfIssuedAgentOptions SelfIssued { get ; set ; } = new ( ) ++ AAuth.AAuthAgentOptions: public AAuthTransportContract ? TransportContract { get ; set ; } ++ AAuth.AAuthAgentOptions: public Action < HttpRequestMessage , string > ? OnSignatureBase { get ; set ; } ++ AAuth.AAuthAgentOptions: public ChallengeHandlingOptions Challenge { get ; set ; } = new ( ) ++ AAuth.AAuthAgentOptions: public Func < string > ? AgentTokenFactory { get ; set ; } ++ AAuth.AAuthAgentOptions: public Func < string ? > ? UpstreamTokenProvider { get ; set ; } ++ AAuth.AAuthAgentOptions: public HttpMessageHandler ? InnerHandler { get ; set ; } ++ AAuth.AAuthAgentOptions: public IAAuthSigner ? Signer { get ; set ; } ++ AAuth.AAuthAgentOptions: public IAAuthTokenCache ? TokenCache { get ; set ; } ++ AAuth.AAuthAgentOptions: public ISignatureKeyProvider ? SignatureKeyProvider { get ; set ; } ++ AAuth.AAuthAgentOptions: public InteractionHandlingOptions Interaction { get ; set ; } = new ( ) ++ AAuth.AAuthAgentOptions: public Mission ? Mission { get ; set ; } ++ AAuth.AAuthAgentOptions: public TimeSpan ? TokenRefreshThreshold { get ; set ; } ++ AAuth.AAuthAgentOptions: public bool ? HandleChallenges { get ; set ; } ++ AAuth.AAuthAgentOptions: public bool ? HandleInteractions { get ; set ; } ++ AAuth.AAuthAgentOptions: public bool ChainFromHttpContext { get ; set ; } ++ AAuth.AAuthAgentOptions: public string ? KeyHandle { get ; set ; } ++ AAuth.AAuthAgentOptions: public string [ ] ? Capabilities { get ; set ; } ++ AAuth.AAuthAgentOptions: public string [ ] ? DevelopmentLoopbackOrigins { get ; set ; } ++ AAuth.AAuthAgentProviderOptions: public string ? RefreshEndpoint { get ; set ; } ++ AAuth.AAuthJwksUriIdentityOptions: public string ? Dwk { get ; set ; } ++ AAuth.AAuthJwksUriIdentityOptions: public string ? Id { get ; set ; } ++ AAuth.AAuthJwksUriIdentityOptions: public string ? KeyId { get ; set ; } ++ AAuth.AAuthSelfIssuedAgentOptions: public string ? Issuer { get ; set ; } ++ AAuth.AAuthSelfIssuedAgentOptions: public string ? KeyId { get ; set ; } ++ AAuth.AAuthSelfIssuedAgentOptions: public string ? Subject { get ; set ; } ++ AAuth: public class AAuthAgentOptions ++ AAuth: public sealed class AAuthAgentProviderOptions ++ AAuth: public sealed class AAuthJwksUriIdentityOptions ++ AAuth: public sealed class AAuthSelfIssuedAgentOptions +``` + +Public owners: `AAuth.AAuthAgentOptions`, `AAuth.AAuthAgentProviderOptions`, `AAuth.AAuthJwksUriIdentityOptions`, `AAuth.AAuthSelfIssuedAgentOptions`, `AAuth`. + +### src/AAuth/DependencyInjection/AAuthAgentServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthAgentServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthAgentServiceCollectionExtensions.cs). + +```diff +- Microsoft.Extensions.DependencyInjection.AAuthAgentServiceCollectionExtensions: public static IServiceCollection AddAAuthAgent ( this IServiceCollection services , string name , Action < AAuthAgentOptions > configure ) ++ Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder: public AAuthAgentBuilder Configure ( Action < AAuthAgentOptions > configure ) ++ Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder: public AAuthAgentBuilder WithAgentProvider ( Action < AAuthAgentProviderOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder: public AAuthAgentBuilder WithGovernance ( GovernanceOptions ? defaultOptions = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder: public IHttpClientBuilder HttpClientBuilder { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder: public IServiceCollection Services { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder: public string Name { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthAgentServiceCollectionExtensions: public const string ConfigurationSection = "AAuth:Agents" ; ++ Microsoft.Extensions.DependencyInjection.AAuthAgentServiceCollectionExtensions: public static AAuthAgentBuilder AddAAuthAgent ( this IServiceCollection services , string name , Action < AAuthAgentOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthAgentServiceCollectionExtensions: public static AAuthAgentBuilder AddAAuthAgent ( this IServiceCollection services , string name , IConfiguration configuration , Action < AAuthAgentOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthAgentServiceCollectionExtensions: public static IServiceCollection AddAAuthAgentFactory ( this IServiceCollection services ) ++ Microsoft.Extensions.DependencyInjection: public sealed class AAuthAgentBuilder +``` + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthAgentBuilder`, `Microsoft.Extensions.DependencyInjection.AAuthAgentServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthApplicationBuilderExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthApplicationBuilderExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthApplicationBuilderExtensions.cs). + +```diff +- Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions: public static IApplicationBuilder UseAAuthChallenge ( this IApplicationBuilder app , ChallengeOptions options ) +- Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions: public static IApplicationBuilder UseAAuthIntermediary ( this IApplicationBuilder app , AAuthVerificationOptions verificationOptions , ChallengeOptions challengeOptions ) +- Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions: public static IApplicationBuilder UseAAuthVerification ( this IApplicationBuilder app , AAuthVerificationOptions ? options = null ) ++ Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions: public static IApplicationBuilder UseAAuthChallenge ( this IApplicationBuilder app , Action < ChallengeOptions > ? configure = null ) ++ Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions: public static IApplicationBuilder UseAAuthIntermediary ( this IApplicationBuilder app , Action < AAuthVerificationOptions > ? configureVerification = null , Action < ChallengeOptions > ? configureChallenge = null ) ++ Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions: public static IApplicationBuilder UseAAuthVerification ( this IApplicationBuilder app , Action < AAuthVerificationOptions > ? configure = null ) +``` + +Public owners: `Microsoft.AspNetCore.Builder.AAuthApplicationBuilderExtensions`, `Microsoft.AspNetCore.Builder`. + +### src/AAuth/DependencyInjection/AAuthDiscoveryServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthDiscoveryServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthDiscoveryServiceCollectionExtensions.cs). + +Public signatures unchanged (2); behavior reviewed under di. + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthDiscoveryServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthFederationServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs). + +```diff +- Microsoft.Extensions.DependencyInjection.AAuthFederationServiceCollectionExtensions: public const string FederationHttpClientName = "aauth-federation" ; +- Microsoft.Extensions.DependencyInjection.AAuthFederationServiceCollectionExtensions: public static IServiceCollection AddAAuthFederation ( this IServiceCollection services , IAAuthKey personServerKey , string personServerIssuer , string personServerKeyId ) +- Microsoft.Extensions.DependencyInjection: public static class AAuthFederationServiceCollectionExtensions +``` + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthFederationServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthGovernanceApplicationBuilderExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthGovernanceApplicationBuilderExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthGovernanceApplicationBuilderExtensions.cs). + +Public signatures unchanged (2); behavior reviewed under di. + +Public owners: `Microsoft.AspNetCore.Builder.AAuthGovernanceApplicationBuilderExtensions`, `Microsoft.AspNetCore.Builder`. + +### src/AAuth/DependencyInjection/AAuthGovernanceClientServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthGovernanceClientServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthGovernanceClientServiceCollectionExtensions.cs). + +```diff +- Microsoft.Extensions.DependencyInjection.AAuthGovernanceClientServiceCollectionExtensions: public static IServiceCollection AddAAuthGovernanceClient ( this IServiceCollection services , Func < IServiceProvider , AAuthClientBuilder > configureBuilder , GovernanceOptions ? defaultOptions = null ) +- Microsoft.Extensions.DependencyInjection.AAuthGovernanceClientServiceCollectionExtensions: public static IServiceCollection AddAAuthGovernanceClient ( this IServiceCollection services , Func < IServiceProvider , AAuthGovernanceClient > factory ) +- Microsoft.Extensions.DependencyInjection: public static class AAuthGovernanceClientServiceCollectionExtensions +``` + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthGovernanceClientServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthGovernanceServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthGovernanceServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthGovernanceServiceCollectionExtensions.cs). + +Public signatures unchanged (4); behavior reviewed under di. + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthGovernanceServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthPersonServerServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthPersonServerServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthPersonServerServiceCollectionExtensions.cs). + +```diff ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder Configure ( Action < AAuthPersonServerOptions > configure ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseAgentPersonBindingStore ( Func < IServiceProvider , IAgentPersonBindingStore > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseAgentPersonBindingStore ( IAgentPersonBindingStore store ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseAgentPersonBindingStore < T > ( ) where T : class , IAgentPersonBindingStore ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseBillingRelationshipCache ( Func < IServiceProvider , IAAuthBillingRelationshipCache > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseBillingRelationshipCache ( IAAuthBillingRelationshipCache cache ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseBillingRelationshipCache < T > ( ) where T : class , IAAuthBillingRelationshipCache ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseClaimsAsserter ( Func < IServiceProvider , IIdentityClaimsAsserter > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseClaimsAsserter ( IIdentityClaimsAsserter asserter ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseClaimsAsserter < T > ( ) where T : class , IIdentityClaimsAsserter ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseCollocatedAccessServer ( Func < IServiceProvider , IAAuthCollapsedFederationPolicy > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseCollocatedAccessServer ( IAAuthCollapsedFederationPolicy policy ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseCollocatedAccessServer ( string resourceIssuer , string accessServerName = AAuthAccessServerBuilder . DefaultName , string ? expectedAccessServerIssuer = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePaymentSettler ( Func < IServiceProvider , IAAuthPaymentSettler > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePaymentSettler ( IAAuthPaymentSettler settler ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePaymentSettler < T > ( ) where T : class , IAAuthPaymentSettler ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePendingStore ( Func < IServiceProvider , IPersonPendingStore > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePendingStore ( IPersonPendingStore store ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePendingStore < T > ( ) where T : class , IPersonPendingStore ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePersonResourceEnrollmentStore ( Func < IServiceProvider , IPersonResourceEnrollmentStore > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePersonResourceEnrollmentStore ( IPersonResourceEnrollmentStore store ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePersonResourceEnrollmentStore < T > ( ) where T : class , IPersonResourceEnrollmentStore ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePersonSubjectDeriver ( Func < IServiceProvider , IPersonSubjectDeriver > factory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePersonSubjectDeriver ( IPersonSubjectDeriver deriver ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UsePersonSubjectDeriver < T > ( ) where T : class , IPersonSubjectDeriver ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseTokenInventory ( IJtiStore inventory ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseTokenInventory < T > ( ) where T : class , IJtiStore ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder UseTokenVerifier ( TokenVerifier verifier ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder WithFederation ( ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder WithGovernance ( ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public AAuthPersonServerBuilder WithTrust ( Action < AAuthTrustOptions > configure ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public IServiceCollection Services { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public const string DefaultName = "PersonServer" ; ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public const string FederationHttpClientName = "aauth-federation" ; ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder: public string Name { get ; } ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerServiceCollectionExtensions: public const string ConfigurationSection = "AAuth:PersonServer" ; ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerServiceCollectionExtensions: public static AAuthPersonServerBuilder AddAAuthPersonServer ( this IServiceCollection services , IConfiguration configuration , string ? name = null , Action < AAuthPersonServerOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection.AAuthPersonServerServiceCollectionExtensions: public static AAuthPersonServerBuilder AddAAuthPersonServer ( this IServiceCollection services , string ? name = null , Action < AAuthPersonServerOptions > ? configure = null ) ++ Microsoft.Extensions.DependencyInjection: public sealed class AAuthPersonServerBuilder ++ Microsoft.Extensions.DependencyInjection: public static class AAuthPersonServerServiceCollectionExtensions +``` + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthPersonServerBuilder`, `Microsoft.Extensions.DependencyInjection.AAuthPersonServerServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/DependencyInjection/AAuthResourceOptions.cs + +Concept/decision: [di](#di). Source: [AAuthResourceOptions.cs](../../../src/AAuth/DependencyInjection/AAuthResourceOptions.cs). + +```diff +- AAuth.AAuthResourceOptions: public Dictionary < string , IAAuthKey > SigningKeys { get ; set ; } = new ( ) +- AAuth.AAuthResourceOptions: public Func < DateTimeOffset > ? Clock { get ; set ; } +- AAuth.AAuthResourceOptions: public TimeSpan MaxFutureSkew { get ; set ; } = TimeSpan . FromSeconds ( 5 ) ++ AAuth.AAuthResourceOptions: public AAuthSigningKeySet SigningKeys { get ; set ; } = new ( ) ++ AAuth.AAuthResourceOptions: public Action < AAuth . Server . AAuthRevocationOptions > ? ConfigureRevocation { get ; set ; } ++ AAuth.AAuthResourceOptions: public IReadOnlyList < string > ? AdditionalSignatureComponents { get ; set ; } ++ AAuth.AAuthResourceOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.AAuthResourceOptions: public string ? AccessServer { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? DocumentationUri { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? KeyHandle { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? KeyId { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? LogoDarkUri { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? LogoUri { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? PolicyUri { get ; set ; } ++ AAuth.AAuthResourceOptions: public string ? TosUri { get ; set ; } +``` + +Public owners: `AAuth.AAuthResourceOptions`, `AAuth`. + +### src/AAuth/DependencyInjection/AAuthResourcePipelineOptions.cs + +Concept/decision: [di](#di). Source: [AAuthResourcePipelineOptions.cs](../../../src/AAuth/DependencyInjection/AAuthResourcePipelineOptions.cs). + +```diff +- AAuth.AAuthResourcePipelineOptions: public Func < string , bool > ? IsTrustedAgentProviderIssuer { get ; set ; } +- AAuth.AAuthResourcePipelineOptions: public Func < string , bool > ? IsTrustedAuthTokenIssuer { get ; set ; } +- AAuth.AAuthResourcePipelineOptions: public IReadOnlySet < string > ? TrustedAgentProviderIssuers { get ; set ; } +- AAuth.AAuthResourcePipelineOptions: public IReadOnlySet < string > ? TrustedAuthTokenIssuers { get ; set ; } ++ AAuth.AAuthResourcePipelineOptions: public AAuth . Server . AAuthTrustOptions Trust { get ; set ; } = new ( ) +``` + +Public owners: `AAuth.AAuthResourcePipelineOptions`, `AAuth`. + +### src/AAuth/DependencyInjection/AAuthResourceServiceCollectionExtensions.cs + +Concept/decision: [di](#di). Source: [AAuthResourceServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthResourceServiceCollectionExtensions.cs). + +```diff ++ Microsoft.Extensions.DependencyInjection.AAuthResourceServiceCollectionExtensions: public const string ConfigurationSection = "AAuth:Resource" ; ++ Microsoft.Extensions.DependencyInjection.AAuthResourceServiceCollectionExtensions: public static IServiceCollection AddAAuthResource ( this IServiceCollection services , IConfiguration configuration , Action < AAuthResourceOptions > ? configure = null ) +``` + +Public owners: `Microsoft.Extensions.DependencyInjection.AAuthResourceServiceCollectionExtensions`, `Microsoft.Extensions.DependencyInjection`. + +### src/AAuth/Discovery/AAuthEgressPolicy.cs + +Concept/decision: [discovery](#discovery). Source: [AAuthEgressPolicy.cs](../../../src/AAuth/Discovery/AAuthEgressPolicy.cs). + +Public signatures unchanged (14); behavior reviewed under discovery. + +Public owners: `AAuth.Discovery.AAuthEgressPolicy`, `AAuth.Discovery.IAAuthDnsResolver`, `AAuth.Discovery`. + +### src/AAuth/Discovery/AAuthHttpTransport.cs + +Concept/decision: [discovery](#discovery). Source: [AAuthHttpTransport.cs](../../../src/AAuth/Discovery/AAuthHttpTransport.cs). + +Public signatures unchanged (10); behavior reviewed under discovery. + +Public owners: `AAuth.Discovery.AAuthHttpTransport`, `AAuth.Discovery.AAuthTransportContract`, `AAuth.Discovery`. + +### src/AAuth/Discovery/JwksClient.cs + +Concept/decision: [discovery](#discovery). Source: [JwksClient.cs](../../../src/AAuth/Discovery/JwksClient.cs). + +```diff +- AAuth.Discovery.JwksClient: public JwksClient ( HttpClient ? http = null , TimeSpan ? cacheTtl = null , TimeSpan ? minRefreshInterval = null , Func < DateTimeOffset > ? clock = null , int maxCacheEntries = 1024 , TimeSpan ? maxCacheAge = null , AAuthEgressPolicy ? policy = null , AAuthTransportContract ? transportContract = null ) ++ AAuth.Discovery.JwksClient: public JwksClient ( HttpClient ? http = null , TimeSpan ? cacheTtl = null , TimeSpan ? minRefreshInterval = null , TimeProvider ? timeProvider = null , int maxCacheEntries = 1024 , TimeSpan ? maxCacheAge = null , AAuthEgressPolicy ? policy = null , AAuthTransportContract ? transportContract = null ) +``` + +Public owners: `AAuth.Discovery.JwksClient`, `AAuth.Discovery`. + +### src/AAuth/Discovery/MetadataClient.cs + +Concept/decision: [discovery](#discovery). Source: [MetadataClient.cs](../../../src/AAuth/Discovery/MetadataClient.cs). + +```diff +- AAuth.Discovery.MetadataClient: public MetadataClient ( HttpClient ? http = null , TimeSpan ? cacheTtl = null , Func < DateTimeOffset > ? clock = null , AAuthEgressPolicy ? policy = null , AAuthTransportContract ? transportContract = null , int maxCacheEntries = 1024 , TimeSpan ? maxCacheAge = null ) ++ AAuth.Discovery.MetadataClient: public MetadataClient ( HttpClient ? http = null , TimeSpan ? cacheTtl = null , TimeProvider ? timeProvider = null , AAuthEgressPolicy ? policy = null , AAuthTransportContract ? transportContract = null , int maxCacheEntries = 1024 , TimeSpan ? maxCacheAge = null ) +``` + +Public owners: `AAuth.Discovery.MetadataClient`, `AAuth.Discovery`. + +### src/AAuth/Discovery/ServerMetadata.cs + +Concept/decision: [discovery](#discovery). Source: [ServerMetadata.cs](../../../src/AAuth/Discovery/ServerMetadata.cs). + +```diff +- AAuth.Discovery.ServerMetadata: public string ? TokenEndpoint { get ; init ; } ++ AAuth.Discovery.ResourceMetadata: public IReadOnlyList < string > ? AdditionalSignatureComponents { get ; init ; } ++ AAuth.Discovery.ServerMetadata: public string ? AuthTokenEndpoint { get ; init ; } ++ AAuth.Discovery.ServerMetadata: public string ? PersonTokenEndpoint { get ; init ; } +``` + +Public owners: `AAuth.Discovery.MetadataClientExtensions`, `AAuth.Discovery.ResourceMetadata`, `AAuth.Discovery.ServerMetadata`, `AAuth.Discovery`. + +### src/AAuth/EnrolledBuilder.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [EnrolledBuilder.cs](../../../src/AAuth/EnrolledBuilder.cs). + +```diff +- AAuth.EnrolledBuilder: public EnrolledBuilder WithRefreshMode ( RefreshMode mode ) +``` + +Public owners: `AAuth.EnrolledBuilder`, `AAuth`. + +### src/AAuth/Errors/AAuthMissionTerminatedException.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthMissionTerminatedException.cs](../../../src/AAuth/Errors/AAuthMissionTerminatedException.cs). + +```diff +- AAuth.Errors.AAuthMissionTerminatedException: public AAuthMissionTerminatedException ( string ? missionStatus = null ) +- AAuth.Errors.AAuthMissionTerminatedException: public AAuthMissionTerminatedException ( string message , string ? missionStatus ) ++ AAuth.Errors.AAuthMissionTerminatedException: public AAuthMissionTerminatedException ( string ? missionStatus = null , string ? terminationReason = null ) ++ AAuth.Errors.AAuthMissionTerminatedException: public AAuthMissionTerminatedException ( string message , string ? missionStatus , string ? terminationReason = null ) ++ AAuth.Errors.AAuthMissionTerminatedException: public string ? TerminationReason { get ; } +``` + +Public owners: `AAuth.Errors.AAuthMissionTerminatedException`, `AAuth.Errors`. + +### src/AAuth/Errors/PollingError.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [PollingError.cs](../../../src/AAuth/Errors/PollingError.cs). + +```diff +- AAuth.Errors.PollingErrorException: public PollingErrorException ( PollingErrorCode errorCode , int statusCode , string ? message = null ) ++ AAuth.Errors.PollingErrorCode: Revoked ++ AAuth.Errors.PollingErrorException: public PollingErrorException ( PollingErrorCode errorCode , int statusCode , string ? message = null , string ? detail = null ) ++ AAuth.Errors.PollingErrorException: public string ? Detail { get ; } +``` + +Public owners: `AAuth.Errors.PollingErrorCode`, `AAuth.Errors.PollingErrorException`, `AAuth.Errors`. + +### src/AAuth/Errors/RevocationError.cs + +Concept/decision: [revocation](#revocation). Source: [RevocationError.cs](../../../src/AAuth/Errors/RevocationError.cs). + +```diff ++ AAuth.Errors.RevocationDownstreamError: RevocationUnavailable ++ AAuth.Errors.RevocationDownstreamError: RevocationUnsupported ++ AAuth.Errors.RevocationError: public static bool TryParseCode ( string ? code , out RevocationErrorCode result ) ++ AAuth.Errors.RevocationError: public static bool TryParseDownstream ( string ? code , out RevocationDownstreamError result ) ++ AAuth.Errors.RevocationError: public static int StatusCode ( RevocationErrorCode code ) ++ AAuth.Errors.RevocationError: public static string ToWireCode ( RevocationDownstreamError error ) ++ AAuth.Errors.RevocationError: public static string ToWireCode ( RevocationErrorCode code ) ++ AAuth.Errors.RevocationErrorCode: InvalidRequest ++ AAuth.Errors.RevocationErrorCode: RateLimited ++ AAuth.Errors.RevocationErrorCode: ServerError ++ AAuth.Errors.RevocationErrorCode: UnsupportedIss ++ AAuth.Errors: public enum RevocationDownstreamError ++ AAuth.Errors: public enum RevocationErrorCode ++ AAuth.Errors: public static class RevocationError +``` + +Public owners: `AAuth.Errors.RevocationDownstreamError`, `AAuth.Errors.RevocationErrorCode`, `AAuth.Errors.RevocationError`, `AAuth.Errors`. + +### src/AAuth/Errors/SignatureError.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [SignatureError.cs](../../../src/AAuth/Errors/SignatureError.cs). + +```diff ++ AAuth.Errors.SignatureErrorCode: ClockSkew ++ AAuth.Errors.SignatureErrorCode: RevokedJwt +``` + +Public owners: `AAuth.Errors.SignatureErrorCode`, `AAuth.Errors.SignatureError`, `AAuth.Errors`. + +### src/AAuth/Errors/TokenError.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [TokenError.cs](../../../src/AAuth/Errors/TokenError.cs). + +```diff +- AAuth.Errors.TokenErrorCode: InteractionRequired +- AAuth.Errors.TokenErrorCode: MissionTerminated ++ AAuth.Errors.TokenErrorCode: AsUnreachable ++ AAuth.Errors.TokenErrorCode: ClockSkew ++ AAuth.Errors.TokenErrorCode: ExpiredPresentedToken ++ AAuth.Errors.TokenErrorCode: ExpiredSubagentToken ++ AAuth.Errors.TokenErrorCode: ExpiredUpstreamToken ++ AAuth.Errors.TokenErrorCode: InvalidPresentedToken ++ AAuth.Errors.TokenErrorCode: InvalidSubagentToken ++ AAuth.Errors.TokenErrorCode: InvalidUpstreamToken ++ AAuth.Errors.TokenErrorCode: RevokedPresentedToken ++ AAuth.Errors.TokenErrorCode: RevokedResourceToken ++ AAuth.Errors.TokenErrorCode: RevokedSubagentToken ++ AAuth.Errors.TokenErrorCode: RevokedUpstreamToken +``` + +Public owners: `AAuth.Errors.TokenErrorCode`, `AAuth.Errors.TokenErrorResponse`, `AAuth.Errors`. + +### src/AAuth/Headers/AAuthRequirementHeader.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthRequirementHeader.cs](../../../src/AAuth/Headers/AAuthRequirementHeader.cs). + +```diff ++ AAuth.Headers.AAuthRequirementHeader: public const string PersonTokenRequirement = "person-token" ; ++ AAuth.Headers.AAuthRequirementHeader: public static string FormatPersonToken ( ) +``` + +Public owners: `AAuth.Headers.AAuthRequirementHeader.ParsedRequirement`, `AAuth.Headers.AAuthRequirementHeader`, `AAuth.Headers`. + +### src/AAuth/Headers/ClaimsRequirement.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [ClaimsRequirement.cs](../../../src/AAuth/Headers/ClaimsRequirement.cs). + +```diff ++ AAuth.Headers.ClaimsRequirement: public static bool ContainsForbiddenClaimName ( IEnumerable < string > ? names ) ++ AAuth.Headers.ClaimsRequirement: public static bool IsRequestableClaimName ( string name ) +``` + +Public owners: `AAuth.Headers.ClaimsRequirement`, `AAuth.Headers`. + +### src/AAuth/Headers/ClaimsResponse.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [ClaimsResponse.cs](../../../src/AAuth/Headers/ClaimsResponse.cs). + +```diff +- AAuth.Headers.ClaimsResponse: public required string Subject { get ; init ; } +``` + +Public owners: `AAuth.Headers.ClaimsResponse`, `AAuth.Headers`. + +### src/AAuth/Headers/ClarificationRequirement.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [ClarificationRequirement.cs](../../../src/AAuth/Headers/ClarificationRequirement.cs). + +Public signatures unchanged (6); behavior reviewed under server-contracts. + +Public owners: `AAuth.Headers.ClarificationRequirement`, `AAuth.Headers`. + +### src/AAuth/Headers/Interaction.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [Interaction.cs](../../../src/AAuth/Headers/Interaction.cs). + +```diff ++ AAuth.Headers.Interaction: public InteractionSource Source { get ; init ; } ++ AAuth.Headers.InteractionSource: PersonServer ++ AAuth.Headers.InteractionSource: Resource ++ AAuth.Headers: public enum InteractionSource +``` + +Public owners: `AAuth.Headers.InteractionSource`, `AAuth.Headers.Interaction`, `AAuth.Headers`. + +### src/AAuth/HttpSig/AAuthHttpClientExtensions.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthHttpClientExtensions.cs](../../../src/AAuth/HttpSig/AAuthHttpClientExtensions.cs). + +```diff +- AAuth.HttpSig.AAuthClientOptions: public IAAuthKey Key { get ; set ; } = null ! +- AAuth.HttpSig.AAuthClientOptions: public IReadOnlyList < string > ? Capabilities { get ; set ; } +- AAuth.HttpSig.AAuthClientOptions: public ISignatureKeyProvider SigningMode { get ; set ; } = null ! ++ AAuth.HttpSig.AAuthClientOptions: public IAAuthSigner ? Signer { get ; set ; } ++ AAuth.HttpSig.AAuthClientOptions: public ISignatureKeyProvider ? SignatureKeyProvider { get ; set ; } ++ AAuth.HttpSig.AAuthClientOptions: public string ? KeyHandle { get ; set ; } ++ AAuth.HttpSig.AAuthClientOptions: public string [ ] ? Capabilities { get ; set ; } +``` + +Public owners: `AAuth.HttpSig.AAuthClientOptions`, `AAuth.HttpSig.AAuthHttpClientExtensions`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/AAuthSigningHandler.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthSigningHandler.cs](../../../src/AAuth/HttpSig/AAuthSigningHandler.cs). + +```diff +- AAuth.HttpSig.AAuthSigningHandler: public AAuthSigningHandler ( IAAuthKey key , Func < string > tokenFactory , Func < DateTimeOffset > ? clock = null ) +- AAuth.HttpSig.AAuthSigningHandler: public AAuthSigningHandler ( IAAuthKey key , ISignatureKeyProvider signatureKeyProvider , Func < DateTimeOffset > ? clock = null ) +- AAuth.HttpSig.AAuthSigningHandler: public static HttpClient CreateClient ( IAAuthKey key , ISignatureKeyProvider provider , HttpMessageHandler ? innerHandler = null ) +- AAuth.HttpSig.AAuthSigningHandler: public void Sign ( HttpRequestMessage request ) ++ AAuth.HttpSig.AAuthSigningHandler: public AAuthSigningHandler ( IAAuthSigner key , Func < string > tokenFactory , TimeProvider ? timeProvider = null ) ++ AAuth.HttpSig.AAuthSigningHandler: public AAuthSigningHandler ( IAAuthSigner key , ISignatureKeyProvider signatureKeyProvider , TimeProvider ? timeProvider = null ) ++ AAuth.HttpSig.AAuthSigningHandler: public async Task SignHeadersAsync ( HttpRequestMessage request , CancellationToken cancellationToken = default ) ++ AAuth.HttpSig.AAuthSigningHandler: public static HttpClient CreateClient ( IAAuthSigner key , ISignatureKeyProvider provider , HttpMessageHandler ? innerHandler = null ) +``` + +Public owners: `AAuth.HttpSig.AAuthSigningHandler`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/AAuthVerifier.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthVerifier.cs](../../../src/AAuth/HttpSig/AAuthVerifier.cs). + +```diff +- AAuth.HttpSig.AAuthVerifier: public Func < DateTimeOffset > Clock { get ; init ; } = ( ) => DateTimeOffset . UtcNow +- AAuth.HttpSig.AAuthVerifier: public TimeSpan MaxFutureSkew { get ; init ; } = TimeSpan . FromSeconds ( 5 ) +- AAuth.HttpSig.AAuthVerifier: public string Verify ( string method , string authority , string path , string signatureKey , string signatureInput , string signatureHeader , IAAuthKey publicKey , string ? authorization = null , string ? mission = null , string label = "sig" , IReadOnlyDictionary < string , string > ? fields = null , IReadOnlyCollection < string > ? requiredComponents = null , string ? keyId = null , IReadOnlyDictionary < string , string [ ] > ? fieldValues = null , string ? requestScheme = null , string ? query = null , string ? requestTarget = null ) ++ AAuth.HttpSig.AAuthVerifier: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System ++ AAuth.HttpSig.AAuthVerifier: public string Verify ( string method , string authority , string path , string signatureKey , string signatureInput , string signatureHeader , IAAuthKey publicKey , string ? authorization = null , string label = "sig" , IReadOnlyDictionary < string , string > ? fields = null , IReadOnlyCollection < string > ? requiredComponents = null , string ? keyId = null , IReadOnlyDictionary < string , string [ ] > ? fieldValues = null , string ? requestScheme = null , string ? query = null , string ? requestTarget = null ) +``` + +Public owners: `AAuth.HttpSig.AAuthVerificationException`, `AAuth.HttpSig.AAuthVerifier`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/ChallengeHandlingOptions.cs + +Concept/decision: [signatures](#signatures). Source: [ChallengeHandlingOptions.cs](../../../src/AAuth/HttpSig/ChallengeHandlingOptions.cs). + +```diff +- AAuth.HttpSig.ChallengeHandlingOptions: public TimeSpan MinPollInterval { get ; set ; } = TimeSpan . FromMilliseconds ( 100 ) ++ AAuth.HttpSig.ChallengeHandlingOptions: public ChallengeHandlingOptions AddResourceMetadata ( ResourceMetadata metadata ) ++ AAuth.HttpSig.ChallengeHandlingOptions: public TimeSpan MinPollInterval { get ; set ; } = TimeSpan . Zero +``` + +Public owners: `AAuth.HttpSig.ChallengeHandlingOptions`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/DefaultSignatureKeyResolver.cs + +Concept/decision: [signatures](#signatures). Source: [DefaultSignatureKeyResolver.cs](../../../src/AAuth/HttpSig/DefaultSignatureKeyResolver.cs). + +```diff +- AAuth.HttpSig.DefaultSignatureKeyResolver: public DefaultSignatureKeyResolver ( JwksClient ? jwksClient = null , MetadataClient ? metadataClient = null , TokenVerifier ? tokenVerifier = null , IEnumerable < ISignatureTokenVerifier > ? tokenVerifiers = null ) ++ AAuth.HttpSig.DefaultSignatureKeyResolver: public DefaultSignatureKeyResolver ( JwksClient ? jwksClient = null , MetadataClient ? metadataClient = null , TokenVerifier ? tokenVerifier = null , IEnumerable < ISignatureTokenVerifier > ? tokenVerifiers = null , IServiceProvider ? services = null , string ? expectedDwk = null ) +``` + +Public owners: `AAuth.HttpSig.DefaultSignatureKeyResolver`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/ISignatureTokenVerifier.cs + +Concept/decision: [signatures](#signatures). Source: [ISignatureTokenVerifier.cs](../../../src/AAuth/HttpSig/ISignatureTokenVerifier.cs). + +```diff +- AAuth.HttpSig.ISignatureTokenVerifier: Task < TokenVerifier . VerifiedToken > VerifyAsync ( string jwt , IAAuthKey issuerKey , TokenVerifier verifier , CancellationToken cancellationToken ) ++ AAuth.HttpSig.ISignatureTokenVerifier: Task < TokenVerifier . VerifiedToken > VerifyAsync ( SignatureTokenVerificationContext context , CancellationToken cancellationToken ) ++ AAuth.HttpSig.ISignatureTokenVerifier: ValueTask < IAAuthKey ? > ResolveIssuerKeyAsync ( SignatureTokenIssuerKeyContext context , CancellationToken cancellationToken ) ++ AAuth.HttpSig.SignatureTokenIssuerKeyContext: public IServiceProvider ? Services { get ; init ; } ++ AAuth.HttpSig.SignatureTokenIssuerKeyContext: public string ? Dwk { get ; init ; } ++ AAuth.HttpSig.SignatureTokenIssuerKeyContext: public string ? ExpectedDwk { get ; init ; } ++ AAuth.HttpSig.SignatureTokenIssuerKeyContext: public string ? Issuer { get ; init ; } ++ AAuth.HttpSig.SignatureTokenIssuerKeyContext: public string ? Kid { get ; init ; } ++ AAuth.HttpSig.SignatureTokenVerificationContext: public IServiceProvider ? Services { get ; init ; } ++ AAuth.HttpSig.SignatureTokenVerificationContext: public string ? Dwk { get ; init ; } ++ AAuth.HttpSig.SignatureTokenVerificationContext: public string ? ExpectedDwk { get ; init ; } ++ AAuth.HttpSig.SignatureTokenVerificationContext: public string ? Issuer { get ; init ; } ++ AAuth.HttpSig.SignatureTokenVerificationContext: public string ? Kid { get ; init ; } ++ AAuth.HttpSig: public sealed record SignatureTokenIssuerKeyContext ( string Jwt , JsonObject Header , JsonObject Payload , string Scheme , string TokenType , TokenVerifier TokenVerifier ) ++ AAuth.HttpSig: public sealed record SignatureTokenVerificationContext ( string Jwt , JsonObject Header , JsonObject Payload , string Scheme , string TokenType , IAAuthKey IssuerKey , TokenVerifier TokenVerifier ) +``` + +Public owners: `AAuth.HttpSig.ISignatureTokenVerifier`, `AAuth.HttpSig.SignatureTokenIssuerKeyContext`, `AAuth.HttpSig.SignatureTokenVerificationContext`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/InteractionHandlingOptions.cs + +Concept/decision: [signatures](#signatures). Source: [InteractionHandlingOptions.cs](../../../src/AAuth/HttpSig/InteractionHandlingOptions.cs). + +```diff +- AAuth.HttpSig.InteractionHandlingOptions: public Func < string , string , CancellationToken , Task > ? OnInteractionRequired { get ; set ; } +- AAuth.HttpSig.InteractionHandlingOptions: public TimeSpan MinPollInterval { get ; set ; } = TimeSpan . FromMilliseconds ( 100 ) ++ AAuth.HttpSig.InteractionHandlingOptions: public Func < AAuth . Headers . Interaction , CancellationToken , Task > ? OnInteractionRequired { get ; set ; } ++ AAuth.HttpSig.InteractionHandlingOptions: public TimeSpan MinPollInterval { get ; set ; } = TimeSpan . Zero +``` + +Public owners: `AAuth.HttpSig.InteractionHandlingOptions`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/NamingTokenVerifier.cs + +Concept/decision: [signatures](#signatures). Source: [NamingTokenVerifier.cs](../../../src/AAuth/HttpSig/NamingTokenVerifier.cs). + +Public signatures unchanged (3); behavior reviewed under signatures. + +Public owners: `AAuth.HttpSig.NamingTokenVerifier`, `AAuth.HttpSig`. + +### src/AAuth/HttpSig/SignatureKeyHeader.cs + +Concept/decision: [signatures](#signatures). Source: [SignatureKeyHeader.cs](../../../src/AAuth/HttpSig/SignatureKeyHeader.cs). + +Public signatures unchanged (10); behavior reviewed under signatures. + +Public owners: `AAuth.HttpSig.SignatureKeyHeader`, `AAuth.HttpSig`. + +### src/AAuth/Identifiers/AgentId.cs + +Concept/decision: [discovery](#discovery). Source: [AgentId.cs](../../../src/AAuth/Identifiers/AgentId.cs). + +Public signatures unchanged (14); behavior reviewed under discovery. + +Public owners: `AAuth.Identifiers.AgentId`, `AAuth.Identifiers`. + +### src/AAuth/Person/AAuthCollapsedFederation.cs + +Concept/decision: [consent](#consent). Source: [AAuthCollapsedFederation.cs](../../../src/AAuth/Person/AAuthCollapsedFederation.cs). + +```diff ++ AAuth.Person.AAuthCollapsedFederationContext: public required HttpContext HttpContext { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required JsonObject ResourceTokenPayload { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required System . IServiceProvider Services { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required TokenVerifier . VerifiedToken PresentedToken { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required string PersonServerIssuer { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required string PersonServerName { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required string ResourceIssuer { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public required string Scope { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationContext: public string ? Account { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationDecision: public bool Declared { get ; } ++ AAuth.Person.AAuthCollapsedFederationDecision: public static AAuthCollapsedFederationDecision Declare ( string accessServerName , string expectedAccessServerIssuer ) ++ AAuth.Person.AAuthCollapsedFederationDecision: public static AAuthCollapsedFederationDecision NotDeclared { get ; } = new ( false , null , null ) ++ AAuth.Person.AAuthCollapsedFederationDecision: public string ? AccessServerName { get ; } ++ AAuth.Person.AAuthCollapsedFederationDecision: public string ? ExpectedAccessServerIssuer { get ; } ++ AAuth.Person.AAuthCollapsedFederationDeclaration: public required string ExpectedAccessServerIssuer { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationDeclaration: public required string ResourceIssuer { get ; init ; } ++ AAuth.Person.AAuthCollapsedFederationDeclaration: public string AccessServerName { get ; init ; } = Microsoft . Extensions . DependencyInjection . AAuthAccessServerBuilder . DefaultName ++ AAuth.Person.IAAuthCollapsedFederationPolicy: ValueTask < AAuthCollapsedFederationDecision > EvaluateAsync ( AAuthCollapsedFederationContext context , CancellationToken cancellationToken = default ) ++ AAuth.Person: public interface IAAuthCollapsedFederationPolicy ++ AAuth.Person: public sealed class AAuthCollapsedFederationContext ++ AAuth.Person: public sealed class AAuthCollapsedFederationDecision ++ AAuth.Person: public sealed class AAuthCollapsedFederationDeclaration +``` + +Public owners: `AAuth.Person.AAuthCollapsedFederationContext`, `AAuth.Person.AAuthCollapsedFederationDecision`, `AAuth.Person.AAuthCollapsedFederationDeclaration`, `AAuth.Person.IAAuthCollapsedFederationPolicy`, `AAuth.Person`. + +### src/AAuth/Person/AAuthPersonKey.cs + +Concept/decision: [consent](#consent). Source: [AAuthPersonKey.cs](../../../src/AAuth/Person/AAuthPersonKey.cs). + +```diff ++ AAuth.Person.AAuthPersonKey: public AAuthPersonKey ( string value ) ++ AAuth.Person.AAuthPersonKey: public override string ToString ( ) ++ AAuth.Person.AAuthPersonKey: public string Value { get ; } ++ AAuth.Person: public readonly record struct AAuthPersonKey +``` + +Public owners: `AAuth.Person.AAuthPersonKey`, `AAuth.Person`. + +### src/AAuth/Person/AAuthPersonServerEndpoints.cs + +Concept/decision: [consent](#consent). Source: [AAuthPersonServerEndpoints.cs](../../../src/AAuth/Person/AAuthPersonServerEndpoints.cs). + +```diff +- AAuth.Person.AAuthPersonServerEndpoints: public static WebApplication MapAAuthPersonServer ( this WebApplication app , AAuthPersonServerOptions options ) +- AAuth.Person.AAuthPersonServerOptions: public AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuthEgressPolicy . Production +- AAuth.Person.AAuthPersonServerOptions: public Action < AAuthRevocationOptions > ? ConfigureRevocation { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public BrowserConsentSessions ? ResourceInteractionSessions { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public Func < PersonPendingEntry , ClarificationRequirement , System . Threading . CancellationToken , Task < ClarificationResponse ? > > ? TriageClarificationAsync { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public Func < string , bool > ? IsTrustedAccessServer { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public IReadOnlyCollection < string > ? TrustedAccessServers { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public IReadOnlyCollection < string > ? UnsignedPathPrefixes { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public IReadOnlyList < string > ? ScopesSupported { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System +- AAuth.Person.AAuthPersonServerOptions: public required IReadOnlyDictionary < string , IAAuthKey > SigningKeys { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public required string Issuer { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public string ? AuditEndpoint { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public string ? InteractionEndpoint { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public string ? MissionEndpoint { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public string ? PermissionEndpoint { get ; init ; } +- AAuth.Person.AAuthPersonServerOptions: public string DefaultScope { get ; init ; } = "" +- AAuth.Person.AAuthPersonServerOptions: public string InteractionPath { get ; init ; } = "/interaction" +- AAuth.Person.AAuthPersonServerOptions: public string PendingPathPrefix { get ; init ; } = "/pending" +- AAuth.Person.AAuthPersonServerOptions: public string RevocationPath { get ; init ; } = "/revoke" +- AAuth.Person.AAuthPersonServerOptions: public string TokenPath { get ; init ; } = "/token" ++ AAuth.Person.AAuthPersonServerEndpoints: public static WebApplication MapAAuthPersonServer ( this WebApplication app , string ? name = null ) ++ AAuth.Person.AAuthPersonServerOptions: public AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuthEgressPolicy . Production ++ AAuth.Person.AAuthPersonServerOptions: public AAuthSigningKeySet SigningKeys { get ; set ; } = new ( ) ++ AAuth.Person.AAuthPersonServerOptions: public AAuthTrustOptions Trust { get ; set ; } = new ( ) ++ AAuth.Person.AAuthPersonServerOptions: public Action < AAuthRevocationOptions > ? ConfigureRevocation { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public BrowserConsentSessions ? ResourceInteractionSessions { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public Func < PersonPendingEntry , ClarificationRequirement , System . Threading . CancellationToken , Task < ClarificationResponse ? > > ? TriageClarificationAsync { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public IDictionary < string , string > PairwiseSubjectSecrets { get ; } = new Dictionary < string , string > ( StringComparer . Ordinal ) ++ AAuth.Person.AAuthPersonServerOptions: public IList < AAuthCollapsedFederationDeclaration > CollapsedFederation { get ; } = new List < AAuthCollapsedFederationDeclaration > ( ) ++ AAuth.Person.AAuthPersonServerOptions: public IReadOnlyCollection < string > ? UnsignedPathPrefixes { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public IReadOnlyList < string > ? ScopesSupported { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Person.AAuthPersonServerOptions: public bool MatchIssuerHost { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? ActivePairwiseSubjectKeyId { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? AuditPath { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? InteractionEndpointPath { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? KeyHandle { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? KeyId { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? MissionPath { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string ? PermissionPath { get ; set ; } ++ AAuth.Person.AAuthPersonServerOptions: public string DefaultScope { get ; set ; } = "" ++ AAuth.Person.AAuthPersonServerOptions: public string InteractionPath { get ; set ; } = "/interaction" ++ AAuth.Person.AAuthPersonServerOptions: public string Issuer { get ; set ; } = "" ++ AAuth.Person.AAuthPersonServerOptions: public string PendingPathPrefix { get ; set ; } = "/pending" ++ AAuth.Person.AAuthPersonServerOptions: public string PersonTokenPath { get ; set ; } = "/person" ++ AAuth.Person.AAuthPersonServerOptions: public string RevocationPath { get ; set ; } = "/revoke" ++ AAuth.Person.AAuthPersonServerOptions: public string TokenPath { get ; set ; } = "/token" +``` + +Public owners: `AAuth.Person.AAuthPersonServerEndpoints`, `AAuth.Person.AAuthPersonServerOptions`, `AAuth.Person`. + +### src/AAuth/Person/AgentAssertedContent.cs + +Concept/decision: [consent](#consent). Source: [AgentAssertedContent.cs](../../../src/AAuth/Person/AgentAssertedContent.cs). + +```diff ++ AAuth.Person.AgentAssertedContent: public string ? Device { get ; init ; } ++ AAuth.Person.AgentAssertedContent: public string ? Justification { get ; init ; } ++ AAuth.Person.AgentAssertedContent: public string ? Platform { get ; init ; } ++ AAuth.Person: public sealed record AgentAssertedContent +``` + +Public owners: `AAuth.Person.AgentAssertedContent`, `AAuth.Person`. + +### src/AAuth/Person/AgentPersonBinding.cs + +Concept/decision: [consent](#consent). Source: [AgentPersonBinding.cs](../../../src/AAuth/Person/AgentPersonBinding.cs). + +```diff ++ AAuth.Person.AgentPersonBinding: public static Task RevokeAsync ( IJtiStore inventory , AgentPersonBindingRecord binding , CancellationToken cancellationToken = default ) ++ AAuth.Person.AgentPersonBinding: public static TokenKey Key ( string personServer , string agentIssuer , string agentId , long generation ) ++ AAuth.Person.AgentPersonBinding: public static async Task < AgentPersonBindingRecord ? > RevokeAsync ( IJtiStore inventory , IAgentPersonBindingStore bindingStore , string personServer , string agentIssuer , string agentId , CancellationToken cancellationToken = default ) ++ AAuth.Person: public static class AgentPersonBinding +``` + +Public owners: `AAuth.Person.AgentPersonBinding`, `AAuth.Person`. + +### src/AAuth/Person/AgentPersonBindingStore.cs + +Concept/decision: [consent](#consent). Source: [AgentPersonBindingStore.cs](../../../src/AAuth/Person/AgentPersonBindingStore.cs). + +```diff ++ AAuth.Person.AgentPersonBindingRecord: public AAuth . Server . TokenKey InventoryKey ++ AAuth.Person.IAgentPersonBindingStore: Task < AgentPersonBindingRecord ? > BindOrVerifyAsync ( AgentPersonBindingContext binding , CancellationToken cancellationToken = default ) ++ AAuth.Person.IAgentPersonBindingStore: Task < AgentPersonBindingRecord ? > GetAsync ( string personServer , string agentIssuer , string agentId , CancellationToken cancellationToken = default ) ++ AAuth.Person.IAgentPersonBindingStore: Task < AgentPersonBindingRecord ? > RevokeAsync ( string personServer , string agentIssuer , string agentId , CancellationToken cancellationToken = default ) ++ AAuth.Person.InMemoryAgentPersonBindingStore: public Task < AgentPersonBindingRecord ? > BindOrVerifyAsync ( AgentPersonBindingContext binding , CancellationToken cancellationToken = default ) ++ AAuth.Person.InMemoryAgentPersonBindingStore: public Task < AgentPersonBindingRecord ? > GetAsync ( string personServer , string agentIssuer , string agentId , CancellationToken cancellationToken = default ) ++ AAuth.Person.InMemoryAgentPersonBindingStore: public Task < AgentPersonBindingRecord ? > RevokeAsync ( string personServer , string agentIssuer , string agentId , CancellationToken cancellationToken = default ) ++ AAuth.Person: public interface IAgentPersonBindingStore ++ AAuth.Person: public sealed class InMemoryAgentPersonBindingStore : IAgentPersonBindingStore ++ AAuth.Person: public sealed record AgentPersonBindingContext ( string PersonServer , string AgentIssuer , string AgentId , AAuthPersonKey PersonKey ) ++ AAuth.Person: public sealed record AgentPersonBindingRecord ( string PersonServer , string AgentIssuer , string AgentId , AAuthPersonKey PersonKey , long Generation ) +``` + +Public owners: `AAuth.Person.AgentPersonBindingRecord`, `AAuth.Person.IAgentPersonBindingStore`, `AAuth.Person.InMemoryAgentPersonBindingStore`, `AAuth.Person`. + +### src/AAuth/Person/IIdentityClaimsAsserter.cs + +Concept/decision: [consent](#consent). Source: [IIdentityClaimsAsserter.cs](../../../src/AAuth/Person/IIdentityClaimsAsserter.cs). + +```diff +- AAuth.Person.DefaultIdentityClaimsAsserter: public DefaultIdentityClaimsAsserter ( string subject = "pairwise-sub" ) +- AAuth.Person.IdentityAssertion: public static IdentityAssertion Assert ( string subject , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) +- AAuth.Person.IdentityAssertion: public static IdentityAssertion NeedsConsent ( ) +- AAuth.Person.IdentityAssertionRequest: public MissionClaim ? Mission { get ; init ; } ++ AAuth.Person.DefaultIdentityClaimsAsserter: public DefaultIdentityClaimsAsserter ( string personKey = "demo-person" ) ++ AAuth.Person.IdentityAssertion: public AAuthPersonKey ? PersonKey { get ; } ++ AAuth.Person.IdentityAssertion: public static IdentityAssertion Assert ( AAuthPersonKey personKey , string ? subject = null , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) ++ AAuth.Person.IdentityAssertion: public static IdentityAssertion NeedsConsent ( AAuthPersonKey ? personKey = null ) ++ AAuth.Person.IdentityAssertionRequest: public AAuthPersonKey ? PersonKey { get ; init ; } ++ AAuth.Person.IdentityAssertionRequest: public AgentAssertedContent ? AgentAsserted { get ; init ; } ++ AAuth.Person.IdentityAssertionRequest: public bool PersonTokenRequest { get ; init ; } ++ AAuth.Person.IdentityAssertionRequest: public string ? LoginHint { get ; init ; } ++ AAuth.Person.IdentityAssertionRequest: public string ? MissionS256 { get ; init ; } ++ AAuth.Person.IdentityAssertionRequest: public string ? Subject { get ; init ; } ++ AAuth.Person.IdentityAssertionRequest: public string AgentIssuer { get ; init ; } = "" +``` + +Public owners: `AAuth.Person.DefaultIdentityClaimsAsserter`, `AAuth.Person.IIdentityClaimsAsserter`, `AAuth.Person.IdentityAssertionKind`, `AAuth.Person.IdentityAssertionRequest`, `AAuth.Person.IdentityAssertion`, `AAuth.Person`. + +### src/AAuth/Person/IPersonPendingStore.cs + +Concept/decision: [consent](#consent). Source: [IPersonPendingStore.cs](../../../src/AAuth/Person/IPersonPendingStore.cs). + +```diff +- AAuth.Person.IPersonPendingStore: PersonPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey ? agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? upstreamAct = null , MissionClaim ? mission = null , DateTimeOffset ? authorizationExpiresAt = null ) +- AAuth.Person.IPersonPendingStore: void MarkAllowed ( string id , string subject , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) +- AAuth.Person.InMemoryPersonPendingStore: public PersonPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey ? agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , JsonObject ? upstreamAct = null , MissionClaim ? mission = null , DateTimeOffset ? authorizationExpiresAt = null ) +- AAuth.Person.InMemoryPersonPendingStore: public void MarkAllowed ( string id , string subject , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) +- AAuth.Person.PersonPendingEntry: public IReadOnlyList < AAuth . Server . TokenKey > SourceTokens { get ; set ; } = [ ] +- AAuth.Person.PersonPendingEntry: public JsonObject ? UpstreamAct { get ; init ; } +- AAuth.Person.PersonPendingEntry: public MissionClaim ? Mission { get ; set ; } ++ AAuth.Person.IPersonPendingObserver: void OnParked ( PersonPendingEntry entry ) ++ AAuth.Person.IPersonPendingStore: PersonPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey ? agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , string ? missionS256 = null , DateTimeOffset ? authorizationExpiresAt = null ) ++ AAuth.Person.IPersonPendingStore: void MarkAllowed ( string id , AAuthPersonKey personKey , string ? subject = null , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) ++ AAuth.Person.InMemoryPersonPendingStore: public PersonPendingEntry Add ( string resourceUrl , string scope , string agentId , IAAuthKey ? agentConfirmationKey , DateTimeOffset agentTokenExpiresAt , string ? missionS256 = null , DateTimeOffset ? authorizationExpiresAt = null ) ++ AAuth.Person.InMemoryPersonPendingStore: public void MarkAllowed ( string id , AAuthPersonKey personKey , string ? subject = null , string ? tenant = null , IReadOnlyList < string > ? roles = null , IReadOnlyList < string > ? groups = null , IReadOnlyDictionary < string , JsonNode ? > ? additionalClaims = null ) ++ AAuth.Person.PersonPendingEntry: public AAuthPersonKey ? PersonKey { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public AgentAssertedContent ? AgentAsserted { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public IReadOnlyList < AAuth . Server . TokenRegistration > SourceTokens { get ; set ; } = [ ] ++ AAuth.Person.PersonPendingEntry: public JsonObject ? ResourceMetadata { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public bool PersonToken { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public string ? ErrorDetail { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public string ? MissionS256 { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public string ? PersonSubject { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public string ? PersonTenant { get ; set ; } ++ AAuth.Person.PersonPendingEntry: public string ? PresentedToken { get ; set ; } ++ AAuth.Person: public interface IPersonPendingObserver +``` + +Public owners: `AAuth.Person.IPersonPendingObserver`, `AAuth.Person.IPersonPendingStore`, `AAuth.Person.InMemoryPersonPendingStore`, `AAuth.Person.PersonPendingEntry`, `AAuth.Person.PersonPendingStatus`, `AAuth.Person`. + +### src/AAuth/Person/PersonResourceEnrollmentStore.cs + +Concept/decision: [consent](#consent). Source: [PersonResourceEnrollmentStore.cs](../../../src/AAuth/Person/PersonResourceEnrollmentStore.cs). + +```diff ++ AAuth.Person.IPersonResourceEnrollmentStore: Task < PersonResourceEnrollment ? > FindBySubjectAsync ( string personServer , string resource , string directedSubject , CancellationToken cancellationToken = default ) ++ AAuth.Person.IPersonResourceEnrollmentStore: Task < PersonResourceEnrollment ? > GetAsync ( string personServer , AAuthPersonKey personKey , string resource , CancellationToken cancellationToken = default ) ++ AAuth.Person.IPersonResourceEnrollmentStore: Task < bool > RecordAsync ( PersonResourceEnrollment enrollment , CancellationToken cancellationToken = default ) ++ AAuth.Person.InMemoryPersonResourceEnrollmentStore: public Task < PersonResourceEnrollment ? > FindBySubjectAsync ( string personServer , string resource , string directedSubject , CancellationToken cancellationToken = default ) ++ AAuth.Person.InMemoryPersonResourceEnrollmentStore: public Task < PersonResourceEnrollment ? > GetAsync ( string personServer , AAuthPersonKey personKey , string resource , CancellationToken cancellationToken = default ) ++ AAuth.Person.InMemoryPersonResourceEnrollmentStore: public Task < bool > RecordAsync ( PersonResourceEnrollment enrollment , CancellationToken cancellationToken = default ) ++ AAuth.Person.PersonResourceEnrollment: public JsonObject ? ResourceMetadata { get ; init ; } ++ AAuth.Person: public interface IPersonResourceEnrollmentStore ++ AAuth.Person: public sealed class InMemoryPersonResourceEnrollmentStore : IPersonResourceEnrollmentStore ++ AAuth.Person: public sealed record PersonResourceEnrollment ( string PersonServer , AAuthPersonKey PersonKey , string Resource , string DirectedSubject , string SubjectKeyId , DateTimeOffset ApprovedAt ) +``` + +Public owners: `AAuth.Person.IPersonResourceEnrollmentStore`, `AAuth.Person.InMemoryPersonResourceEnrollmentStore`, `AAuth.Person.PersonResourceEnrollment`, `AAuth.Person`. + +### src/AAuth/Person/PersonSubjectDeriver.cs + +Concept/decision: [consent](#consent). Source: [PersonSubjectDeriver.cs](../../../src/AAuth/Person/PersonSubjectDeriver.cs). + +```diff ++ AAuth.Person.HmacPersonSubjectDeriver: public HmacPersonSubjectDeriver ( IOptionsMonitor < AAuthPersonServerOptions > options , string name ) ++ AAuth.Person.HmacPersonSubjectDeriver: public Task < DerivedPersonSubject > DeriveAsync ( string personServer , AAuthPersonKey personKey , string resource , CancellationToken cancellationToken = default ) ++ AAuth.Person.IPersonSubjectDeriver: Task < DerivedPersonSubject > DeriveAsync ( string personServer , AAuthPersonKey personKey , string resource , CancellationToken cancellationToken = default ) ++ AAuth.Person: public interface IPersonSubjectDeriver ++ AAuth.Person: public sealed class HmacPersonSubjectDeriver : IPersonSubjectDeriver ++ AAuth.Person: public sealed record DerivedPersonSubject ( string Subject , string KeyId ) +``` + +Public owners: `AAuth.Person.HmacPersonSubjectDeriver`, `AAuth.Person.IPersonSubjectDeriver`, `AAuth.Person`. + +### src/AAuth/SelfIssuingBuilder.cs + +Concept/decision: [agent-clients](#agent-clients). Source: [SelfIssuingBuilder.cs](../../../src/AAuth/SelfIssuingBuilder.cs). + +Public signatures unchanged (19); behavior reviewed under agent-clients. + +Public owners: `AAuth.SelfIssuingBuilder`, `AAuth`. + +### src/AAuth/Server/AAuthAuthorizationRequest.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthAuthorizationRequest.cs](../../../src/AAuth/Server/AAuthAuthorizationRequest.cs). + +```diff +- AAuth.Server: public sealed record AAuthAuthorizationRequest ( string Scope , AAuthVerificationResult Verification ) ++ AAuth.Server.AAuthAuthorizationRequest: public IDictionary < string , object ? > Features { get ; } = new Dictionary < string , object ? > ( StringComparer . Ordinal ) ++ AAuth.Server: public sealed record AAuthAuthorizationRequest ( string ? Scope , AAuthVerificationResult Verification ) +``` + +Public owners: `AAuth.Server.AAuthAuthorizationRequest`, `AAuth.Server`. + +### src/AAuth/Server/AAuthProblemDetails.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthProblemDetails.cs](../../../src/AAuth/Server/AAuthProblemDetails.cs). + +```diff ++ AAuth.Server.AAuthProblemDetails: public static IResult Polling ( PollingErrorCode code , string ? detail = null , IDictionary < string , object ? > ? extensions = null ) ++ AAuth.Server.AAuthProblemDetails: public static IResult SourceExpired ( IEnumerable < TokenRegistration > sources , DateTimeOffset now , IResult ? otherwise = null ) ++ AAuth.Server.AAuthProblemDetails: public static IResult SourceRevoked ( Tokens . TokenVerificationException exception ) ++ AAuth.Server.AAuthProblemDetails: public static IResult TokenEndpoint ( TokenErrorCode code , string ? detail = null , IDictionary < string , object ? > ? extensions = null ) ++ AAuth.Server.AAuthProblemDetails: public static int PollingStatus ( PollingErrorCode code ) ++ AAuth.Server.AAuthProblemDetails: public static int TokenEndpointStatus ( TokenErrorCode code ) +``` + +Public owners: `AAuth.Server.AAuthProblemDetails`, `AAuth.Server`. + +### src/AAuth/Server/AAuthRevocationOptions.cs + +Concept/decision: [revocation](#revocation). Source: [AAuthRevocationOptions.cs](../../../src/AAuth/Server/AAuthRevocationOptions.cs). + +```diff +- AAuth.Server.AAuthRevocationOptions: public Func < TokenGrant , CancellationToken , Task < bool > > ? RevokeGrantAsync { get ; set ; } +- AAuth.Server.AAuthRevocationOptions: public Func < string , TokenKey , bool > ? IsTrustedPersonServer { get ; set ; } +- AAuth.Server.AAuthRevocationOptions: public IReadOnlyCollection < string > ? TrustedPersonServers { get ; set ; } +- AAuth.Server.AAuthRevocationOptions: public bool AllowTokenIssuer { get ; set ; } ++ AAuth.Server.AAuthRevocationOptions: public Func < TokenGrant , CancellationToken , Task < RevocationDownstreamError ? > > ? RevokeGrantAsync { get ; set ; } ++ AAuth.Server.AAuthRevocationOptions: public Func < string , bool > ? IsAcceptedIssuer { get ; set ; } ++ AAuth.Server.AAuthRevocationOptions: public RevocationLimits ? Limits { get ; set ; } = new ( ) ++ AAuth.Server.AAuthRevocationOptions: public TimeSpan DeferAfter { get ; set ; } = TimeSpan . FromSeconds ( 20 ) ++ AAuth.Server.AAuthRevocationOptions: public TimeSpan MaxTokenLifetime { get ; set ; } = TimeSpan . FromHours ( 24 ) ++ AAuth.Server.AAuthRevocationOptions: public bool ReportDownstream { get ; set ; } = true +``` + +Public owners: `AAuth.Server.AAuthRevocationOptions`, `AAuth.Server`. + +### src/AAuth/Server/AAuthRevocationService.cs + +Concept/decision: [revocation](#revocation). Source: [AAuthRevocationService.cs](../../../src/AAuth/Server/AAuthRevocationService.cs). + +```diff ++ AAuth.Server.IAAuthRevocationService: Task < RevocationCascadeResult > CascadeAsync ( TokenKey token , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthRevocationService: Task < RevocationCascadeResult > RevokeAgentAsync ( string agentIssuer , string sub , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthRevocationService: Task < RevocationCascadeResult > RevokeMissionAsync ( string s256 , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthRevocationService: Task < RevocationCascadeResult > RevokeTokenAsync ( string jti , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthRevocationService: Task < RevocationDownstreamResult > RevokeAtAsync ( Uri endpoint , string jti , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) ++ AAuth.Server: public interface IAAuthRevocationService +``` + +Public owners: `AAuth.Server.IAAuthRevocationService`, `AAuth.Server`. + +### src/AAuth/Server/AAuthServerIdentity.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthServerIdentity.cs](../../../src/AAuth/Server/AAuthServerIdentity.cs). + +```diff ++ AAuth.Server.IAAuthServerIdentity: AAuthEgressPolicy EgressPolicy { get ; } ++ AAuth.Server.IAAuthServerIdentity: AAuthSigningKeySet SigningKeys { get ; } ++ AAuth.Server.IAAuthServerIdentity: HttpClient CreateSignedClient ( HttpMessageHandler ? innerHandler = null , AAuthTransportContract ? transportContract = null ) ++ AAuth.Server.IAAuthServerIdentity: string Dwk { get ; } ++ AAuth.Server.IAAuthServerIdentity: string Issuer { get ; } ++ AAuth.Server.IAAuthServerIdentity: string Name { get ; } ++ AAuth.Server.IAAuthServerIdentity: string Url ( string path ) ++ AAuth.Server: public interface IAAuthServerIdentity +``` + +Public owners: `AAuth.Server.IAAuthServerIdentity`, `AAuth.Server`. + +### src/AAuth/Server/AAuthTokenProvenance.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthTokenProvenance.cs](../../../src/AAuth/Server/AAuthTokenProvenance.cs). + +```diff ++ AAuth.Server.AAuthTokenProvenance: public TokenKey ? PresentedToken { get ; init ; } ++ AAuth.Server.AAuthTokenProvenance: public TokenKey ? UpstreamToken { get ; init ; } ++ AAuth.Server: public sealed record AAuthTokenProvenance ( string TokenType , string Audience , string Subject , string PersonServer , UpstreamCallerRecord Caller ) ++ AAuth.Server: public sealed record UpstreamCallerRecord ( string AgentIssuer , string AgentId , TokenKey AgentToken , TokenKey AgentPersonBinding ) +``` + +Public owners: `AAuth.Server.AAuthTokenProvenance`, `AAuth.Server`. + +### src/AAuth/Server/AAuthTrust.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthTrust.cs](../../../src/AAuth/Server/AAuthTrust.cs). + +Public signatures unchanged (2); behavior reviewed under server-contracts. + +Public owners: `AAuth.Server.AAuthTrust`, `AAuth.Server`. + +### src/AAuth/Server/AAuthTrustPolicy.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthTrustPolicy.cs](../../../src/AAuth/Server/AAuthTrustPolicy.cs). + +```diff ++ AAuth.Server.AAuthTrustContext: public AAuthTrustContext ( string issuer , AAuthTrustedParty party , IServiceProvider services ) ++ AAuth.Server.AAuthTrustContext: public AAuthTrustedParty Party { get ; } ++ AAuth.Server.AAuthTrustContext: public HttpContext ? HttpContext { get ; init ; } ++ AAuth.Server.AAuthTrustContext: public IServiceProvider Services { get ; } ++ AAuth.Server.AAuthTrustContext: public string ? TokenDwk { get ; init ; } ++ AAuth.Server.AAuthTrustContext: public string ? TokenType { get ; init ; } ++ AAuth.Server.AAuthTrustContext: public string Issuer { get ; } ++ AAuth.Server.AAuthTrustOptions: public AAuthTrustRule AccessServers { get ; set ; } = new ( ) ++ AAuth.Server.AAuthTrustOptions: public AAuthTrustRule AgentProviders { get ; set ; } = new ( ) ++ AAuth.Server.AAuthTrustOptions: public AAuthTrustRule AuthTokenIssuers { get ; set ; } = new ( ) ++ AAuth.Server.AAuthTrustOptions: public AAuthTrustRule PersonServers { get ; set ; } = new ( ) ++ AAuth.Server.AAuthTrustOptions: public AAuthTrustRule RuleFor ( AAuthTrustedParty party ) ++ AAuth.Server.AAuthTrustOptions: public IAAuthTrustPolicy ? Policy { get ; set ; } ++ AAuth.Server.AAuthTrustOptions: public ValueTask < bool > IsTrustedAsync ( AAuthTrustContext context , CancellationToken cancellationToken = default ) ++ AAuth.Server.AAuthTrustOptions: public ValueTask < bool > IsTrustedAsync ( string issuer , AAuthTrustedParty party , IServiceProvider services , HttpContext ? httpContext = null , string ? tokenType = null , string ? tokenDwk = null , CancellationToken cancellationToken = default ) ++ AAuth.Server.AAuthTrustOptions: public bool IsConfigured ( AAuthTrustedParty party , IServiceProvider ? services = null ) ++ AAuth.Server.AAuthTrustRule: public Func < AAuthTrustContext , CancellationToken , ValueTask < bool > > ? PredicateAsync { get ; set ; } ++ AAuth.Server.AAuthTrustRule: public Func < string , bool > ? Predicate { get ; set ; } ++ AAuth.Server.AAuthTrustRule: public IReadOnlySet < string > ? Allowed { get ; set ; } ++ AAuth.Server.AAuthTrustRule: public async ValueTask < bool > EvaluateAsync ( AAuthTrustContext context , CancellationToken cancellationToken = default ) ++ AAuth.Server.AAuthTrustRule: public bool IsConfigured ++ AAuth.Server.AAuthTrustedParty: AccessServer ++ AAuth.Server.AAuthTrustedParty: AgentProvider ++ AAuth.Server.AAuthTrustedParty: AuthTokenIssuer ++ AAuth.Server.AAuthTrustedParty: PersonServer ++ AAuth.Server.IAAuthTrustPolicy: ValueTask < bool > IsTrustedAsync ( AAuthTrustContext context , CancellationToken cancellationToken = default ) ++ AAuth.Server: public enum AAuthTrustedParty ++ AAuth.Server: public interface IAAuthTrustPolicy ++ AAuth.Server: public sealed class AAuthTrustContext ++ AAuth.Server: public sealed class AAuthTrustOptions ++ AAuth.Server: public sealed class AAuthTrustRule +``` + +Public owners: `AAuth.Server.AAuthTrustContext`, `AAuth.Server.AAuthTrustOptions`, `AAuth.Server.AAuthTrustRule`, `AAuth.Server.AAuthTrustedParty`, `AAuth.Server.IAAuthTrustPolicy`, `AAuth.Server`. + +### src/AAuth/Server/AuthTokenResponse.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AuthTokenResponse.cs](../../../src/AAuth/Server/AuthTokenResponse.cs). + +```diff +- AAuth.Server.AuthTokenResponse: public static IResult Create ( Func < string > mint , DateTimeOffset ceiling , TimeProvider ? timeProvider = null ) +- AAuth.Server.AuthTokenResponse: public static async Task < IResult > CreateTrackedAsync ( Func < string > mint , DateTimeOffset ceiling , IJtiStore inventory , IReadOnlyCollection < TokenKey > sources , TimeProvider ? timeProvider = null , CancellationToken cancellationToken = default ) ++ AAuth.Server.AuthTokenResponse: public static IResult Revoked ( ) ++ AAuth.Server.AuthTokenResponse: public static Task < IResult > CreateTrackedAsync ( Func < CancellationToken , ValueTask < string > > mint , DateTimeOffset ceiling , IJtiStore inventory , IReadOnlyCollection < TokenRegistration > sources , TimeProvider ? timeProvider = null , CancellationToken cancellationToken = default ) ++ AAuth.Server.AuthTokenResponse: public static async Task < IResult > CreateAsync ( Func < CancellationToken , ValueTask < string > > mint , DateTimeOffset ceiling , TimeProvider ? timeProvider = null , CancellationToken cancellationToken = default ) ++ AAuth.Server.AuthTokenResponse: public static async Task < IResult > CreateTrackedAsync ( Func < CancellationToken , ValueTask < string > > mint , DateTimeOffset ceiling , IJtiStore inventory , IReadOnlyCollection < TokenRegistration > sources , string member , TimeProvider ? timeProvider = null , CancellationToken cancellationToken = default , IResult ? ceilingExpired = null , AAuthTokenProvenance ? provenance = null ) +``` + +Public owners: `AAuth.Server.AuthTokenResponse`, `AAuth.Server`. + +### src/AAuth/Server/Authorization/AAuthAuthorizationEndpointExtension.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthAuthorizationEndpointExtension.cs](../../../src/AAuth/Server/Authorization/AAuthAuthorizationEndpointExtension.cs). + +```diff ++ AAuth.Server.Authorization.IAAuthAuthorizationEndpointExtension: ValueTask < AAuthAuthorizationExtensionResult > ReadAsync ( HttpContext context , JsonObject body , AAuthAuthorizationRequest request , CancellationToken cancellationToken = default ) ++ AAuth.Server.Authorization: public interface IAAuthAuthorizationEndpointExtension ++ AAuth.Server.Authorization: public sealed record AAuthAuthorizationExtensionResult ( bool SatisfiesAuthorizationClaim = false ) +``` + +Public owners: `AAuth.Server.Authorization.IAAuthAuthorizationEndpointExtension`, `AAuth.Server.Authorization`. + +### src/AAuth/Server/Authorization/AAuthAuthorizationExtensionException.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthAuthorizationExtensionException.cs](../../../src/AAuth/Server/Authorization/AAuthAuthorizationExtensionException.cs). + +```diff ++ AAuth.Server.Authorization.AAuthAuthorizationExtensionException: public AAuthAuthorizationExtensionException ( string error , string ? detail = null , Exception ? innerException = null ) ++ AAuth.Server.Authorization.AAuthAuthorizationExtensionException: public string ? Detail { get ; } ++ AAuth.Server.Authorization.AAuthAuthorizationExtensionException: public string Error { get ; } ++ AAuth.Server.Authorization: public sealed class AAuthAuthorizationExtensionException : Exception +``` + +Public owners: `AAuth.Server.Authorization.AAuthAuthorizationExtensionException`, `AAuth.Server.Authorization`. + +### src/AAuth/Server/BrowserConsentSessions.cs + +Concept/decision: [consent](#consent). Source: [BrowserConsentSessions.cs](../../../src/AAuth/Server/BrowserConsentSessions.cs). + +```diff ++ AAuth.Server.BrowserInteraction: public async Task < bool > CompleteOutOfBandAsync ( DeferredState lifecycle , Func < CancellationToken , Task < bool > > apply , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Server.BrowserConsentDecision`, `AAuth.Server.BrowserConsentSessions`, `AAuth.Server.BrowserInteraction`, `AAuth.Server`. + +### src/AAuth/Server/CallChaining/CallChainingHandler.cs + +Concept/decision: [governance](#governance). Source: [CallChainingHandler.cs](../../../src/AAuth/Server/CallChaining/CallChainingHandler.cs). + +```diff +- AAuth.Server.CallChaining.CallChainingHandler: public async Task < string > ExchangeForDownstreamAsync ( string upstreamAuthToken , string resourceToken , Func < Interaction , CancellationToken , Task > ? onInteractionRequired = null , DeferredPollerOptions ? pollerOptions = null , CancellationToken cancellationToken = default , string ? account = null ) ++ AAuth.Server.CallChaining.CallChainingHandler: public async Task < string > ExchangeForDownstreamAsync ( string upstreamToken , string resourceToken , string presentedToken , Func < Interaction , CancellationToken , Task > ? onInteractionRequired = null , DeferredPollerOptions ? pollerOptions = null , CancellationToken cancellationToken = default , string ? account = null ) +``` + +Public owners: `AAuth.Server.CallChaining.CallChainingHandler`, `AAuth.Server.CallChaining`. + +### src/AAuth/Server/CallChaining/CallChainingOptions.cs + +Concept/decision: [governance](#governance). Source: [CallChainingOptions.cs](../../../src/AAuth/Server/CallChaining/CallChainingOptions.cs). + +```diff +- AAuth.Server.CallChaining.CallChainingOptions: public Func < HttpClient > ? HttpClientFactory { get ; init ; } +- AAuth.Server.CallChaining.CallChainingOptions: public required IAAuthKey AgentKey { get ; init ; } +- AAuth.Server.CallChaining.CallChainingOptions: public required ISignatureKeyProvider SignatureKeyProvider { get ; init ; } ++ AAuth.Server.CallChaining.CallChainingOptions: public Func < HttpClient > ? HttpClientFactory { get ; set ; } ++ AAuth.Server.CallChaining.CallChainingOptions: public required IAAuthSigner AgentKey { get ; set ; } ++ AAuth.Server.CallChaining.CallChainingOptions: public required ISignatureKeyProvider SignatureKeyProvider { get ; set ; } +``` + +Public owners: `AAuth.Server.CallChaining.CallChainingOptions`, `AAuth.Server.CallChaining`. + +### src/AAuth/Server/CallChaining/CallChainingRouter.cs + +Concept/decision: [governance](#governance). Source: [CallChainingRouter.cs](../../../src/AAuth/Server/CallChaining/CallChainingRouter.cs). + +```diff +- AAuth.Server.CallChaining.CallChainingRouter: public static string ResolveDownstreamServer ( string upstreamAuthToken , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) ++ AAuth.Server.CallChaining.CallChainingRouter: public static string ResolveDownstreamServer ( string upstreamToken , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +``` + +Public owners: `AAuth.Server.CallChaining.CallChainingRouter`, `AAuth.Server.CallChaining`. + +### src/AAuth/Server/CallChaining/ChainedInteractions.cs + +Concept/decision: [governance](#governance). Source: [ChainedInteractions.cs](../../../src/AAuth/Server/CallChaining/ChainedInteractions.cs). + +```diff ++ AAuth.Server.CallChaining.AAuthChainedInteractions: public static ChainedInteractionEntry Park ( string intermediaryBaseUrl , string pendingPrefix , string interactionPrefix , AAuthInteractionChainedException exception , string operationName , JsonObject state , DateTimeOffset expiresAt ) ++ AAuth.Server.CallChaining.AAuthChainedInteractions: public static IResult Accepted ( HttpContext context , ChainedInteractionEntry entry , AAuthEgressPolicy ? policy = null ) ++ AAuth.Server.CallChaining.AAuthChainedInteractions: public static IResult RedirectToDownstream ( ChainedInteractionEntry entry ) ++ AAuth.Server.CallChaining: public sealed record ChainedInteractionEntry ( string Id , string Code , string InteractionUrl , string PendingUrl , Interaction DownstreamInteraction , string OperationName , JsonObject State , DateTimeOffset ExpiresAt ) ++ AAuth.Server.CallChaining: public static class AAuthChainedInteractions +``` + +Public owners: `AAuth.Server.CallChaining.AAuthChainedInteractions`, `AAuth.Server.CallChaining`. + +### src/AAuth/Server/Challenge/AAuthChallengeMiddleware.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthChallengeMiddleware.cs](../../../src/AAuth/Server/Challenge/AAuthChallengeMiddleware.cs). + +```diff ++ AAuth.Server.Challenge.AAuthChallengeMiddleware: public static async ValueTask < string > BuildResourceTokenAsync ( ChallengeOptions options , AAuthVerifiedAssertion presented , string ? scope , string ? account = null , IReadOnlyDictionary < string , string > ? scopeDescriptions = null , IReadOnlyCollection < string > ? personServerScopes = null , Interaction ? interaction = null , string ? loginHint = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Server.Challenge.AAuthChallengeMiddleware`, `AAuth.Server.Challenge`. + +### src/AAuth/Server/Challenge/ChallengeOptions.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [ChallengeOptions.cs](../../../src/AAuth/Server/Challenge/ChallengeOptions.cs). + +```diff +- AAuth.Server.Challenge.ChallengeOptions: public AAuthAccessMode AccessMode { get ; init ; } = AAuthAccessMode . RequireAuthToken +- AAuth.Server.Challenge.ChallengeOptions: public IAAuthKey ? ResourceSigningKey { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public IReadOnlyDictionary < string , string > ? ScopeDescriptions { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public IReadOnlySet < string > ? AllowedSignatureKeySchemes { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public System . Func < Microsoft . AspNetCore . Http . HttpContext , string ? > ? RequestedAccount { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public bool MissionAware { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public string ? DefaultScopes { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public string ? PersonServerAudience { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public string ? ResourceIdentifier { get ; init ; } +- AAuth.Server.Challenge.ChallengeOptions: public string ? ResourceKeyId { get ; init ; } ++ AAuth.Server.Challenge.ChallengeOptions: public AAuthAccessMode AccessMode { get ; set ; } = AAuthAccessMode . RequireAuthToken ++ AAuth.Server.Challenge.ChallengeOptions: public AAuthSigningKeySet ? ResourceSigningKeys { get ; set ; } ++ AAuth.Server.Challenge.ChallengeOptions: public IReadOnlyDictionary < string , string > ? ScopeDescriptions { get ; set ; } ++ AAuth.Server.Challenge.ChallengeOptions: public System . Func < Microsoft . AspNetCore . Http . HttpContext , string ? > ? RequestedAccount { get ; set ; } ++ AAuth.Server.Challenge.ChallengeOptions: public string ? AccessServer { get ; set ; } ++ AAuth.Server.Challenge.ChallengeOptions: public string ? DefaultScopes { get ; set ; } ++ AAuth.Server.Challenge.ChallengeOptions: public string ? ResourceIdentifier { get ; set ; } +``` + +Public owners: `AAuth.Server.Challenge.ChallengeOptions`, `AAuth.Server.Challenge`. + +### src/AAuth/Server/DeferredState.cs + +Concept/decision: [consent](#consent). Source: [DeferredState.cs](../../../src/AAuth/Server/DeferredState.cs). + +```diff +- AAuth.Server.DeferredState: public async Task < IResult > ExecuteAsync ( HttpContext context , DateTimeOffset expiry , TimeProvider timeProvider , Func < Task < IResult > > operation ) ++ AAuth.Server.DeferredState: public async Task < IResult > ExecuteAsync ( HttpContext context , DateTimeOffset expiry , TimeProvider timeProvider , Func < Task < IResult > > operation , Func < Task < IResult ? > > ? beforeExpiry = null ) +``` + +Public owners: `AAuth.Server.DeferredState`, `AAuth.Server`. + +### src/AAuth/Server/Endpoints/AAuthEndpointExtensions.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthEndpointExtensions.cs](../../../src/AAuth/Server/Endpoints/AAuthEndpointExtensions.cs). + +```diff +- Microsoft.AspNetCore.Builder.AAuthEndpointExtensions: public static RouteHandlerBuilder RequireAAuth ( this RouteHandlerBuilder builder , string ? scope = null , string ? role = null , bool missionAware = false ) ++ Microsoft.AspNetCore.Builder.AAuthEndpointExtensions: public static RouteHandlerBuilder RequireAAuth ( this RouteHandlerBuilder builder , string ? scope = null , string ? role = null , IAAuthTrustPolicy ? trust = null ) ++ Microsoft.AspNetCore.Builder.AAuthEndpointExtensions: public static RouteHandlerBuilder RequireAAuthPersonToken ( this RouteHandlerBuilder builder ) +``` + +Public owners: `Microsoft.AspNetCore.Builder.AAuthEndpointExtensions`, `Microsoft.AspNetCore.Builder`. + +### src/AAuth/Server/Endpoints/AAuthEndpointRequirement.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthEndpointRequirement.cs](../../../src/AAuth/Server/Endpoints/AAuthEndpointRequirement.cs). + +```diff +- AAuth.Server.Endpoints.AAuthEndpointRequirement: public bool MissionAware { get ; init ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public Func < string , bool > ? IsTrustedAgentProviderIssuer { get ; set ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public Func < string , bool > ? IsTrustedAuthTokenIssuer { get ; set ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public IAAuthKey ? ResourceSigningKey { get ; set ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public IReadOnlySet < string > ? TrustedAgentProviderIssuers { get ; set ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public IReadOnlySet < string > ? TrustedAuthTokenIssuers { get ; set ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public string ? PersonServerAudience { get ; set ; } +- AAuth.Server.Endpoints.AAuthServerOptions: public string ? ResourceKeyId { get ; set ; } ++ AAuth.Server.Endpoints.AAuthEndpointRequirement: public IAAuthTrustPolicy ? Trust { get ; init ; } ++ AAuth.Server.Endpoints.AAuthServerOptions: public AAuthSigningKeySet ? ResourceSigningKeys { get ; set ; } ++ AAuth.Server.Endpoints.AAuthServerOptions: public AAuthTrustOptions Trust { get ; set ; } = new ( ) ++ AAuth.Server.Endpoints.AAuthServerOptions: public string ? AccessServer { get ; set ; } +``` + +Public owners: `AAuth.Server.Endpoints.AAuthEndpointRequirement`, `AAuth.Server.Endpoints.AAuthServerOptions`, `AAuth.Server.Endpoints`. + +### src/AAuth/Server/Governance/AAuthGovernancePipelineOptions.cs + +Concept/decision: [governance](#governance). Source: [AAuthGovernancePipelineOptions.cs](../../../src/AAuth/Server/Governance/AAuthGovernancePipelineOptions.cs). + +```diff +- AAuth.Server.Governance.AAuthGovernancePipelineOptions: public string ? Approver { get ; set ; } +- AAuth.Server.Governance.AAuthGovernancePipelineOptions: public string InteractionPath { get ; set ; } = "/mission-interaction" ++ AAuth.Server.Governance.AAuthGovernancePipelineOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Server.Governance.AAuthGovernancePipelineOptions: public string ? PersonServer { get ; set ; } ++ AAuth.Server.Governance.AAuthGovernancePipelineOptions: public string InteractionEndpointPath { get ; set ; } = "/mission-interaction" +``` + +Public owners: `AAuth.Server.Governance.AAuthGovernancePipelineOptions`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/DefaultAuditSink.cs + +Concept/decision: [governance](#governance). Source: [DefaultAuditSink.cs](../../../src/AAuth/Server/Governance/DefaultAuditSink.cs). + +Public signatures unchanged (3); behavior reviewed under governance. + +Public owners: `AAuth.Server.Governance.DefaultAuditSink`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/DefaultInteractionRelay.cs + +Concept/decision: [governance](#governance). Source: [DefaultInteractionRelay.cs](../../../src/AAuth/Server/Governance/DefaultInteractionRelay.cs). + +Public signatures unchanged (2); behavior reviewed under governance. + +Public owners: `AAuth.Server.Governance.DefaultInteractionRelay`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/DefaultPermissionDecider.cs + +Concept/decision: [governance](#governance). Source: [DefaultPermissionDecider.cs](../../../src/AAuth/Server/Governance/DefaultPermissionDecider.cs). + +Public signatures unchanged (2); behavior reviewed under governance. + +Public owners: `AAuth.Server.Governance.DefaultPermissionDecider`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/GovernanceEndpoints.cs + +Concept/decision: [governance](#governance). Source: [GovernanceEndpoints.cs](../../../src/AAuth/Server/Governance/GovernanceEndpoints.cs). + +```diff +- AAuth.Server.Governance.GovernanceEndpoints: public static AuditRecord ParseAudit ( JsonObject body , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Server.Governance.GovernanceEndpoints: public static IResult ? Authorize ( HttpContext context , MissionClaim ? reference , StoredMission ? mission ) +- AAuth.Server.Governance.GovernanceEndpoints: public static IResult MissionTerminated ( string missionStatus = "terminated" ) +- AAuth.Server.Governance.GovernanceEndpoints: public static InteractionRequest ParseInteraction ( JsonObject body , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Server.Governance.GovernanceEndpoints: public static JsonObject MissionTerminatedBody ( string missionStatus = "terminated" ) +- AAuth.Server.Governance.GovernanceEndpoints: public static MissionProposal ParseMissionProposal ( JsonObject body ) +- AAuth.Server.Governance.GovernanceEndpoints: public static PermissionRequest ParsePermission ( JsonObject body , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static AuditRecord ParseAudit ( JsonObject body ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static IResult ? Authorize ( HttpContext context , string ? missionS256 , StoredMission ? mission , string ? expectedPersonServer = null ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static IResult MissionTerminated ( string ? terminationReason = null ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static InteractionRequest ParseInteraction ( JsonObject body ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static JsonObject MissionTerminatedBody ( string ? terminationReason = null ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static MissionProposal ParseMissionProposal ( JsonObject body , AAuth . Discovery . AAuthEgressPolicy ? egressPolicy = null ) ++ AAuth.Server.Governance.GovernanceEndpoints: public static PermissionRequest ParsePermission ( JsonObject body ) +``` + +Public owners: `AAuth.Server.Governance.GovernanceEndpoints`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IDeferredConsentStore.cs + +Concept/decision: [consent](#consent). Source: [IDeferredConsentStore.cs](../../../src/AAuth/Server/Governance/IDeferredConsentStore.cs). + +```diff +- AAuth.Server.Governance.DeferredConsent: public string Approver { get ; init ; } = string . Empty ++ AAuth.Server.Governance.DeferredConsent: public DateTimeOffset ? MissionExpiresAt { get ; init ; } ++ AAuth.Server.Governance.DeferredConsent: public IReadOnlyList < string > ? MissionApprovedResources { get ; init ; } ++ AAuth.Server.Governance.DeferredConsent: public string PersonServer { get ; init ; } = string . Empty +``` + +Public owners: `AAuth.Server.Governance.DeferredConsentKind`, `AAuth.Server.Governance.DeferredConsent`, `AAuth.Server.Governance.IDeferredConsentStore`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IInteractionRelay.cs + +Concept/decision: [governance](#governance). Source: [IInteractionRelay.cs](../../../src/AAuth/Server/Governance/IInteractionRelay.cs). + +Public signatures unchanged (7); behavior reviewed under governance. + +Public owners: `AAuth.Server.Governance.IInteractionRelay`, `AAuth.Server.Governance.InteractionRelayResult`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IMissionApprover.cs + +Concept/decision: [governance](#governance). Source: [IMissionApprover.cs](../../../src/AAuth/Server/Governance/IMissionApprover.cs). + +```diff +- AAuth.Server.Governance: public sealed record MissionApprovalContext ( string Agent , string Approver , MissionProposal Proposal ) ++ AAuth.Server.Governance.MissionApprovalDecision: public IReadOnlyList < string > ? ApprovedResources { get ; init ; } ++ AAuth.Server.Governance.MissionApprovalDecision: public System . DateTimeOffset ? ExpiresAt { get ; init ; } ++ AAuth.Server.Governance: public sealed record MissionApprovalContext ( string Agent , string PersonServer , MissionProposal Proposal ) +``` + +Public owners: `AAuth.Server.Governance.IMissionApprover`, `AAuth.Server.Governance.MissionApprovalDecision`, `AAuth.Server.Governance.MissionApprovalOutcome`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IMissionLog.cs + +Concept/decision: [governance](#governance). Source: [IMissionLog.cs](../../../src/AAuth/Server/Governance/IMissionLog.cs). + +```diff ++ AAuth.Server.Governance.MissionLogEntry: public JsonObject ? Parameters { get ; init ; } ++ AAuth.Server.Governance.MissionLogEntry: public JsonObject ? Result { get ; init ; } ++ AAuth.Server.Governance.MissionLogEntryKind: Update +``` + +Public owners: `AAuth.Server.Governance.IMissionLog`, `AAuth.Server.Governance.MissionLogEntryKind`, `AAuth.Server.Governance.MissionLogEntry`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IMissionPersonTokenIssuer.cs + +Concept/decision: [governance](#governance). Source: [IMissionPersonTokenIssuer.cs](../../../src/AAuth/Server/Governance/IMissionPersonTokenIssuer.cs). + +```diff ++ AAuth.Server.Governance.IMissionPersonTokenIssuer: Task < IReadOnlyDictionary < string , string > > IssueAsync ( MissionPersonTokenRequest request , CancellationToken ct = default ) ++ AAuth.Server.Governance.MissionPersonTokenRequest: public DateTimeOffset ? MissionExpiresAt { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required DateTimeOffset AgentTokenExpiresAt { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required IAAuthKey ConfirmationKey { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required IReadOnlyList < TokenRegistration > SourceTokens { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required IReadOnlyList < string > Resources { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required string AgentId { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required string MissionS256 { get ; init ; } ++ AAuth.Server.Governance.MissionPersonTokenRequest: public required string PersonServer { get ; init ; } ++ AAuth.Server.Governance: public interface IMissionPersonTokenIssuer ++ AAuth.Server.Governance: public sealed record MissionPersonTokenRequest +``` + +Public owners: `AAuth.Server.Governance.IMissionPersonTokenIssuer`, `AAuth.Server.Governance.MissionPersonTokenRequest`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IMissionStore.cs + +Concept/decision: [governance](#governance). Source: [IMissionStore.cs](../../../src/AAuth/Server/Governance/IMissionStore.cs). + +```diff +- AAuth.Server.Governance.IMissionStore: Task < StoredMission ? > GetAsync ( string s256 , CancellationToken ct = default ) +- AAuth.Server.Governance.IMissionStore: Task SetStateAsync ( string s256 , MissionState state , CancellationToken ct = default ) +- AAuth.Server.Governance: public sealed record StoredMission ( string S256 , string Approver , string Agent , ReadOnlyMemory < byte > Blob ) ++ AAuth.Server.Governance.IMissionStore: Task < StoredMission ? > GetAsync ( string personServer , string s256 , CancellationToken ct = default ) ++ AAuth.Server.Governance.IMissionStore: Task TerminateAsync ( string personServer , string s256 , string terminationReason , CancellationToken ct = default ) ++ AAuth.Server.Governance.StoredMission: public DateTimeOffset ? ExpiresAt { get ; init ; } ++ AAuth.Server.Governance.StoredMission: public string ? TerminationReason { get ; init ; } ++ AAuth.Server.Governance: public sealed record StoredMission ( string S256 , string PersonServer , string Agent , ReadOnlyMemory < byte > Blob ) +``` + +Public owners: `AAuth.Server.Governance.IMissionStore`, `AAuth.Server.Governance.StoredMission`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/IMissionTokenConsent.cs + +Concept/decision: [consent](#consent). Source: [IMissionTokenConsent.cs](../../../src/AAuth/Server/Governance/IMissionTokenConsent.cs). + +```diff +- AAuth.Server.Governance.MissionTokenConsentContext: public required MissionClaim Mission { get ; init ; } ++ AAuth.Server.Governance.MissionTokenConsentContext: public AAuth . Person . AgentAssertedContent ? AgentAsserted { get ; init ; } ++ AAuth.Server.Governance.MissionTokenConsentContext: public IReadOnlyList < MissionLogEntry > AcceptedUpdates { get ; internal init ; } = Array . Empty < MissionLogEntry > ( ) ++ AAuth.Server.Governance.MissionTokenConsentContext: public required string MissionS256 { get ; init ; } +``` + +Public owners: `AAuth.Server.Governance.IMissionTokenConsent`, `AAuth.Server.Governance.MissionTokenConsentContext`, `AAuth.Server.Governance.MissionTokenConsentDecision`, `AAuth.Server.Governance.MissionTokenConsentKind`, `AAuth.Server.Governance.MissionTokenConsentStage`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/InMemoryMissionStore.cs + +Concept/decision: [governance](#governance). Source: [InMemoryMissionStore.cs](../../../src/AAuth/Server/Governance/InMemoryMissionStore.cs). + +```diff +- AAuth.Server.Governance.InMemoryMissionStore: public Task < StoredMission ? > GetAsync ( string s256 , CancellationToken ct = default ) +- AAuth.Server.Governance.InMemoryMissionStore: public Task SetStateAsync ( string s256 , MissionState state , CancellationToken ct = default ) ++ AAuth.Server.Governance.InMemoryMissionStore: public Task < StoredMission ? > GetAsync ( string personServer , string s256 , CancellationToken ct = default ) ++ AAuth.Server.Governance.InMemoryMissionStore: public Task TerminateAsync ( string personServer , string s256 , string terminationReason , CancellationToken ct = default ) +``` + +Public owners: `AAuth.Server.Governance.InMemoryMissionStore`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/MissionApprovalBuilder.cs + +Concept/decision: [governance](#governance). Source: [MissionApprovalBuilder.cs](../../../src/AAuth/Server/Governance/MissionApprovalBuilder.cs). + +```diff +- AAuth.Server.Governance.MissionApprovalBuilder: public static ( byte [ ] Blob , string S256 ) Build ( string approver , string agent , MissionProposal proposal , IReadOnlyList < MissionTool > approvedTools , DateTimeOffset approvedAt ) ++ AAuth.Server.Governance.MissionApprovalBuilder: public static ( byte [ ] Blob , string S256 ) Build ( string agent , MissionProposal proposal , IReadOnlyList < MissionTool > approvedTools , DateTimeOffset approvedAt , DateTimeOffset ? expiresAt = null , IReadOnlyList < string > ? approvedResources = null ) ++ AAuth.Server.Governance.MissionApprovalBuilder: public static JsonObject Response ( ReadOnlySpan < byte > blob , string s256 , IReadOnlyList < string > ? capabilities = null , IReadOnlyDictionary < string , string > ? personTokens = null ) +``` + +Public owners: `AAuth.Server.Governance.MissionApprovalBuilder`, `AAuth.Server.Governance`. + +### src/AAuth/Server/Governance/MissionPersonTokenExtensions.cs + +Concept/decision: [governance](#governance). Source: [MissionPersonTokenExtensions.cs](../../../src/AAuth/Server/Governance/MissionPersonTokenExtensions.cs). + +```diff ++ AAuth.Server.Governance.MissionPersonTokenExtensions: public static async Task < IReadOnlyDictionary < string , string > ? > IssueMissionPersonTokensAsync ( this HttpContext context , string personServer , string missionS256 , IReadOnlyList < string > resources , DateTimeOffset ? expiresAt = null ) ++ AAuth.Server.Governance: public static class MissionPersonTokenExtensions +``` + +Public owners: `AAuth.Server.Governance.MissionPersonTokenExtensions`, `AAuth.Server.Governance`. + +### src/AAuth/Server/HeldInvocations.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [HeldInvocations.cs](../../../src/AAuth/Server/HeldInvocations.cs). + +```diff ++ AAuth.Server.AAuthHeldInvocationExtensions: public static IEndpointConventionBuilder MapAAuthHeldInvocations ( this IEndpointRouteBuilder endpoints ) ++ AAuth.Server.AAuthHeldInvocationExtensions: public static IServiceCollection AddAAuthHeldInvocations ( this IServiceCollection services , Action < AAuthHeldInvocationOptions > ? configure = null ) ++ AAuth.Server.AAuthHeldInvocationExtensions: public static TBuilder WithHeldInvocation < TBuilder > ( this TBuilder builder , string operation , Func < HttpContext , JsonObject ? , CancellationToken , Task < HeldInvocationResult > > execute , TimeSpan ? pendingLifetime = null ) where TBuilder : IEndpointConventionBuilder ++ AAuth.Server.AAuthHeldInvocationOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Server.AAuthHeldInvocationOptions: public TimeSpan PendingLifetime { get ; set ; } = TimeSpan . FromMinutes ( 10 ) ++ AAuth.Server.AAuthHeldInvocationOptions: public string PathPrefix { get ; set ; } = "/aauth/held" ++ AAuth.Server.AAuthSingleUseGateExtensions: public static async Task < HeldInvocationResult > ExecuteOnceAsync ( this IAAuthSingleUseGate gate , string jti , DateTimeOffset expiresAt , Func < CancellationToken , Task < HeldInvocationResult > > execute , CancellationToken cancellationToken = default ) ++ AAuth.Server.AAuthSingleUseKeys: public static string ForAuthToken ( string issuer , string jti ) ++ AAuth.Server.HeldInvocation: public bool ExpiredObserved { get ; init ; } ++ AAuth.Server.HeldInvocation: public string ? ConsumedBy { get ; init ; } ++ AAuth.Server.HeldInvocationResult: public IResult ToResult ( ) ++ AAuth.Server.HeldInvocationResult: public static HeldInvocationResult Json ( object value , int statusCode = StatusCodes . Status200OK ) ++ AAuth.Server.IAAuthHeldInvocationStore: ValueTask < HeldInvocation ? > GetAsync ( string id , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthHeldInvocationStore: ValueTask < bool > TryConsumeAsync ( string id , string singleUseKey , DateTimeOffset retainUntil , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthHeldInvocationStore: ValueTask < bool > TryExpireAsync ( string id , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthHeldInvocationStore: ValueTask AddAsync ( HeldInvocation invocation , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthHeldInvocations: Task < IResult > HoldAsync ( HttpContext context , string resourceToken , IReadOnlyCollection < string > requiredScopes , JsonObject ? state = null ) ++ AAuth.Server.IAAuthHeldInvocations: Task < IResult > PollAsync ( HttpContext context , string id ) ++ AAuth.Server.IAAuthHeldInvocations: string PathPrefix { get ; } ++ AAuth.Server.IAAuthSingleUseGate: ValueTask < HeldInvocationResult ? > GetResultAsync ( string key , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthSingleUseGate: ValueTask < SingleUseClaim > TryClaimAsync ( string key , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthSingleUseGate: ValueTask CompleteAsync ( string key , HeldInvocationResult result , CancellationToken cancellationToken = default ) ++ AAuth.Server.IAAuthSingleUseGate: ValueTask ReleaseAsync ( string key , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemoryHeldInvocationStore: public ValueTask < HeldInvocation ? > GetAsync ( string id , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemoryHeldInvocationStore: public ValueTask < bool > TryConsumeAsync ( string id , string singleUseKey , DateTimeOffset retainUntil , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemoryHeldInvocationStore: public ValueTask < bool > TryExpireAsync ( string id , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemoryHeldInvocationStore: public ValueTask AddAsync ( HeldInvocation invocation , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemorySingleUseGate: public ValueTask < HeldInvocationResult ? > GetResultAsync ( string key , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemorySingleUseGate: public ValueTask < SingleUseClaim > TryClaimAsync ( string key , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemorySingleUseGate: public ValueTask CompleteAsync ( string key , HeldInvocationResult result , CancellationToken cancellationToken = default ) ++ AAuth.Server.InMemorySingleUseGate: public ValueTask ReleaseAsync ( string key , CancellationToken cancellationToken = default ) ++ AAuth.Server: public interface IAAuthHeldInvocationStore ++ AAuth.Server: public interface IAAuthHeldInvocations ++ AAuth.Server: public interface IAAuthSingleUseGate ++ AAuth.Server: public readonly record struct SingleUseClaim ( bool Claimed , HeldInvocationResult ? Result ) ++ AAuth.Server: public sealed class AAuthHeldInvocationOptions ++ AAuth.Server: public sealed class InMemoryHeldInvocationStore ( TimeProvider ? timeProvider = null ) : IAAuthHeldInvocationStore ++ AAuth.Server: public sealed class InMemorySingleUseGate ( TimeProvider ? timeProvider = null ) : IAAuthSingleUseGate ++ AAuth.Server: public sealed record HeldInvocation ( string Id , string Operation , string ResourceToken , string AgentJkt , IReadOnlyList < string > RequiredScopes , DateTimeOffset PendingExpiresAt , JsonObject ? State = null ) ++ AAuth.Server: public sealed record HeldInvocationEndpointMetadata ( string Operation , Func < HttpContext , JsonObject ? , CancellationToken , Task < HeldInvocationResult > > Execute , TimeSpan ? PendingLifetime = null ) ++ AAuth.Server: public sealed record HeldInvocationResult ( int StatusCode , string ? ContentType , byte [ ] Body ) ++ AAuth.Server: public static class AAuthHeldInvocationExtensions ++ AAuth.Server: public static class AAuthSingleUseGateExtensions ++ AAuth.Server: public static class AAuthSingleUseKeys +``` + +Public owners: `AAuth.Server.AAuthHeldInvocationExtensions`, `AAuth.Server.AAuthHeldInvocationOptions`, `AAuth.Server.AAuthSingleUseGateExtensions`, `AAuth.Server.AAuthSingleUseKeys`, `AAuth.Server.HeldInvocationResult`, `AAuth.Server.HeldInvocation`, `AAuth.Server.IAAuthHeldInvocationStore`, `AAuth.Server.IAAuthHeldInvocations`, `AAuth.Server.IAAuthSingleUseGate`, `AAuth.Server.InMemoryHeldInvocationStore`, `AAuth.Server.InMemorySingleUseGate`, `AAuth.Server`. + +### src/AAuth/Server/IJtiStore.cs + +Concept/decision: [revocation](#revocation). Source: [IJtiStore.cs](../../../src/AAuth/Server/IJtiStore.cs). + +```diff +- AAuth.Server.IJtiStore: Task < bool > RevokeAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.IJtiStore: Task < TokenGrant ? > GetGrantAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.IJtiStore: Task < bool > CheckProvenanceQuotaAsync ( UpstreamCallerRecord caller , string resource , CancellationToken ct = default ) ++ AAuth.Server.IJtiStore: Task < bool > ContainsTokenAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.IJtiStore: Task < string ? > GetSubjectAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.IJtiStore: Task RecordSubjectAsync ( TokenKey token , string subject , CancellationToken ct = default ) ++ AAuth.Server.IJtiStore: Task RevokeAsync ( TokenKey token , DateTimeOffset expiresAt , CancellationToken ct = default ) +``` + +Public owners: `AAuth.Server.IJtiStore`, `AAuth.Server`. + +### src/AAuth/Server/InMemoryJtiStore.cs + +Concept/decision: [revocation](#revocation). Source: [InMemoryJtiStore.cs](../../../src/AAuth/Server/InMemoryJtiStore.cs). + +```diff +- AAuth.Server.InMemoryJtiStore: public InMemoryJtiStore ( TimeProvider ? timeProvider = null , int capacity = 100_000 , TimeSpan ? retention = null ) +- AAuth.Server.InMemoryJtiStore: public Task < bool > RevokeAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.InMemoryJtiStore: public InMemoryJtiStore ( TimeProvider ? timeProvider = null , int capacity = 100_000 , TimeSpan ? retention = null , int provenanceResourceQuota = 1_000 ) ++ AAuth.Server.InMemoryJtiStore: public Task < TokenGrant ? > GetGrantAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.InMemoryJtiStore: public Task < bool > CheckProvenanceQuotaAsync ( UpstreamCallerRecord caller , string resource , CancellationToken ct = default ) ++ AAuth.Server.InMemoryJtiStore: public Task < bool > ContainsTokenAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.InMemoryJtiStore: public Task < string ? > GetSubjectAsync ( TokenKey token , CancellationToken ct = default ) ++ AAuth.Server.InMemoryJtiStore: public Task RecordSubjectAsync ( TokenKey token , string subject , CancellationToken ct = default ) ++ AAuth.Server.InMemoryJtiStore: public Task RevokeAsync ( TokenKey token , DateTimeOffset expiresAt , CancellationToken ct = default ) +``` + +Public owners: `AAuth.Server.InMemoryJtiStore`, `AAuth.Server`. + +### src/AAuth/Server/Metadata/AAuthAccessServerMetadataOptions.cs + +Concept/decision: [resource-managed](#resource-managed). Source: [AAuthAccessServerMetadataOptions.cs](../../../src/AAuth/Server/Metadata/AAuthAccessServerMetadataOptions.cs). + +```diff +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuth . Discovery . AAuthEgressPolicy . Production +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public required IReadOnlyDictionary < string , IAAuthKey > SigningKeys { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public required string Issuer { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public required string TokenEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? Description { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? DocumentationUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? LogoDarkUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? LogoUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? Name { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? PolicyUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? RevocationEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? TosUri { get ; init ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public required AAuthSigningKeySet SigningKeys { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public required string AuthTokenEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public required string Issuer { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? Description { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? DocumentationUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? LogoDarkUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? LogoUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? Name { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? PolicyUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? RevocationEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthAccessServerMetadataOptions: public string ? TosUri { get ; set ; } +``` + +Public owners: `AAuth.Server.Metadata.AAuthAccessServerMetadataOptions`, `AAuth.Server.Metadata`. + +### src/AAuth/Server/Metadata/AAuthAgentMetadataOptions.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthAgentMetadataOptions.cs](../../../src/AAuth/Server/Metadata/AAuthAgentMetadataOptions.cs). + +```diff +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuth . Discovery . AAuthEgressPolicy . Production +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public required IReadOnlyDictionary < string , IAAuthKey > SigningKeys { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public required string Issuer { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? CallbackEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? Description { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? DocumentationUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? LoginEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? LogoDarkUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? LogoUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? Name { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? PolicyUri { get ; init ; } +- AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? TosUri { get ; init ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public AAuthSigningKeySet SigningKeys { get ; set ; } = new ( ) ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public bool LocalhostCallbackAllowed { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? CallbackEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? Description { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? DocumentationUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? EventEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? LogoDarkUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? LogoUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? Name { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? PolicyUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string ? TosUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthAgentMetadataOptions: public string Issuer { get ; set ; } = "" +``` + +Public owners: `AAuth.Server.Metadata.AAuthAgentMetadataOptions`, `AAuth.Server.Metadata`. + +### src/AAuth/Server/Metadata/AAuthPersonServerMetadataOptions.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [AAuthPersonServerMetadataOptions.cs](../../../src/AAuth/Server/Metadata/AAuthPersonServerMetadataOptions.cs). + +```diff +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuth . Discovery . AAuthEgressPolicy . Production +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public IReadOnlyList < string > ? ScopesSupported { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required IReadOnlyDictionary < string , IAAuthKey > SigningKeys { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required string Issuer { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required string TokenEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? AuditEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? Description { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? DocumentationUri { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? InteractionEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? LogoDarkUri { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? LogoUri { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? MissionEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? Name { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? PermissionEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? PolicyUri { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? RevocationEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? TosUri { get ; init ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public IReadOnlyList < string > ? ScopesSupported { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required AAuthSigningKeySet SigningKeys { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required string AuthTokenEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required string Issuer { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public required string PersonTokenEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? AuditEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? Description { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? DocumentationUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? InteractionEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? LogoDarkUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? LogoUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? MissionEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? Name { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? PermissionEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? PolicyUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? RevocationEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthPersonServerMetadataOptions: public string ? TosUri { get ; set ; } +``` + +Public owners: `AAuth.Server.Metadata.AAuthPersonServerMetadataOptions`, `AAuth.Server.Metadata`. + +### src/AAuth/Server/Metadata/WellKnownEndpoints.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [WellKnownEndpoints.cs](../../../src/AAuth/Server/Metadata/WellKnownEndpoints.cs). + +```diff +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuth . Discovery . AAuthEgressPolicy . Production +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public IReadOnlyDictionary < string , IAAuthKey > ? SigningKeys { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public IReadOnlyDictionary < string , JsonNode ? > ? AdditionalMetadata { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public IReadOnlyDictionary < string , string > ? ScopeDescriptions { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public int ? SignatureWindow { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public required string Issuer { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? AccessMode { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? AuthorizationEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? Description { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? DocumentationUri { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? LogoDarkUri { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? LogoUri { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? Name { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? PolicyUri { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? RevocationEndpoint { get ; init ; } +- AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? TosUri { get ; init ; } +- AAuth.Server.Metadata.WellKnownEndpoints: public static IEndpointRouteBuilder MapAAuthAccessServerWellKnown ( this IEndpointRouteBuilder endpoints , AAuthAccessServerMetadataOptions options ) +- AAuth.Server.Metadata.WellKnownEndpoints: public static IEndpointRouteBuilder MapAAuthAgentWellKnown ( this IEndpointRouteBuilder endpoints , AAuthAgentMetadataOptions options ) +- AAuth.Server.Metadata.WellKnownEndpoints: public static IEndpointRouteBuilder MapAAuthPersonServerWellKnown ( this IEndpointRouteBuilder endpoints , AAuthPersonServerMetadataOptions options ) +- AAuth.Server.Metadata.WellKnownEndpoints: public static IEndpointRouteBuilder MapAAuthResourceWellKnown ( this IEndpointRouteBuilder endpoints , AAuthResourceMetadataOptions options ) ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; set ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public AAuthSigningKeySet ? SigningKeys { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public IReadOnlyDictionary < string , JsonNode ? > ? AdditionalMetadata { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public IReadOnlyDictionary < string , string > ? ScopeDescriptions { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public IReadOnlyList < string > ? AdditionalSignatureComponents { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public int ? SignatureWindow { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public required string Issuer { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? AccessMode { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? AccessServer { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? AuthorizationEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? Description { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? DocumentationUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? LogoDarkUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? LogoUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? Name { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? PolicyUri { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? RevocationEndpoint { get ; set ; } ++ AAuth.Server.Metadata.AAuthResourceMetadataOptions: public string ? TosUri { get ; set ; } ++ AAuth.Server.Metadata.WellKnownEndpoints: public static IEndpointRouteBuilder MapAAuthAgentWellKnown ( this IEndpointRouteBuilder endpoints , Action < AAuthAgentMetadataOptions > configure ) +``` + +Public owners: `AAuth.Server.Metadata.AAuthResourceMetadataOptions`, `AAuth.Server.Metadata.WellKnownEndpoints`, `AAuth.Server.Metadata`. + +### src/AAuth/Server/ResourceManaged/AAuthInteractionEndpointExtensions.cs + +Concept/decision: [resource-managed](#resource-managed). Source: [AAuthInteractionEndpointExtensions.cs](../../../src/AAuth/Server/ResourceManaged/AAuthInteractionEndpointExtensions.cs). + +Public signatures unchanged (2); behavior reviewed under resource-managed. + +Public owners: `Microsoft.AspNetCore.Builder.AAuthInteractionEndpointExtensions`, `Microsoft.AspNetCore.Builder`. + +### src/AAuth/Server/RevocationClient.cs + +Concept/decision: [revocation](#revocation). Source: [RevocationClient.cs](../../../src/AAuth/Server/RevocationClient.cs). + +```diff +- AAuth.Server.RevocationClient: public async Task < HttpStatusCode > RevokeAsync ( Uri endpoint , TokenKey token , CancellationToken cancellationToken = default ) ++ AAuth.Server.RevocationClient: public TimeSpan MaxPollDuration { get ; init ; } = TimeSpan . FromMinutes ( 2 ) ++ AAuth.Server.RevocationClient: public async Task < RevocationResult > RevokeAsync ( Uri endpoint , string jti , DateTimeOffset expiresAt , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Server.RevocationClient`, `AAuth.Server`. + +### src/AAuth/Server/RevocationEndpoint.cs + +Concept/decision: [revocation](#revocation). Source: [RevocationEndpoint.cs](../../../src/AAuth/Server/RevocationEndpoint.cs). + +```diff +- AAuth.Server.RevocationEndpoint: public static IEndpointRouteBuilder MapAAuthRevocationEndpoint ( this IEndpointRouteBuilder endpoints , IJtiStore jtiStore , Action < AAuthRevocationOptions > ? configure , string path = "/revoke" ) +- AAuth.Server.RevocationEndpoint: public static IEndpointRouteBuilder MapAAuthRevocationEndpoint ( this IEndpointRouteBuilder endpoints , IJtiStore jtiStore , string path = "/revoke" ) +- AAuth.Server.RevocationEndpoint: public static IJtiStore MapAAuthIssuerRevocation ( this WebApplication app , string issuer , string dwk , AAuth . Crypto . IAAuthKey signingKey , string signingKid , string path , AAuth . Discovery . AAuthEgressPolicy egressPolicy , TimeProvider clock , Action < AAuthRevocationOptions > ? configure ) ++ AAuth.Server.RevocationEndpoint: public static IEndpointRouteBuilder MapAAuthRevocationEndpoint ( this IEndpointRouteBuilder endpoints , string path = "/revoke" , Action < AAuthRevocationOptions > ? configure = null ) ++ AAuth.Server.RevocationEndpoint: public static WebApplication MapAAuthResourceRevocation ( this WebApplication app ) +``` + +Public owners: `AAuth.Server.RevocationEndpoint`, `AAuth.Server`. + +### src/AAuth/Server/RevocationLimits.cs + +Concept/decision: [revocation](#revocation). Source: [RevocationLimits.cs](../../../src/AAuth/Server/RevocationLimits.cs). + +```diff ++ AAuth.Server.RevocationLimits: public TimeSpan Window { get ; set ; } = TimeSpan . FromMinutes ( 1 ) ++ AAuth.Server.RevocationLimits: public int MaxEntriesPerIssuer { get ; set ; } = 10_000 ++ AAuth.Server.RevocationLimits: public int MaxRequestsPerIssuer { get ; set ; } = 600 ++ AAuth.Server: public sealed class RevocationLimits +``` + +Public owners: `AAuth.Server.RevocationLimits`, `AAuth.Server`. + +### src/AAuth/Server/RevocationResult.cs + +Concept/decision: [revocation](#revocation). Source: [RevocationResult.cs](../../../src/AAuth/Server/RevocationResult.cs). + +```diff ++ AAuth.Server.RevocationCascadeResult: public IReadOnlyList < RevocationDownstreamResult > Downstream { get ; init ; } = [ ] ++ AAuth.Server.RevocationDownstreamResult: public IReadOnlyList < RevocationDownstreamResult > Downstream { get ; init ; } = [ ] ++ AAuth.Server.RevocationResult: public IReadOnlyList < RevocationDownstreamResult > Downstream { get ; init ; } = [ ] ++ AAuth.Server.RevocationResult: public RevocationDownstreamError ? Failure { get ; init ; } ++ AAuth.Server.RevocationResult: public required HttpStatusCode StatusCode { get ; init ; } ++ AAuth.Server.RevocationResult: public string ? Error { get ; init ; } ++ AAuth.Server: public sealed record RevocationCascadeResult ++ AAuth.Server: public sealed record RevocationDownstreamResult ( string Recipient , RevocationDownstreamError ? Error ) ++ AAuth.Server: public sealed record RevocationResult +``` + +Public owners: `AAuth.Server.RevocationCascadeResult`, `AAuth.Server.RevocationDownstreamResult`, `AAuth.Server.RevocationResult`, `AAuth.Server`. + +### src/AAuth/Server/TokenGrant.cs + +Concept/decision: [revocation](#revocation). Source: [TokenGrant.cs](../../../src/AAuth/Server/TokenGrant.cs). + +```diff ++ AAuth.Server.TokenGrant: public AAuthTokenProvenance ? Provenance { get ; init ; } +``` + +Public owners: `AAuth.Server.TokenGrant`, `AAuth.Server`. + +### src/AAuth/Server/TokenRegistration.cs + +Concept/decision: [revocation](#revocation). Source: [TokenRegistration.cs](../../../src/AAuth/Server/TokenRegistration.cs). + +```diff +- AAuth.Server.TokenRegistration: public static TokenRegistration FromVerified ( TokenVerifier . VerifiedToken token ) ++ AAuth.Server.TokenRegistration: public TokenCredential ? Credential { get ; init ; } ++ AAuth.Server.TokenRegistration: public static TokenRegistration FromVerified ( TokenVerifier . VerifiedToken token , TokenCredential ? credential = null ) ++ AAuth.Server.TokenRegistration: public string ? TokenType { get ; init ; } +``` + +Public owners: `AAuth.Server.TokenRegistration`, `AAuth.Server`. + +### src/AAuth/Server/TokenRequestBody.cs + +Concept/decision: [server-contracts](#server-contracts). Source: [TokenRequestBody.cs](../../../src/AAuth/Server/TokenRequestBody.cs). + +Public signatures unchanged (2); behavior reviewed under server-contracts. + +Public owners: `AAuth.Server.TokenRequestBody`, `AAuth.Server`. + +### src/AAuth/Server/Verification/AAuthAccessMode.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthAccessMode.cs](../../../src/AAuth/Server/Verification/AAuthAccessMode.cs). + +```diff ++ AAuth.Server.Verification.AAuthAccessMode: PersonTokenRequired +``` + +Public owners: `AAuth.Server.Verification.AAuthAccessMode`, `AAuth.Server.Verification`. + +### src/AAuth/Server/Verification/AAuthAuthenticationHandler.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthAuthenticationHandler.cs](../../../src/AAuth/Server/Verification/AAuthAuthenticationHandler.cs). + +```diff +- AAuth.Server.Verification.AAuthAuthenticationHandler: public const string ActorAgentClaimType = "aauth:act_agent" ; ++ AAuth.Server.Verification.AAuthAuthenticationHandler: public const string MissionClaimType = "aauth:mission_s256" ; ++ AAuth.Server.Verification.AAuthAuthenticationHandler: public const string PersonServerClaimType = "aauth:ps" ; ++ AAuth.Server.Verification.AAuthAuthenticationHandler: public const string TenantClaimType = "aauth:tenant" ; +``` + +Public owners: `AAuth.Server.Verification.AAuthAuthenticationHandler`, `AAuth.Server.Verification`. + +### src/AAuth/Server/Verification/AAuthHttpContextExtensions.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthHttpContextExtensions.cs](../../../src/AAuth/Server/Verification/AAuthHttpContextExtensions.cs). + +```diff ++ AAuth.Server.Verification.AAuthHttpContextExtensions: public static AAuthVerifiedAssertion ? GetAAuthVerifiedAssertion ( this HttpContext context ) +``` + +Public owners: `AAuth.Server.Verification.AAuthHttpContextExtensions`, `AAuth.Server.Verification`. + +### src/AAuth/Server/Verification/AAuthVerificationMiddleware.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthVerificationMiddleware.cs](../../../src/AAuth/Server/Verification/AAuthVerificationMiddleware.cs). + +Public signatures unchanged (14); behavior reviewed under signatures. + +Public owners: `AAuth.Server.Verification.AAuthVerificationMiddleware`, `AAuth.Server.Verification.VerificationResult`, `AAuth.Server.Verification`. + +### src/AAuth/Server/Verification/AAuthVerificationOptions.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthVerificationOptions.cs](../../../src/AAuth/Server/Verification/AAuthVerificationOptions.cs). + +```diff +- AAuth.Server.Verification.AAuthVerificationOptions: public Func < DateTimeOffset > ? Clock { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public Func < Microsoft . AspNetCore . Http . HttpContext , string ? > ? ExpectedAccount { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public Func < string , bool > ? IsTrustedAgentProviderIssuer { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public Func < string , bool > ? IsTrustedAuthTokenIssuer { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public IReadOnlyCollection < string > RequiredComponents { get ; init ; } = [ ] +- AAuth.Server.Verification.AAuthVerificationOptions: public IReadOnlyList < string > AcceptedSchemes { get ; init ; } = [ "jwt" ] +- AAuth.Server.Verification.AAuthVerificationOptions: public IReadOnlySet < string > ? TrustedAgentProviderIssuers { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public IReadOnlySet < string > ? TrustedAuthTokenIssuers { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public TimeSpan ClockSkew { get ; init ; } = TimeSpan . FromSeconds ( 30 ) +- AAuth.Server.Verification.AAuthVerificationOptions: public TimeSpan MaxFutureSkew { get ; init ; } = TimeSpan . FromSeconds ( 5 ) +- AAuth.Server.Verification.AAuthVerificationOptions: public bool GenericSignatureKeys { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public int MaxActDepth { get ; init ; } = 10 +- AAuth.Server.Verification.AAuthVerificationOptions: public static AAuthVerificationOptions Generic ( Func < DateTimeOffset > ? clock = null ) +- AAuth.Server.Verification.AAuthVerificationOptions: public string ? ResourceIdentifier { get ; init ; } +- AAuth.Server.Verification.AAuthVerificationOptions: public string SignatureLabel { get ; init ; } = "sig" ++ AAuth.Server.Verification.AAuthVerificationOptions: public AAuthTrustOptions Trust { get ; set ; } = new ( ) ++ AAuth.Server.Verification.AAuthVerificationOptions: public Func < Microsoft . AspNetCore . Http . HttpContext , string ? > ? ExpectedAccount { get ; set ; } ++ AAuth.Server.Verification.AAuthVerificationOptions: public IReadOnlyCollection < string > RequiredComponents { get ; set ; } = [ ] ++ AAuth.Server.Verification.AAuthVerificationOptions: public IReadOnlyList < string > AcceptedSchemes { get ; set ; } = [ "jwt" ] ++ AAuth.Server.Verification.AAuthVerificationOptions: public TimeProvider TimeProvider { get ; set ; } = TimeProvider . System ++ AAuth.Server.Verification.AAuthVerificationOptions: public TimeSpan ClockSkew { get ; set ; } = TimeSpan . FromSeconds ( 30 ) ++ AAuth.Server.Verification.AAuthVerificationOptions: public bool GenericSignatureKeys { get ; set ; } ++ AAuth.Server.Verification.AAuthVerificationOptions: public bool RequireBodyCoverage { get ; set ; } ++ AAuth.Server.Verification.AAuthVerificationOptions: public static AAuthVerificationOptions Generic ( TimeProvider ? timeProvider = null ) ++ AAuth.Server.Verification.AAuthVerificationOptions: public string ? ExpectedAuthTokenDwk { get ; set ; } ++ AAuth.Server.Verification.AAuthVerificationOptions: public string ? ResourceIdentifier { get ; set ; } ++ AAuth.Server.Verification.AAuthVerificationOptions: public string SignatureLabel { get ; set ; } = "sig" +``` + +Public owners: `AAuth.Server.Verification.AAuthVerificationOptions`, `AAuth.Server.Verification`. + +### src/AAuth/Server/Verification/AAuthVerificationResult.cs + +Concept/decision: [signatures](#signatures). Source: [AAuthVerificationResult.cs](../../../src/AAuth/Server/Verification/AAuthVerificationResult.cs). + +```diff +- AAuth.Server.Verification.AAuthVerificationResult: public string ? ActorAgent { get ; init ; } ++ AAuth.Server.Verification.AAuthVerificationResult: public IReadOnlySet < string > CoveredComponents { get ; init ; } = new HashSet < string > ( ) ++ AAuth.Server.Verification.AAuthVerificationResult: public string ? AgentPersonServer { get ; init ; } ++ AAuth.Server.Verification.AAuthVerificationResult: public string ? MissionS256 { get ; init ; } ++ AAuth.Server.Verification.AAuthVerificationResult: public string ? PersonServer { get ; init ; } ++ AAuth.Server.Verification.AAuthVerificationResult: public string ? Tenant { get ; init ; } +``` + +Public owners: `AAuth.Server.Verification.AAuthVerificationResult`, `AAuth.Server.Verification`. + +### src/AAuth/Server/Verification/IssuerTrust.cs + +Concept/decision: [signatures](#signatures). Source: [IssuerTrust.cs](../../../src/AAuth/Server/Verification/IssuerTrust.cs). + +```diff +- AAuth.Server.Verification.IssuerTrust: public static bool IsTrusted ( IReadOnlyCollection < string > ? set , Func < string , bool > ? policy , string id ) +- AAuth.Server.Verification: public static class IssuerTrust +``` + +Public owners: `AAuth.Server.Verification.IssuerTrust`, `AAuth.Server.Verification`. + +### src/AAuth/Tokens/ActChainBuilder.cs + +Concept/decision: [tokens](#tokens). Source: [ActChainBuilder.cs](../../../src/AAuth/Tokens/ActChainBuilder.cs). + +```diff +- AAuth.Tokens.ActChainBuilder: public static JsonObject BuildNestedAct ( string upstreamAgentId , JsonObject ? upstreamChain = null , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens.ActChainBuilder: public static bool ValidateChain ( JsonObject act , int maxDepth = 10 , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens: public static class ActChainBuilder +``` + +Public owners: `AAuth.Tokens.ActChainBuilder`, `AAuth.Tokens`. + +### src/AAuth/Tokens/ActChainReader.cs + +Concept/decision: [tokens](#tokens). Source: [ActChainReader.cs](../../../src/AAuth/Tokens/ActChainReader.cs). + +```diff +- AAuth.Tokens.ActChainReader: public static IReadOnlyList < string > GetDelegationChain ( JsonObject payload , int maxDepth = 10 , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens.ActChainReader: public static int GetChainDepth ( JsonObject payload , int maxDepth = 10 , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens.ActChainReader: public static string ? GetImmediateActor ( JsonObject payload , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens.ActChainReader: public static string ? GetOriginalActor ( JsonObject payload , int maxDepth = 10 , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens: public static class ActChainReader +``` + +Public owners: `AAuth.Tokens.ActChainReader`, `AAuth.Tokens`. + +### src/AAuth/Tokens/AgentAuthTokenValidator.cs + +Concept/decision: [tokens](#tokens). Source: [AgentAuthTokenValidator.cs](../../../src/AAuth/Tokens/AgentAuthTokenValidator.cs). + +```diff +- AAuth.Tokens.AgentAuthTokenValidator: public static void Validate ( string authToken , string resourceToken , IAAuthKey signingKey , string agentToken , string ? subagentToken = null , string ? upstreamToken = null , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) ++ AAuth.Tokens.AgentAuthTokenValidator: public static void Validate ( string authToken , string resourceToken , IAAuthKey signingKey , string agentToken , string presentedToken , string ? subagentToken = null , string ? upstreamToken = null , string ? expectedDwk = null ) +``` + +Public owners: `AAuth.Tokens.AgentAuthTokenValidator`, `AAuth.Tokens`. + +### src/AAuth/Tokens/AgentIssuanceContext.cs + +Concept/decision: [tokens](#tokens). Source: [AgentIssuanceContext.cs](../../../src/AAuth/Tokens/AgentIssuanceContext.cs). + +```diff +- AAuth.Tokens.AgentIssuanceContext: public JsonObject ? Act { get ; init ; } +- AAuth.Tokens.AgentIssuanceContext: public static async Task < AgentIssuanceContext > VerifyAsync ( string agentToken , string ? subagentToken , string ? upstreamToken , TokenVerifier verifier , MetadataClient metadata , JwksClient jwks , Func < string , bool > isTrustedUpstreamIssuer , CancellationToken cancellationToken = default ) +- AAuth.Tokens.AgentIssuanceContext: public void ValidateResourceContext ( JsonObject resource , string ? governingPersonServer = null ) ++ AAuth.Tokens.AgentIssuanceContext: public bool SubAgent { get ; init ; } ++ AAuth.Tokens.AgentIssuanceContext: public required string AgentIssuer { get ; init ; } ++ AAuth.Tokens.AgentIssuanceContext: public static async Task < AgentIssuanceContext > VerifyAsync ( string agentToken , string ? subagentToken , string ? upstreamToken , string personServer , TokenVerifier verifier , MetadataClient metadata , JwksClient jwks , Func < string , CancellationToken , ValueTask < bool > > isTrustedAuthTokenIssuer , CancellationToken cancellationToken = default , TokenCredential ? agentTokenCredential = null , IJtiStore ? upstreamInventory = null ) ++ AAuth.Tokens.AgentIssuanceContext: public void ValidateResourceContext ( JsonObject resource ) +``` + +Public owners: `AAuth.Tokens.AgentIssuanceContext`, `AAuth.Tokens`. + +### src/AAuth/Tokens/AgentTokenBuilder.cs + +Concept/decision: [tokens](#tokens). Source: [AgentTokenBuilder.cs](../../../src/AAuth/Tokens/AgentTokenBuilder.cs). + +```diff +- AAuth.Tokens.AgentTokenBuilder: public required IAAuthKey Key { get ; init ; } +- AAuth.Tokens.AgentTokenBuilder: public string Build ( ) ++ AAuth.Tokens.AgentTokenBuilder: public async ValueTask < string > BuildAsync ( CancellationToken cancellationToken = default ) ++ AAuth.Tokens.AgentTokenBuilder: public required IAAuthSigner Key { get ; init ; } ++ AAuth.Tokens.AgentTokenBuilder: public static readonly TimeSpan MaximumLifetime = TimeSpan . FromHours ( 24 ) ; +``` + +Public owners: `AAuth.Tokens.AgentTokenBuilder`, `AAuth.Tokens`. + +### src/AAuth/Tokens/AuthTokenBuilder.cs + +Concept/decision: [tokens](#tokens). Source: [AuthTokenBuilder.cs](../../../src/AAuth/Tokens/AuthTokenBuilder.cs). + +```diff +- AAuth.Tokens.AuthTokenBuilder: public JsonObject ? Act { get ; init ; } +- AAuth.Tokens.AuthTokenBuilder: public MissionClaim ? Mission { get ; init ; } +- AAuth.Tokens.AuthTokenBuilder: public required IAAuthKey Key { get ; init ; } +- AAuth.Tokens.AuthTokenBuilder: public required string Agent { get ; init ; } +- AAuth.Tokens.AuthTokenBuilder: public string ? Subject { get ; init ; } +- AAuth.Tokens.AuthTokenBuilder: public string Build ( ) ++ AAuth.Tokens.AuthTokenBuilder: public async ValueTask < string > BuildAsync ( CancellationToken cancellationToken = default ) ++ AAuth.Tokens.AuthTokenBuilder: public required IAAuthSigner Key { get ; init ; } ++ AAuth.Tokens.AuthTokenBuilder: public required string PersonServer { get ; init ; } ++ AAuth.Tokens.AuthTokenBuilder: public required string Subject { get ; init ; } ++ AAuth.Tokens.AuthTokenBuilder: public string ? MissionS256 { get ; init ; } +``` + +Public owners: `AAuth.Tokens.AuthTokenBuilder`, `AAuth.Tokens`. + +### src/AAuth/Tokens/AuthTokenResponseValidator.cs + +Concept/decision: [tokens](#tokens). Source: [AuthTokenResponseValidator.cs](../../../src/AAuth/Tokens/AuthTokenResponseValidator.cs). + +```diff +- AAuth.Tokens.AuthTokenResponseValidator: public async Task < AuthTokenDeliveryResult > ValidateAsync ( string authToken , string expectedIssuer , string expectedAudience , string expectedAgentId , IAAuthKey agentKey , JsonObject ? expectedActContext = null , string ? requestedScope = null , CancellationToken ct = default , string ? expectedAccount = null ) +- AAuth.Tokens.AuthTokenResponseValidator: public static bool ActChainsMatch ( JsonObject ? actual , JsonObject ? expected , AAuthEgressPolicy ? policy = null ) ++ AAuth.Tokens.AuthTokenResponseValidator: public async Task < AuthTokenDeliveryResult > ValidateAsync ( string authToken , string expectedIssuer , string expectedAudience , string expectedSubject , string expectedPersonServer , IAAuthKey agentKey , DateTimeOffset presentedTokenExpiresAt , string ? requestedScope = null , CancellationToken ct = default , string ? expectedAccount = null ) +``` + +Public owners: `AAuth.Tokens.AuthTokenDeliveryResult`, `AAuth.Tokens.AuthTokenResponseValidator`, `AAuth.Tokens`. + +### src/AAuth/Tokens/MissionClaim.cs + +Concept/decision: [tokens](#tokens). Source: [MissionClaim.cs](../../../src/AAuth/Tokens/MissionClaim.cs). + +```diff +- AAuth.Tokens.MissionClaim: public JsonObject ToJsonObject ( ) +- AAuth.Tokens.MissionClaim: public static MissionClaim ? FromPayload ( JsonObject ? payload , AAuth . Discovery . AAuthEgressPolicy ? policy = null ) +- AAuth.Tokens: public sealed record MissionClaim ( string Approver , string S256 ) +``` + +Public owners: `AAuth.Tokens.MissionClaim`, `AAuth.Tokens`. + +### src/AAuth/Tokens/MissionReference.cs + +Concept/decision: [tokens](#tokens). Source: [MissionReference.cs](../../../src/AAuth/Tokens/MissionReference.cs). + +```diff ++ AAuth.Tokens.MissionReference: public const string ClaimName = "mission_s256" ; ++ AAuth.Tokens.MissionReference: public static bool IsValid ( string ? value ) ++ AAuth.Tokens.MissionReference: public static string ? Read ( JsonObject ? document ) ++ AAuth.Tokens: public static class MissionReference +``` + +Public owners: `AAuth.Tokens.MissionReference`, `AAuth.Tokens`. + +### src/AAuth/Tokens/PersonTokenBuilder.cs + +Concept/decision: [tokens](#tokens). Source: [PersonTokenBuilder.cs](../../../src/AAuth/Tokens/PersonTokenBuilder.cs). + +```diff ++ AAuth.Tokens.PersonTokenBuilder: public AAuth . Discovery . AAuthEgressPolicy EgressPolicy { get ; init ; } = AAuth . Discovery . AAuthEgressPolicy . Production ++ AAuth.Tokens.PersonTokenBuilder: public DateTimeOffset ? AuthorizationExpiresAt { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public DateTimeOffset ? IssuedAt { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System ++ AAuth.Tokens.PersonTokenBuilder: public TimeSpan Lifetime { get ; init ; } = TimeSpan . FromHours ( 1 ) ++ AAuth.Tokens.PersonTokenBuilder: public async ValueTask < string > BuildAsync ( CancellationToken cancellationToken = default ) ++ AAuth.Tokens.PersonTokenBuilder: public const string PersonDwk = "aauth-person.json" ; ++ AAuth.Tokens.PersonTokenBuilder: public const string TokenType = "aa-person+jwt" ; ++ AAuth.Tokens.PersonTokenBuilder: public required DateTimeOffset AgentTokenExpiresAt { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public required IAAuthKey ConfirmationKey { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public required IAAuthSigner Key { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public required string Audience { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public required string Issuer { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public required string KeyId { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public required string Subject { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public string ? MissionS256 { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public string ? Tenant { get ; init ; } ++ AAuth.Tokens.PersonTokenBuilder: public string ? TokenId { get ; init ; } ++ AAuth.Tokens: public sealed class PersonTokenBuilder +``` + +Public owners: `AAuth.Tokens.PersonTokenBuilder`, `AAuth.Tokens`. + +### src/AAuth/Tokens/ResourceTokenBuilder.cs + +Concept/decision: [tokens](#tokens). Source: [ResourceTokenBuilder.cs](../../../src/AAuth/Tokens/ResourceTokenBuilder.cs). + +```diff +- AAuth.Tokens.ResourceTokenBuilder: public MissionClaim ? Mission { get ; init ; } +- AAuth.Tokens.ResourceTokenBuilder: public required IAAuthKey Key { get ; init ; } +- AAuth.Tokens.ResourceTokenBuilder: public required string Agent { get ; init ; } +- AAuth.Tokens.ResourceTokenBuilder: public string Build ( ) ++ AAuth.Tokens.ResourceTokenBuilder: public async ValueTask < string > BuildAsync ( CancellationToken cancellationToken = default ) ++ AAuth.Tokens.ResourceTokenBuilder: public required IAAuthSigner Key { get ; init ; } ++ AAuth.Tokens.ResourceTokenBuilder: public required string PersonServer { get ; init ; } ++ AAuth.Tokens.ResourceTokenBuilder: public required string PresentedJti { get ; init ; } ++ AAuth.Tokens.ResourceTokenBuilder: public required string Subject { get ; init ; } ++ AAuth.Tokens.ResourceTokenBuilder: public string ? LoginHint { get ; init ; } ++ AAuth.Tokens.ResourceTokenBuilder: public string ? MissionS256 { get ; init ; } ++ AAuth.Tokens.ResourceTokenBuilder: public string ? Tenant { get ; init ; } +``` + +Public owners: `AAuth.Tokens.ResourceTokenBuilder`, `AAuth.Tokens`. + +### src/AAuth/Tokens/TokenVerifier.cs + +Concept/decision: [tokens](#tokens). Source: [TokenVerifier.cs](../../../src/AAuth/Tokens/TokenVerifier.cs). + +```diff +- AAuth.Tokens.TokenVerifier.VerifiedToken: public MissionClaim ? Mission +- AAuth.Tokens.TokenVerifier: public Func < DateTimeOffset > Clock { get ; init ; } = ( ) => DateTimeOffset . UtcNow +- AAuth.Tokens.TokenVerifier: public TimeSpan ClockSkew { get ; init ; } = TimeSpan . FromSeconds ( 30 ) +- AAuth.Tokens.TokenVerifier: public VerifiedToken VerifyAuthToken ( string jwt , IAAuthKey issuerKey , string expectedAudience , IAAuthKey httpSignatureKey , string expectedAgentId , string ? expectedDwk = null , string ? expectedMaxScope = null , AccountExpectation ? accountExpectation = null ) +- AAuth.Tokens.TokenVerifier: public async Task < VerifiedToken > VerifyAuthTokenWithJwksAsync ( string jwt , MetadataClient metadata , JwksClient jwks , string expectedAudience , IAAuthKey httpSignatureKey , string expectedAgentId , string ? expectedMaxScope = null , CancellationToken cancellationToken = default , AccountExpectation ? accountExpectation = null ) +- AAuth.Tokens.TokenVerifier: public async Task < VerifiedToken > VerifyResourceTokenAsync ( string jwt , string expectedAudience , string expectedAgentId , string expectedAgentJkt , MetadataClient metadata , JwksClient jwks , string ? expectedApprover = null , string ? subagentAgentJkt = null , CancellationToken cancellationToken = default ) +- AAuth.Tokens.TokenVerifier: public int MaxActDepth { get ; init ; } = 10 ++ AAuth.Tokens.TokenCredential: Presented ++ AAuth.Tokens.TokenVerifier.VerifiedToken: public string ? MissionS256 ++ AAuth.Tokens.TokenVerifier.VerifiedToken: public string ? Subject ++ AAuth.Tokens.TokenVerifier.VerifiedToken: public string ? Tenant ++ AAuth.Tokens.TokenVerifier.VerifiedToken: public string Jti ++ AAuth.Tokens.TokenVerifier: public Func < string , string , IAAuthKey ? > ? LocalIssuerKeys { get ; init ; } ++ AAuth.Tokens.TokenVerifier: public Task < VerifiedToken > VerifyAuthTokenWithJwksAsync ( string jwt , MetadataClient metadata , JwksClient jwks , string expectedAudience , IAAuthKey httpSignatureKey , string ? expectedDwk = null , string ? expectedMaxScope = null , CancellationToken cancellationToken = default , AccountExpectation ? accountExpectation = null ) ++ AAuth.Tokens.TokenVerifier: public Task < VerifiedToken > VerifyPersonTokenWithJwksAsync ( string jwt , MetadataClient metadata , JwksClient jwks , string expectedAudience , IAAuthKey httpSignatureKey , CancellationToken cancellationToken = default ) ++ AAuth.Tokens.TokenVerifier: public TimeProvider TimeProvider { get ; init ; } = TimeProvider . System ++ AAuth.Tokens.TokenVerifier: public TimeSpan ClockSkew { get ; init ; } = TimeSpan . FromSeconds ( 60 ) ++ AAuth.Tokens.TokenVerifier: public TokenVerifier WithLocalIssuer ( string issuer , AAuthSigningKeySet keys ) ++ AAuth.Tokens.TokenVerifier: public VerifiedToken VerifyAuthToken ( string jwt , IAAuthKey issuerKey , string expectedAudience , IAAuthKey httpSignatureKey , string ? expectedDwk = null , string ? expectedMaxScope = null , AccountExpectation ? accountExpectation = null ) ++ AAuth.Tokens.TokenVerifier: public VerifiedToken VerifyPersonToken ( string jwt , IAAuthKey issuerKey , string expectedAudience , IAAuthKey httpSignatureKey ) ++ AAuth.Tokens.TokenVerifier: public async Task < VerifiedToken > VerifyPresentedTokenAsync ( string presentedToken , VerifiedToken resourceToken , MetadataClient metadata , JwksClient jwks , CancellationToken cancellationToken = default ) ++ AAuth.Tokens.TokenVerifier: public async Task < VerifiedToken > VerifyResourceTokenAsync ( string jwt , string expectedAudience , string expectedAgentJkt , MetadataClient metadata , JwksClient jwks , string ? subagentAgentJkt = null , string ? expectedPersonServer = null , CancellationToken cancellationToken = default ) +``` + +Public owners: `AAuth.Tokens.TokenCredential`, `AAuth.Tokens.TokenVerificationException`, `AAuth.Tokens.TokenVerifier.VerifiedToken`, `AAuth.Tokens.TokenVerifier`, `AAuth.Tokens`. + +### src/AAuth/Tokens/UpstreamTokenValidator.cs + +Concept/decision: [tokens](#tokens). Source: [UpstreamTokenValidator.cs](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs). + +```diff +- AAuth.Tokens.UpstreamTokenValidationResult: public JsonObject ? UpstreamAct { get ; init ; } +- AAuth.Tokens.UpstreamTokenValidationResult: public MissionClaim ? Mission { get ; init ; } +- AAuth.Tokens.UpstreamTokenValidationResult: public string ? Agent { get ; init ; } +- AAuth.Tokens.UpstreamTokenValidationResult: public string ? IssuerDwk { get ; init ; } +- AAuth.Tokens.UpstreamTokenValidationResult: public string ? MissionApprover { get ; init ; } +- AAuth.Tokens.UpstreamTokenValidator: public Task < UpstreamTokenValidationResult > ValidateAsync ( string upstreamToken , string expectedAudience , IReadOnlySet < string > trustedIssuers , CancellationToken ct = default ) +- AAuth.Tokens.UpstreamTokenValidator: public async Task < UpstreamTokenValidationResult > ValidateAsync ( string upstreamToken , string expectedAudience , Func < string , bool > isTrustedIssuer , CancellationToken ct = default ) ++ AAuth.Tokens.UpstreamTokenValidationResult: public AAuthTokenProvenance ? Provenance { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidationResult: public UpstreamCallerRecord ? Caller { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidationResult: public string ? Audience { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidationResult: public string ? MissionS256 { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidationResult: public string ? PersonServer { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidationResult: public string ? Tenant { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidationResult: public string ? TokenType { get ; init ; } ++ AAuth.Tokens.UpstreamTokenValidator: public async Task < UpstreamTokenValidationResult > ValidateAsync ( string upstreamToken , string intermediary , string expectedPersonServer , Func < string , CancellationToken , ValueTask < bool > > isTrustedAuthTokenIssuer , CancellationToken ct = default ) ++ AAuth.Tokens.UpstreamTokenValidator: public async Task < UpstreamTokenValidationResult > ValidateAtPersonServerAsync ( string upstreamToken , string intermediary , string personServer , IJtiStore inventory , Func < string , CancellationToken , ValueTask < bool > > isTrustedAuthTokenIssuer , CancellationToken ct = default ) +``` + +Public owners: `AAuth.Tokens.UpstreamTokenValidationResult`, `AAuth.Tokens.UpstreamTokenValidator`, `AAuth.Tokens`. diff --git a/.agent/plans/2026-09-11-aauth-v11-spec-migration/capability-scenarios.md b/.agent/plans/2026-09-11-aauth-v11-spec-migration/capability-scenarios.md new file mode 100644 index 00000000..5bc94680 --- /dev/null +++ b/.agent/plans/2026-09-11-aauth-v11-spec-migration/capability-scenarios.md @@ -0,0 +1,79 @@ +--- +description: Proposed draft-11 migration scenarios and validation in both primary apps. +--- + +# Capability scenarios - draft-11 WIP + +Planning baseline: 2026-09-11. No scenarios below are claimed implemented or +executed. Findings reference [research.md](research.md), which supplies pinned +spec lines and current implementation evidence. Both +[SampleApp](../../../samples/SampleApp/) and +[GuidedTour](../../../samples/GuidedTour/) are deliverables, not interchangeable +substitutes. Reuse [CapabilitySupport](../../../samples/CapabilitySupport/), +[EventSupport](../../../samples/EventSupport/), and existing resource projects. + +## Required scenarios + +| ID | Scenario and resource | Proposed visible protocol sequence in both apps | Required negative/runtime evidence | +|---|---|---|---| +| S01 | Person identity, focused Profile endpoint | Enroll or self-issue; agent-only call yields person challenge; obtain person token with consent; serve person preferences; step up on a scope-protected endpoint. Preserve separate generic Profile routes. F02/F03/F06 | Person token rejected as auth token; wrong audience/key; issuer-colliding `sub`; absence of agent/act at person-resource surface | +| S02 | Calendar three-party authorization | Person acquisition; person-signed resource request; resource token plus exact presented token to PS; auth token; protected read and scope denial. F01-F05 | Scope-only auth invalid; stale/different presented `jti`; mission/tenant stripping; correct account and subject | +| S03 | Wallet four-party authorization | Person token; resource challenge; PS consent and AS policy; forwarded presented token; delivered auth token verified by PS; protected access. Run stub and Keycloak modes. F04/F06/F16 | PS and AS independently reject substitution; claims cannot replace person identity; terminal AS denial relayed versus 502 unavailable | +| S04 | Inbox resource-managed session | Existing resource login/interaction; AAuth-Access opaque session; Authorization: AAuth reuse and rolling replacement. New label is session-token, not a new PS flow. F05/F23 | Token68/multiple values, signature coverage, wrong key/account/origin, revocation/reset behavior remain protected | +| S05 | Mission approval, update and completion | Propose tools/resources; decode envelope and verify blob digest; use returned person token; local permission/audit; accept an update without changing mission hash; propose completion at mission URL; follow-up then person acceptance. F07-F10 | Envelope whitespace independent of hash; blob tampering; update affects cached consent; mission expires during consent; non-owner/missing equivalence; no reactivation | +| S06 | Concierge downstream chaining | Receive upstream authorization; route via its PS, not intermediary PS or AS issuer; obtain downstream person token; downstream resource/exchange; return result and PS-side attribution. F11 | Distinct caller/intermediary keys; correct upstream audience; two people and resources; downstream sub not copied; Q3/Q4 must be resolved | +| S07 | Parent/worker authorization | Parent obtains worker-key person token; passes it to worker; worker obtains resource token; parent exchanges resource/presented/worker tokens; worker presents auth token. Reuse [FederatedWorkerScenario](../../../samples/FederatedWorkerScenario.cs). F11 | Parent cannot present worker token with parent key; worker cannot call PS directly; unrelated parent fails; no resource actor chain | +| S08 | Wallet revocation cascade | PS revokes person token at AS; AS revokes issued auth tokens at resource; subsequent access rejected with appropriate error; fresh-person authorization succeeds only if policy permits. F14-F16 | Same jti/different issuer isolation; unseen-token revocation acknowledged; pending grant withdrawal; resource source expiry does not truncate valid auth grant | +| S09 | Bookings per-call approval | Discover operation/account; proposal with concrete parameters; approval; single execution; lost-response retry returns retained result. Show held-invocation 202 path and test 401 retry separately. F17-F19 | Concurrent fresh signatures under same grant execute once; changed parameters/account/key fail; same proposal hash with two grants remains distinct | +| S10 | Catalog standard OpenAPI aggregation | Replace OpenAPI Gateway service maps with one valid definition containing unique operation IDs, or separately identified resources after Q6. Discover, authorize, execute and reject an ungranted operation. F18 | Collision detection, no obsolete standard vocabulary/qualifier emitted, seven vocabulary tests preserved | +| S11 | Documents resource-first permission | Retain resource-owned interaction before PS consent, but start the authorization leg with person identity and exact presented-token exchange. F03/F04/F10 | Resource refusal prevents downstream consent/grant; PS relay is not authoritative resource completion; new token and step indices correct | +| S12 | Public and protected Events | Preserve AP subscribe/event flows and public subscriptions. Protected Bookings ticket uses the Q5-agreed trusted binding after migrated auth; deliver resource self-JWT event and persist delivery state. F20 | Wrong key/agent/account/operation ticket redemption; replay; restart; no false use of person sub as agent ID; Q5 unresolved means not closed | +| S13 | Refresh and recoverable errors | Fake-clock SDK scenarios plus representative browser token renewal; refresh agent then person then auth; surface clock skew; distinguish revoked credential, AS denial and unavailable AS. F12/F16 | No refresh loop for future iat; no replay of unsafe original request; cancellation doesn't publish renewed state; original expiry retained in fixtures | + +## Optional decisions + +| ID | Capability | Proposed default | +|---|---|---| +| S14 | Operation access annotations | Include a small OpenAPI/AsyncAPI/MCP metadata demonstration when its actual flow exists. Runtime requirements remain authoritative; no operation session-token, and no budget marker claiming unimplemented accounting. F19 | +| S15 | Resource-link discovery and algorithm advertisement | Include validated metadata support and a focused discovery scenario if selected in Q6; malformed links fail before fetch. Preserve verifier key-discovery isolation. F05 | +| S16 | R3 approve release instead of execute | Default no execution feature; represent or reject result-bearing proposals explicitly. If selected, add a side-effect-free Documents query scenario to both apps with truthful already-executed display and retained result; not the existing permission flow renamed. F21 | +| S17 | Full Budgets | Separate initiative by default, with its own metering, usage, settlement, race and persistence gates. A metadata hint or example JSON is insufficient. F22 | +| S18 | Hosted worker enrollment/delayed artifacts | Preserve existing self-issued worker and live-signature paths. Hosted AP endpoint design and delayed verifier remain separately selected capabilities. F23 | + +## Walkthrough synchronization + +[TourSession](../../../samples/GuidedTour/TourSession.cs#L300) and +[e2e tour helper](../../../tests/e2e/helpers/tour.ts#L48) have independent step +counts. Plan arrays, dispatchers, polling/approval indices, actor lanes, nested +protocol sequences, captured headers/bodies, snippets, payload selectors, and +completion counts must all change in the same owning phase. + +SampleApp legacy pages use buttons and response panels rather than the entire +GuidedTour timeline. Shared Wallet/Catalog/Documents/Events components have +their own sequence models. Preserve each app's interaction conventions while +using common protocol services and exact code templates where they already exist. +Update numeric selections and removed `act.agent` assertions in +[Wallet browser helpers](../../../tests/e2e/helpers/wallet-protocol.ts) and +all step-dependent tests, not just displayed labels. + +Every selected new user-facing capability must be exercised in both apps. SDK +tests, a console demonstration, or a static prose section cannot substitute for +one missing host. Avoid one new server per test variation; add a resource only +when reuse would obscure an existing single-purpose example. + +## Browser and environment evidence + +- Reuse the two projects in [e2e configuration](../../../tests/e2e/playwright.config.ts) + and existing consent helpers; require fresh services and zero retries for + migration evidence. Run both stub and live-Keycloak modes separately. +- Capture actual wire values for identity/key/account/mission expectations; + inspect the payload of the selected step, not any matching text on the page. +- Retain desktop/mobile layout, reset/re-enrollment, concurrent sessions, + deferred approval/cancel/deny, authenticated consent and CSRF checks. +- .NET 10, Node 20+, locked npm dependencies, Chromium, available local ports, + and isolated state are prerequisites. Live Keycloak requires its configured + realm/container and human or automated test-user consent, as applicable. +- External whoami and external sub-agent/mission interoperability remain separate + gates requiring reachable HTTPS metadata/JWKS and compatible deployed drafts. + A local pass, unavailable external service, or old draft-10 evidence is not + draft-11 external success. No external state was changed in this research. \ No newline at end of file diff --git a/.agent/plans/2026-09-11-aauth-v11-spec-migration/conformance-ledger.md b/.agent/plans/2026-09-11-aauth-v11-spec-migration/conformance-ledger.md new file mode 100644 index 00000000..5350f270 --- /dev/null +++ b/.agent/plans/2026-09-11-aauth-v11-spec-migration/conformance-ledger.md @@ -0,0 +1,205 @@ +--- +description: Draft-11 WIP requirement risks, negative controls, and planned verification ledger. +--- + +# Conformance ledger - draft-11 WIP + +Source audit only, 2026-09-11. SDK baseline +`94576a3ebcba8cd1d167923e50c8796132057600`; spec pins and citations are in +[research.md](research.md). No row is an executed draft-11 conformance pass. +F labels refer to research findings; phase numbers refer to the +[implementation plan](implementation-plan.md). Test files are existing homes +to extend, not assertions that proposed cases already exist or pass. + +## Requirement-to-check map + +| ID | Source assessment | Discriminating future regression | Existing test home | Phase | +|---|---|---|---|---| +| F01 | D: auth builder requires agent, permits absent subject, emits act | Require ps/sub without agent/act; reject missing subject and reserved-claim injection | [AuthTokenStructureTests](../../../tests/AAuth.Conformance/AuthTokens/AuthTokenStructureTests.cs), [AuthTokenBuilderTests](../../../tests/AAuth.Tests/Tokens/AuthTokenBuilderTests.cs) | 4 | +| F02 | R: person-token lifecycle absent | Verify person typ/DWK/issuer/audience/key/expiry; reject scope/account; isolate resource/mission/key caches | [TokenVerifierTests](../../../tests/AAuth.Tests/Tokens/TokenVerifierTests.cs), [PersonServerMapperTests](../../../tests/AAuth.Conformance/Person/PersonServerMapperTests.cs), [holder tests](../../../tests/AAuth.Tests/Agent/AAuthTokenHolderTests.cs) | 2, 3, 5 | +| F03 | R: agent-only challenge still mints resource token | Agent yields person requirement; person mints; runtime auth step-up mints; auth-only authorization endpoint fails | [ChallengeMiddlewareTests](../../../tests/AAuth.Conformance/HttpSignatures/ChallengeMiddlewareTests.cs) | 4 | +| F04 | R: no presented parameter; D clarification replacement API gap | Same claims/different jti; stripped mission/tenant; wrong key/audience/PS; refreshed holder; reject at PS/AS before mutation; atomically replace both tokens under Q13 | [ChallengeHandlerTests](../../../tests/AAuth.Tests/Agent/ChallengeHandlerTests.cs), [AccessServerClientTests](../../../tests/AAuth.Tests/AccessServerClientTests.cs), [DeferredFederationTests](../../../tests/AAuth.Conformance/Person/DeferredFederationTests.cs) | 4, 5 | +| F05 | R: old endpoint/session names | Minimal PS metadata; missing/invalid endpoint; unknown-mode fallback; exact algorithm list; bad link rejected before fetch | [AllRolesWellKnownMetadataTests](../../../tests/AAuth.Conformance/Discovery/AllRolesWellKnownMetadataTests.cs), [ResourceAccessModeMetadataTests](../../../tests/AAuth.Conformance/Discovery/ResourceAccessModeMetadataTests.cs), [MetadataClientTests](../../../tests/AAuth.Tests/Discovery/MetadataClientTests.cs) | 1, 2, 5 | +| F06 | R: qualified identity exists, validators use agent/act | Same sub across issuers distinct; tenant change preserves person; agent policy cannot silently accept person-token requests | [AuthorizationIntegrationTests](../../../tests/AAuth.Conformance/HttpSignatures/AuthorizationIntegrationTests.cs), [AuthTokenDeliveryTests](../../../tests/AAuth.Conformance/AuthTokens/AuthTokenDeliveryTests.cs) | 4, 9 | +| F07 | R: exact bytes exist, approval is raw body/header | Envelope formatting independent of digest; blob mutation rejected; capabilities not hashed; no mission header | [MissionS256Tests](../../../tests/AAuth.Conformance/Missions/MissionS256Tests.cs), [MissionHeaderSeamTests](../../../tests/AAuth.Conformance/Missions/MissionHeaderSeamTests.cs) | 3, 4 | +| F08 | R: no update log; completion via interaction | Update changes later consent without changing mission hash; required action; completion remains active until acceptance | [GovernanceServerTests](../../../tests/AAuth.Conformance/Missions/GovernanceServerTests.cs), [GovernanceDeferredConsentMapperTests](../../../tests/AAuth.Conformance/Missions/GovernanceDeferredConsentMapperTests.cs) | 3, 6 | +| F09 | R: no mission expiry; store allows reactivation | Expire during resumed PS operations; terminal/save races; opaque reason; foreign/missing equal responses and controlled timing | [MissionTerminatedTests](../../../tests/AAuth.Conformance/Missions/MissionTerminatedTests.cs), [GovernanceEndpointMapperTests](../../../tests/AAuth.Conformance/Missions/GovernanceEndpointMapperTests.cs) | 3, 6, 9 | +| F10 | R: consent evidence provenance incomplete | Misleading justification cannot replace resource display; fixed subject survives claims push; updates reach policy/UI | [MockPersonServerTests](../../../tests/AAuth.Tests/Integration/MockPersonServerTests.cs), [DeferredFederationTests](../../../tests/AAuth.Conformance/Person/DeferredFederationTests.cs) | 4, 6 | +| F11 | D upstream conflict; R parent/routing | Distinct caller/intermediary/worker keys; upstream PS differs from issuer/intermediary PS; downstream sub not copied; direct worker rejected | [CallChainingRouterTests](../../../tests/AAuth.Conformance/CallChaining/CallChainingRouterTests.cs), [UpstreamTokenValidationTests](../../../tests/AAuth.Conformance/AuthTokens/UpstreamTokenValidationTests.cs), [CallChainingTests](../../../tests/AAuth.Conformance/AuthTokens/CallChainingTests.cs) | 6 | +| F12 | R: expiry skew and isolated refresh | Exact-now/subsecond exp in header/body; independent future iat; preserved source ceilings through consent; top-down concurrent refresh | [TokenVerifierTests](../../../tests/AAuth.Tests/Tokens/TokenVerifierTests.cs), [IssuanceBoundsTests](../../../tests/AAuth.Conformance/AuthTokens/IssuanceBoundsTests.cs), [TokenRefreshHandlerTests](../../../tests/AAuth.Tests/Agent/TokenRefreshHandlerTests.cs) | 2, 4, 5 | +| F13 | R: PS identity signing exists; default body coverage absent | Missing coverage, altered bytes, and signed malformed JSON get distinct outcomes before policy; future created gets clock skew | [SignatureV10AdversarialTests](../../../tests/AAuth.Tests/HttpSig/SignatureV10AdversarialTests.cs), [SignatureV10WireTests](../../../tests/AAuth.Tests/HttpSig/SignatureV10WireTests.cs), [SignatureErrorTests](../../../tests/AAuth.Conformance/Errors/SignatureErrorTests.cs) | 1, 4, 9 | +| F14 | D store; R wire: unseen revocation absent | Unseen/repeated jti/exp returns 200; injected issuer cannot select namespace; bad exp rejected; old override removed | [JtiStoreAndRevocationTests](../../../tests/AAuth.Conformance/Discovery/JtiStoreAndRevocationTests.cs) | 7 | +| F15 | D: every ancestry source also bounds expiry | Five-minute resource source can back a longer auth grant; withdrawal still blocks issuance; person/step-up ancestry retained | [RevocationLifecycleTests](../../../tests/AAuth.Conformance/Discovery/RevocationLifecycleTests.cs), [IssuanceBoundsTests](../../../tests/AAuth.Conformance/AuthTokens/IssuanceBoundsTests.cs) | 7 | +| F16 | R: revoked/federation error meanings differ | Header revocation 401, body 400, pending withdrawal 403; immediate/polled AS denial preserved; malformed success maps 502 | [SignatureErrorTests](../../../tests/AAuth.Conformance/Errors/SignatureErrorTests.cs), [PollingErrorTests](../../../tests/AAuth.Conformance/Errors/PollingErrorTests.cs), [AccessServerClientTests](../../../tests/AAuth.Tests/AccessServerClientTests.cs) | 1, 4, 5, 7 | +| F17 | D R3; R agent: no consumed grant/results | 202 never resends original body; concurrent completion executes once; lost-response retry returns retained result; 401 retry also single-use | [DeferredExchangeTests](../../../tests/AAuth.Tests/Agent/DeferredExchangeTests.cs), [DeferredStateTests](../../../tests/AAuth.Tests/Server/DeferredStateTests.cs), [ResourceR3Tests](../../../tests/AAuth.R3.Tests/ResourceR3Tests.cs) | 5, 8 | +| F18 | D: gateway removed, hash already correct | No Conditional/Version/gateway API or emission; seven vocabularies; collision-free Catalog; unchanged byte/structural equality | [R3VocabularyTests](../../../tests/AAuth.R3.Tests/R3VocabularyTests.cs), [R3ModelTests](../../../tests/AAuth.R3.Tests/R3ModelTests.cs), [R3HashTests](../../../tests/AAuth.R3.Tests/R3HashTests.cs) | 1, 8 | +| F19 | R: R3 identity/reader context changes | R3 AS checks provenance; foreign PS cannot read unentitled document; persistent audit; annotations never grant access | [AccessEndpointR3Tests](../../../tests/AAuth.R3.Tests/AccessEndpointR3Tests.cs), [R3SqliteAuditTests](../../../tests/AAuth.R3.Tests/R3SqliteAuditTests.cs), [ResourceR3Tests](../../../tests/AAuth.R3.Tests/ResourceR3Tests.cs) | 4, 8 | +| F20 | D: protected ticket reads removed agent | Agreed trusted binding survives new token; wrong key/agent/account/operation rejected; persistence/replay and event no-cnf preserved | [EventHttpTests](../../../tests/AAuth.Events.Tests/EventHttpTests.cs), [EventPersistenceTests](../../../tests/AAuth.Events.Tests/EventPersistenceTests.cs), [EventsTokenTests](../../../tests/AAuth.Events.Tests/EventsTokenTests.cs) | 4, 8 | +| F21 | R: result not exposed to policy | Result reaches capable policy or explicit unsupported response; never silently treat release request as execute approval | [R3ModelTests](../../../tests/AAuth.R3.Tests/R3ModelTests.cs), [AccessEndpointR3Tests](../../../tests/AAuth.R3.Tests/AccessEndpointR3Tests.cs) | 8 or separate | +| F22 | R: Budgets unsupported | No false metering claims; selected future capability needs atomic amount/denomination/reservation/settlement tests | [ScopeNarrowingTests](../../../tests/AAuth.Conformance/AuthTokens/ScopeNarrowingTests.cs) is a starting point, not budget coverage | 0, separate | +| F23 | R: informational bootstrap and generic carriers | Existing enrollment/carrier matrix retained; optional delayed verifier never changes live acceptance | [Bootstrap tests](../../../tests/AAuth.Tests/HttpSig/AAuthClientBuilderBootstrapTests.cs), [AAuthVerifierTests](../../../tests/AAuth.Tests/HttpSig/AAuthVerifierTests.cs) | 6, 9 or separate | +| F24 | D tool paths; R UI/static inventory | Generator cannot overwrite v10 map; exact snippets compile; both apps run matching steps and payloads; no stale live wire text | [SnippetCompilationTests](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs), [e2e](../../../tests/e2e/) | 1, 9-11 | + +## Negative requirement audit + +ENFORCED means an actual rejecting/bounding path was inspected. VACUOUS means +the built-in capability is absent, not compliant. UNENFORCEABLE means the local +verifier lacks the evidence needed; another boundary or deployment must own it. +All verdicts are scoped source observations, not runtime test results. + +| Requirement | Governing clause | Current verdict | Disposition | +|---|---|---|---| +| Person token no scope/account | [P898](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L898), `#person-token-structure` | VACUOUS absent issuer | Reserved claims and negative verification, F02 | +| Person cannot replace required auth | [P920](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L920), `#person-token-verification` | Unsupported type rejected; new acceptance path unimplemented | Explicit typed policy separation, F02/F06 | +| Agent-only request cannot mint challenge | [P637](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L637), `#requirement-auth-token` | UNENFORCED v11 prerequisite | Verified person/auth context, F03 | +| No substituted or stripped identity/mission | [P767](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L767), `#resource-token-verification` | UNENFORCED new paired-token check | Compare exact named credential at PS/AS, F04 | +| No resource-visible agent/act | [P1781](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L1781), `#auth-token-structure` | UNENFORCED v11 producer contract | Remove core issuance, preserve AP/Events identities, F01/F20 | +| Auth cannot outlive source agent | [P1775](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L1775), `#auth-token-structure` | ENFORCED builder ceiling; UNENFORCEABLE independently without source at resource | Preserve issuer bound; add presented/mission, F12 | +| Terminal mission cannot reactivate | [P1516](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L1516), `#mission-management` | UNENFORCED store mutation/replacement | Atomic terminal state, F09 | +| No mission disclosure before owner authorization | [P1540](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L1540), `#mission-endpoint-errors` | Owner rejection exists; equivalence UNVERIFIED | Equal responses and measured timing, F09 | +| Worker cannot authorize itself | [P1917](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L1917), `#sub-agents` | ENFORCED PS auth parent check | Apply to person endpoint, F11 | +| Caller cannot select another revocation issuer | [P2690](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2690), `#token-revocation` | UNENFORCED with existing cross-issuer override | Signer-derived namespace, F14 | +| Revoked resource token cannot mint auth | [P2753](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2753), `#token-revocation` | UNENFORCED new source tracking | Withdrawal edge distinct from expiry ceiling, F15 | +| One per-call grant cannot execute twice | [R676](../../../aauth-spec/v11/draft-hardt-aauth-r3.md#L676), `#per-call-flow` | UNENFORCED R3 execution boundary | Atomic consumption/result retention, F17 | +| Event self-JWT no cnf | [E367](../../../aauth-spec/v11/draft-hardt-aauth-events.md#L367), `#event-token` | ENFORCED EventsTokens rejection | Preserve companion profile, F20 | +| Link cannot direct arbitrary fetch/key trust | [P2154](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2154), `#resource-metadata-link` | VACUOUS absent consumer | Validate before fetch; exclude key resolver, F05 | +| 403 no signature error/negotiation headers | [P2254](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2254), `#verification` | ENFORCED inspected SDK signature paths, not arbitrary host middleware | Regress new polling/AS/issuer-admission errors, F16 | +| No pre-execution of billed/metered/audited work | [R696](../../../aauth-spec/v11/draft-hardt-aauth-r3.md#L696), `#release-gating` | VACUOUS absent capability; side effects UNENFORCEABLE from JSON alone | Explicit host policy, default disabled, F21 | +| Consumption plus reservations cannot exceed budget | [B871](../../../aauth-spec/v11/draft-hardt-aauth-budgets.md#L871), `#overshoot` | VACUOUS absent metering | Separate selected capability, F22 | + +## Finding owners and executed checks + +Recorded 2026-09-29, after implementation. The tables above keep the +pre-implementation source audit. This table names the component that owns each +finding and the tests that now discriminate it. Every test name was confirmed +in `tests/` by grep. The implementation log records each test's rerun +evidence. + +| F | Owner | Phase | Executed discriminatory checks | +|---|---|---|---| +| F01 | `AuthTokenBuilder` | 4 | `AuthTokenStructureTests.PayloadNamesPersonNotAgent`, `.PayloadAct_Omitted`, `.ReservedClaims_RejectedInAdditionalClaims`, `.Builder_RejectsMissingSubjectOrPersonServer` | +| F02 | `PersonTokenBuilder`, `TokenVerifier`, `AAuthPersonServerEndpoints` | 2, 3, 5 | `PersonServerMapperTests.PersonTokenEndpoint_IssuesPersonToken`, `.PersonTokenEndpoint_LifetimeIsCappedByEveryBound`; `SignatureV10AdversarialTests.RawMalformedValuesHaveTypedErrorsWithoutTrustedContext` (person `scope`/`account`); `AuthTokenVerificationTests.Rejects_PersonToken`; `AccountBindingTests.CachedPersonToken_IsSelectedForAnyAccount` | +| F03 | `AAuthChallengeMiddleware` | 4 | `ChallengeMiddlewareTests.ChallengesAgentTokenWithPersonTokenRequirement`, `.ChallengesPersonTokenWithResourceToken`; `ChallengeHandlerTests.PrerequisiteAndStepUp_WireBodies` | +| F04 | `TokenVerifier.VerifyPresentedTokenAsync`, PS and AS token endpoints | 4, 5 | `PersonServerMapperTests.TokenRequest_MissingPresentedToken_Rejected`, `.TokenRequest_MismatchedPresentedToken_Rejected`, `.TokenRequest_OverwrittenIdentity_Rejected`, `.Clarification_ReplacementIsVerifiedAndChangesConsentScope`; `DeferredFederationTests.AsRejectsResourceTokenNotNamingTheSigningPsOrPresentedToken`; `ChallengeHandlerTests.PresentedToken_SurvivesHolderRefresh` | +| F05 | `MetadataClient`, `WellKnownEndpoints` | 1, 2, 5 | `AllRolesWellKnownMetadataTests.PsMetadata_RequiresPersonTokenEndpoint`; `ResourceAccessModeMetadataTests.AgentReadsDraft11PersonServerEndpoints`, `.RejectsRenamedAccessMode`, `.AgentParsesOnlyKnownAccessModes`. Algorithm lists and `aauth-resource` links are excluded optional items (see below). | +| F06 | `AAuthVerificationMiddleware`, `IssuerTrust`, `IJtiStore` keys | 4, 9 | `ChallengeMiddlewareTests.PersonTokenIssuerTrustIsIndependent`; `TokenInventoryTests.SameIdFromTwoIssuers_IsolatedIncludingGrants`; `RevocationLifecycleTests.ResourceMiddleware_SameAuthJtiFromTwoIssuers_RemainsIsolated`; `AuthTokenDeliveryTests.AccountDelivery_MatchesExactResourceExpectation` | +| F07 | `Mission`, `MissionProposal`, governance endpoints | 3, 4 | `MissionS256Tests.RawBytes_AreVerbatim`, `.Envelope_RejectsMismatchedS256`; `GovernanceDeferredConsentMapperTests.Mission_DefaultApprover_ReturnsApprovedBlob` (no `AAuth-Mission` header), `.MissionUpdate_OwnedMissionOnly` (update bytes and hash) | +| F08 | `MissionTokenConsentContext`, PS mission review | 3, 6 | `PersonServerMapperTests.AcceptedUpdate_ReachesConsentAndResetsFastPath`; `GovernanceDeferredConsentMapperTests.AcceptedUpdate_ReachesPermissionDecision`, `.MissionUpdate_OwnedMissionOnly` | +| F09 | `InMemoryMissionStore`, `GovernanceEndpoints` | 3, 6, 9 | `GovernanceServerTests.MissionStore_TerminatedIsFinal`, `.MissionStore_ConcurrentMutationKeepsTerminal`, `.MissionStore_ReplacementKeepsEarliestExpiry`; `GovernanceEndpointMapperTests.MissionAuthorization_RejectsInvalidContext`; `PersonServerMapperTests.Mission_Terminated_Rejected` | +| F10 | `AgentAssertedContent`, PS consent context | 4, 6 | `PersonServerMapperTests.AgentAssertedContent_ReachesAsserterApartFromResourceContext`; `MockPersonServerTests.Interaction_ConsentPage_AttributesAgentAssertedContentApartFromResource`; `DeferredFederationTests.ClaimsPushPreservesRequestedCredentialNamedIdentity` | +| F11 | `CallChainingRouter`, `UpstreamTokenValidator`, `AgentIssuanceContext` | 6 | `PersonServerMapperTests.CallChaining_UpstreamAudienceMustBeIntermediaryIssuer`, `.SubAgent_DirectRequest_Rejected`; `DeferredFederationTests.FourPartyUsesDistinctChildKeyAndUpstreamBounds`, `.SubagentTokenFromAnotherIssuerOrParent_IsInvalidSubagentToken` | +| F12 | `TokenVerifier`, `AuthTokenBuilder`, `TokenRefreshHandler` | 2, 4, 5 | `IssuanceBoundsTests.DirectAndDeferred_UseOriginalAgentAndParentBounds`, `.Deferred_RejectsOriginalExpiryDespiteFreshPollCarrier`; `PersonServerMapperTests.AuthToken_IsCappedByMissionExpiry`; `TokenRefreshHandlerTests.DefaultMargin_IsFiveMinutes`, `.ConcurrentRequests_OnlyRefreshOnce` | +| F13 | `AAuthVerifier`, `AAuthSigningHandler`, `AAuthVerificationMiddleware` | 1, 4, 9 | `SignatureErrorTests.CreatedOutsideWindow_ReturnsDistinctCodes`; `PersonServerMapperTests.PsBody_UncoveredOrTampered_FailsBeforeAsserter`; `DeferredFederationTests.AsBodyUncoveredOrTampered_FailsBeforePolicyOrPendingState`; `JtiStoreAndRevocationTests.Revocation_RequiresBodyCoverageAtEveryRecipient` | +| F14 | `RevocationEndpoint`, `InMemoryJtiStore` | 7 | `JtiStoreAndRevocationTests.Revocation_IssuerCannotRevokeOtherIssuerWithSameId`, `.Revocation_RejectsMalformedRequest`; `TokenInventoryTests.UnseenRevocation_IsRetainedUntilItsExpiryPlusRetention` | +| F15 | `AuthTokenResponse`, `IJtiStore` grants, PS and AS token endpoints | 7 | `PersonServerMapperTests.ResourceTokenLifetime_DoesNotCapAuthTokenOrGrant`, `.RevokedResourceToken_RejectedAndEndsPending`; `DeferredFederationTests.AsRefusesWithdrawnResourceToken`; `TokenInventoryTests.MissingOrRevokedSource_CannotCreateGrant`; `RevocationLifecycleTests.UpstreamRevokedDuringConsentCannotMintAfterApproval` | +| F16 | `SignatureErrorResult`, `AAuthProblemDetails`, `PollingErrorException` | 1, 4, 5, 7 | `ReplayDetectionMiddlewareTests.RevokedAuthToken_Rejected`; `PollingErrorTests.TerminalCodes_AreDistinctWithDetail`; `ChallengeHandlerTests.Exchange_EveryPublishedError_IsDistinct`; `DeferredFederationTests.AsOutcomesMapSeparatelyFromLocalCancellation` | +| F17 | `AAuthHeldInvocations`, `AAuthSingleUseGrants`, `ChallengeHandler` | 5, 8 | `ChallengeHandlerTests.DeferredAuthToken_PollsPendingUrlWithoutResendingBody`; `HeldInvocationTests.SingleUseGrant_ExecutesOncePerJti`; `BookingsPolicyTests.EveryRoute_EnforcesGrantedPerCallRejectedAndApprovedParameters` | +| F18 | R3 model and vocabularies | 1, 8 | `TokenClaimTests.Draft11WireNames_PerCallClaimAndNoDocumentVersion`; `R3VocabularyTests.MalformedOrRemovedDiscoveryFails`, `.MergedDefinition_RenamedCollidingOperationsAreDistinct`; `R3Draft11FixtureTests.Annotations_ApplySpecRules` | +| F19 | `R3DocumentReaderPolicy`, R3 AS token endpoint | 4, 8 | `BookingsPolicyTests.PersonServerEvaluator_ReadsOnlyDocumentsItIsEntitledTo`; `AccessEndpointR3Tests.UncoveredOrTamperedBodyFailsBeforeDocumentPolicyOrAudit`, `.TokenEndpoint_DoesNotReleaseTokenThatExpiresDuringAudit`; `R3SqliteAuditTests.Commit_SurvivesRestartAndConcurrentIssuance` | +| F20 | `EventsTokens`, subscription tickets | 4, 8 | `EventHttpTests.ForeignIssuerCannotSpendVictimTicketOrInjectSubscription`; `EventPersistenceTests.TicketRedemptionIsAtomicAndPreservesAccount`, `.AgentContextPersistsAndEventsDedupeOnIssuerAndJti`; `EventsTokenTests.InvalidEventClaimsFail` (`cnf`) | +| F21 | `R3ProposalDocument` | 8 | `R3Draft11FixtureTests.ResultBearingProposal_FailsClosedInsteadOfBecomingAnExecutionApproval`. Release gating is unsupported and fails closed. | +| F22 | None (Budgets) | Separate | Excluded: the SDK meters nothing and claims no Budgets support. Re-entry needs its own plan. | +| F23 | `AAuthClientBuilder` bootstrap | 6 | `AAuthClientBuilderBootstrapTests.Enrolled_ResourceManagedAccess_ComposesBeforeInteractionHandling`. No delayed verifier exists, so live acceptance is unchanged. Delayed verification stays separate work. | +| F24 | `tools/ApiSurface`, documentation tests, e2e | 1, 9-11 | `SnippetCompilationTests.Documentation_FrozenSurface`; `DocumentationLinkTests`; the full Playwright run (76 passed, 1 skipped, 2026-09-29) | + +## Negative requirements: execution evidence + +Recorded 2026-09-29. The verdicts in the audit above describe the source before +implementation. This table records each negative's execution evidence, or its +explicit conditional disposition. + +| Requirement | Evidence or disposition | +|---|---| +| Person token no scope/account | `SignatureV10AdversarialTests.RawMalformedValuesHaveTypedErrorsWithoutTrustedContext` (`aa-person+jwt` with `scope` or `account` is `invalid_jwt`) | +| Person cannot replace required auth | `AuthTokenVerificationTests.Rejects_PersonToken` | +| Agent-only request cannot mint challenge | `ChallengeMiddlewareTests.ChallengesAgentTokenWithPersonTokenRequirement` (bare `requirement=person-token`, no resource token) | +| No substituted or stripped identity/mission | `PersonServerMapperTests.TokenRequest_OverwrittenIdentity_Rejected`, `.TokenRequest_MismatchedPresentedToken_Rejected`; `DeferredFederationTests.AsRejectsResourceTokenNotNamingTheSigningPsOrPresentedToken` | +| No resource-visible agent/act | `AuthTokenStructureTests.PayloadNamesPersonNotAgent`, `.PayloadAct_Omitted`, `.ReservedClaims_RejectedInAdditionalClaims` | +| Auth cannot outlive source agent | `IssuanceBoundsTests.DirectAndDeferred_UseOriginalAgentAndParentBounds`; `PersonServerMapperTests.AuthToken_IsCappedByMissionExpiry`. A resource cannot check the agent ceiling itself, since it never sees the agent token. The issuer owns that bound. | +| Terminal mission cannot reactivate | `GovernanceServerTests.MissionStore_TerminatedIsFinal`, `.MissionStore_ConcurrentMutationKeepsTerminal` | +| No mission disclosure before owner authorization | `GovernanceEndpointMapperTests.MissionAuthorization_RejectsInvalidContext` (foreign equals missing: `404 mission_not_found`, nothing logged). Conditional: equal timing is a property of the `IMissionStore` implementation. The in-memory store does one keyed lookup for both cases; a deployment's store owns its own timing. | +| Worker cannot authorize itself | `PersonServerMapperTests.SubAgent_DirectRequest_Rejected` | +| Caller cannot select another revocation issuer | `JtiStoreAndRevocationTests.Revocation_IssuerCannotRevokeOtherIssuerWithSameId` | +| Revoked resource token cannot mint auth | `PersonServerMapperTests.RevokedResourceToken_RejectedAndEndsPending`; `DeferredFederationTests.AsRefusesWithdrawnResourceToken` (added 2026-09-29, after this audit found the check missing) | +| One per-call grant cannot execute twice | `HeldInvocationTests.SingleUseGrant_ExecutesOncePerJti`; `BookingsPolicyTests.EveryRoute_EnforcesGrantedPerCallRejectedAndApprovedParameters` | +| Event self-JWT no cnf | `EventsTokenTests.InvalidEventClaimsFail` (`cnf` present fails) | +| Link cannot direct arbitrary fetch/key trust | Conditional: no `aauth-resource` link consumer exists (AG-03 excluded). Selecting AG-03 requires validation before fetch. | +| 403 no signature error/negotiation headers | `SignatureV10AdversarialTests.AuthorizationDenialHasNoSignatureHeaders`; `GovernanceEndpointMapperTests.MissionAuthorization_RejectsInvalidContext` | +| No pre-execution of billed/metered/audited work | Conditional: release gating is unsupported. `R3Draft11FixtureTests.ResultBearingProposal_FailsClosedInsteadOfBecomingAnExecutionApproval` proves a release request never becomes an execute approval. | +| Consumption plus reservations cannot exceed budget | Conditional: Budgets is excluded (F22). No metering exists to overshoot. | + +## Upgrade checklist ownership + +Recorded 2026-09-29. Every ID in +[upgrade-10-to-11](../../../aauth-spec/v11/upgrade-10-to-11/README.md) is listed +here: 55 PS, 33 RS, 30 AG, 7 AP and 22 AS. Each has one owning phase or a +recorded optional disposition. + +| Role | Phase | IDs | +|---|---|---| +| PS | 1 | PS-01, PS-100, PS-101, PS-102, PS-103, PS-104 | +| PS | 2 | PS-02, PS-10, PS-11, PS-12, PS-13, PS-20, PS-95 | +| PS | 3 | PS-04, PS-80, PS-81, PS-82, PS-83, PS-84, PS-85, PS-86 | +| PS | 4 | PS-30, PS-31, PS-32, PS-33, PS-34, PS-35, PS-36, PS-40, PS-50, PS-51, PS-52, PS-53, PS-54, PS-55 | +| PS | 6 | PS-60, PS-61, PS-62, PS-63, PS-64, PS-70, PS-71 | +| PS | 7 | PS-03, PS-110, PS-111, PS-112, PS-113, PS-114, PS-115 | +| RS | 1 | RS-01, RS-02, RS-50, RS-51, RS-52 | +| RS | 2 | RS-10, RS-11, RS-12 | +| RS | 4 | RS-20, RS-21, RS-30, RS-31, RS-32, RS-33, RS-34, RS-40, RS-41, RS-42 | +| RS | 6 | RS-70, RS-71, RS-72, RS-73, RS-74, RS-75 | +| RS | 7 | RS-03, RS-43, RS-60, RS-61 | +| AG | 1 | AG-01, AG-02, AG-52 | +| AG | 2 | AG-10 | +| AG | 3 | AG-30, AG-31, AG-32, AG-33, AG-34 | +| AG | 4 | AG-20, AG-21, AG-22, AG-23, AG-24, AG-25 | +| AG | 5 | AG-11, AG-12, AG-26, AG-50, AG-51, AG-60, AG-61, AG-62, AG-63, AG-64, AG-70 | +| AG | 6 | AG-40 | +| AP | 1 | AP-01, AP-03, AP-04, AP-05 | +| AP | 6 | AP-02 | +| AP | 7 | AP-07 | +| AS | 1 | AS-01, AS-30, AS-31, AS-32 | +| AS | 4 | AS-10, AS-11, AS-15, AS-16, AS-17, AS-20, AS-21, AS-22 | +| AS | 6 | AS-12, AS-13, AS-14 | +| AS | 7 | AS-02, AS-40, AS-41, AS-42, AS-43, AS-44 | + +Optional items: + +| ID | Disposition | Evidence | +|---|---|---| +| PS-05, RS-04, AP-06, AS-03 | Excluded: no `accept_signature_algs` advertisement. Verifiers still enforce their algorithm set. | No `accept_signature_algs` in `src/` | +| RS-04 (link), AG-03 | Excluded: no `aauth-resource` link publishing or discovery | No link consumer in `src/` | +| RS-13 | Excluded as a dedicated mode. Identity-only endpoints pass verified person tokens, and metadata can declare `access_mode: person-token`. No per-endpoint step-up helper exists for person-identity resources. | `ResourceAccessModeMetadataTests.EmitsEachAccessMode` | +| RS-35 | Selected (Phase 4) | `ResourceTokenBuilder.LoginHint`; `PersonServerMapperTests.PersonTokenRequest_CapabilitiesAndLoginHintReachAsserter` | +| RS-36 | Selected (Phase 5) | `AAuthHeldInvocations`; `HeldInvocationTests`; `ChallengeHandlerTests.DeferredAuthToken_PollsPendingUrlWithoutResendingBody` | +| RS-62 | Selected (Phase 7): resources revoke with the generic `RevocationClient`. PS and AS recipients enforce PS-112 and AS-42. | `DeferredFederationTests.AsRefusesWithdrawnResourceToken` (signed as the resource) | +| PS-87, AG-35 | Selected (Phase 3) | `MissionClient.UpdateAsync`; `GovernanceDeferredConsentMapperTests.MissionUpdate_OwnedMissionOnly` | +| PS-88, AG-36 | Selected (Phase 3) | `MissionProposal` `resources`; `MissionPersonTokenIssuanceTests.PartialResourceApproval_LimitsApprovedResourcesAndPersonTokens` | +| PS-89 | Selected (Phase 3) | `GovernanceServerTests.MissionStore_ReplacementKeepsEarliestExpiry`; `PersonServerMapperTests.Mission_Terminated_Rejected` (expired) | +| PS-90 | Partly selected (Phase 3): the SDK reports `termination_reason: expired`. `IMissionStore` records no other reasons, so they are omitted. | `PersonServerMapperTests.Mission_Terminated_Rejected`; `GovernanceEndpointMapperTests.MissionAuthorization_RejectsInvalidContext` | +| PS-96 | Host capability: a PS completes a hosted interaction over its own channel by calling `IPersonPendingStore.MarkAllowed` or `MarkDenied`. No sample demonstrates a non-browser channel. | `IPersonPendingStore` | + +## Revocation cascade: executed checks + +Recorded 2026-09-30 by the SDK API surface plan, Phase 6 +([log](../2026-09-29-sdk-api-surface-consistency/implementation-log.md)). +The cascades run through `IAAuthRevocationService`, which the inbound endpoint +and app code share. + +| Requirement | Governing clause | Executed discriminatory checks | +|---|---|---| +| PS revokes a person token at its `aud` and at every AS it presented it to; SHOULD revoke person tokens issued from it as an upstream token | [P2752](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2752), `#revocation-cascade` | `PersonTokenRevocationCascadeTests.RevokeToken_ReachesAudienceAndEveryAccessServer`, `.RevokeToken_RevokesUpstreamDerivedPersonTokens` | +| PS revokes a mission: later requests under its `s256` are denied; SHOULD revoke the tokens issued under it | [P2754](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2754), `#revocation-cascade` | `MissionRevocationCascadeTests.RevokeMission_TerminatesAndRevokesMissionTokens` | +| AP revokes an agent token: the PS MUST deny it and SHOULD revoke what it issued to that agent's `sub`, whichever agent token it presented; the binding is unaltered | [P2755](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2755), `#revocation-cascade` | `AgentTokenRevocationCascadeTests.ProviderRevoke_CascadesBySubAcrossAgentTokens`, `.RevokeAgent_RevokesIssuedTokensOnly` | +| Records: agent token `(iss, jti)` with its `sub`; issued tokens with resource and `exp`; upstream `(iss, jti)` | [P2758](../../../aauth-spec/v11/draft-hardt-oauth-aauth-protocol.md#L2758), `#revocation-cascade` | Covered by the three rows above; `IJtiStore.RecordSubjectAsync` and `GetGrantAsync` close the gap | + +## Evidence state + +Implementation must record exact commands, failures, fixes/reruns, API/docs +inventory output, fresh browser modes and unavailable prerequisites in +[implementation-log.md](implementation-log.md). No test counts are inherited +from the historical v10 ledger. Research checks concern Markdown, source +references, classification and coverage only. + +Final independent review includes synthesis across F04/F07 mission stripping, +F08/F11 consent authority after updates, F12/F15 expiry versus withdrawal, +F17/F20 ticket issuance on retained-result retries, and F18/F24 Catalog examples. \ No newline at end of file diff --git a/.agent/plans/2026-09-11-aauth-v11-spec-migration/docs-surface-map.md b/.agent/plans/2026-09-11-aauth-v11-spec-migration/docs-surface-map.md new file mode 100644 index 00000000..8e696d73 --- /dev/null +++ b/.agent/plans/2026-09-11-aauth-v11-spec-migration/docs-surface-map.md @@ -0,0 +1,1013 @@ +--- +description: Draft-11 WIP documentation and embedded-snippet impact inventory. +--- + +# Documentation surface map - draft-11 WIP + +Analysis only, 2026-09-11, baseline `94576a3ebcba8cd1d167923e50c8796132057600`. +This map follows the draft-10 inventory pattern without claiming every embedded +block has already been enumerated or validated. Requirements and citations live +in [research.md](research.md); F labels associate the change with that evidence. +Public documentation still correctly targets draft-10 until implementation and +verification change that claim. A WIP research snapshot is not a target bump. + +## Live page inventory + +| Surface | Current locations | Required content change | Validation class | +|---|---|---|---| +| Product and package entry points | [README](../../../README.md), [samples README](../../../samples/README.md), [core package](../../../src/AAuth/), [R3 package](../../../src/AAuth.R3/), [Events package](../../../src/AAuth.Events/) | Five access modes, person-token leg, current supported/excluded capabilities, WIP versus published target; do not claim all companions are migrated. F02/F20/F22/F23 | Target/source consistency, links, compiled quick-start excerpts | +| Learning path | [docs index](../../../docs/README.md), [concepts](../../../docs/concepts.md), [getting started](../../../docs/getting-started.md), [glossary](../../../docs/glossary.md) | Agent/person/session/auth distinction; person continuity versus proofing; resource-visible key/person identity, not agent/actor chain. F01-F06 | Semantic review and runnable first-use scenario | +| API/configuration | [configuration](../../../docs/reference/configuration.md), [dependency injection](../../../docs/reference/dependency-injection.md) | Required new endpoint fields and builders; clock policy, role body coverage, caches, ownership, expiry/revocation storage. F02/F05/F12-F15 | Source declaration/default checks and C# compilation | +| Server contracts | [server guides](../../../docs/server/) | Token issuance, claims projection, verification, authorization policies, challenges, metadata, replay/revocation; person token must never bypass scope authorization. F01-F06/F13-F16 | Endpoint tests plus prose/HTTP examples | +| Revocation | [replay detection](../../../docs/server/replay-detection.md) | `jti/exp` body, verified caller namespace, unseen-token 200, person-to-AS cascade, expiry versus dependency. Remove cross-issuer PS override examples. F14/F15 | Parse examples and exercise actual HTTP responses | +| Signing modes | [signing-mode guides](../../../docs/signing-modes/) | Separate generic Signature Keys demonstrations from AAuth agent/server role rules; preserve Events self-JWT and AP naming-key refresh. F13/F23 | Carrier matrix tests and exact code examples | +| Standard workflows | [workflow guides](../../../docs/workflows/) | Person acquisition before Calendar/Wallet resource challenges, PS/AS presented-token forwarding, runtime step-up/202 completion; keep Inbox resource-managed flow distinct. F02-F05/F17 | Captured-wire assertions and matching diagrams | +| Missions | [missions](../../../docs/advanced/missions.md), [governance clients](../../../docs/advanced/mission-governance-clients.md), [mission workflow](../../../docs/workflows/mission-governed-access.md) | Encoded approval, hash of decoded blob, optional resource-keyed person-token map, no AAuth-Mission, accepted updates and new completion URL, terminal reasons/expiry. F07-F10 | Blob hash tests, compiled client examples, actual consent workflow | +| Chaining and workers | [advanced guides](../../../docs/advanced/), [workflow guides](../../../docs/workflows/), [worker scenario](../../../samples/FederatedWorkerScenario.cs) | Upstream `ps` routing, parent-issued worker person token, no resource actor chain. Keep Q3-Q5 caveats visible until resolved. F11/F20 | Distinct-key/person tests and both-app flows | +| R3 and Catalog | [R3 workflow](../../../docs/workflows/rich-resource-requests.md), [Catalog guide](../../../docs/workflows/catalog-gateway.md) | PerCall rename, remove document Version and OpenAPI Gateway standard contract, redesign Catalog discovery, seven vocabularies; preserve raw-byte hashing. F17-F19 | JSON/schema/claim checks, executed Catalog and Bookings scenarios | +| Errors, interaction and observability | [error handling](../../../docs/advanced/error-handling.md), [interaction chaining](../../../docs/advanced/interaction-chaining.md), [clarification](../../../docs/advanced/clarification-chat.md), [observability](../../../docs/advanced/observability.md) | Presented-token errors, truthful revocation, AS relay versus unavailability, clock-skew recovery, captured credential in clarification; redact sensitive person/mission/ticket state. F04/F08/F16 | Negative endpoint/polling tests; example response classification | +| Bootstrap and keys | [key management](../../../docs/advanced/key-management.md), [platform attestation](../../../docs/advanced/platform-attestation.md), sample AP/console help | Multiple agent keys versus published AP key; parent acquisition guidance remains informational; avoid unsupported platform/hosted-enrollment claims. F23 | Existing enrollment/refresh regressions, source review | +| New optional features | R3 annotations/result-release descriptions and Budgets references | State selection and limitations explicitly. An annotation is not a grant or implemented metering; a result field is not permission to pre-execute billable work. F19/F21/F22 | Capability guard tests or explicit unsupported status | + +## Embedded and executable content + +| Content class | Owning files/directories | Required treatment | +|---|---|---| +| GuidedTour runtime | [TourSession](../../../samples/GuidedTour/TourSession.cs), [components](../../../samples/GuidedTour/Components/) | Step plans/counts, dispatcher indices, approval/poll indices, actor lanes, selected payloads, nested sequences, reset and completion must agree. | +| SampleApp runtime | [pages](../../../samples/SampleApp/Components/Pages/), [EnrollmentService](../../../samples/SampleApp/EnrollmentService.cs), [SelfIssuedIdentity](../../../samples/SampleApp/SelfIssuedIdentity.cs) | Real button actions, account selectors, consent links, state and payload panels move with API changes. Do not assume every legacy page is a numbered GuidedTour sequence. | +| Shared capability UI | [CapabilitySupport](../../../samples/CapabilitySupport/), [EventSupport](../../../samples/EventSupport/) | Sessions, code templates, protocol sequence components and wrapper routes in both apps must stay synchronized. | +| Compiled server/console examples | [mock resources](../../../samples/MockResourceServers/), [mock PS](../../../samples/MockPersonServer/), [mock AS](../../../samples/MockAccessServers/), [AgentConsole](../../../samples/AgentConsole/), [MissionAgent](../../../samples/MissionAgent/), [Concierge](../../../samples/Concierge/), [EventAgent](../../../samples/EventAgent/), [LiveWhoAmITest](../../../samples/LiveWhoAmITest/) | Fix callers in the owning code phase, including custom minting/approval paths that bypass standard mappers. Console output and help are instructional too. | +| Non-compiled snippets | Markdown and quoted fences, raw/interpolated/ordinary C# strings, Razor preformatted/inline blocks, JSON/HTTP examples, Mermaid diagrams | Inventory by syntax and old-wire patterns; compilation alone cannot find stale text or wrong captured-step associations. | +| Browser expectations | [e2e tests](../../../tests/e2e/), [tour helper](../../../tests/e2e/helpers/tour.ts), [Wallet helper](../../../tests/e2e/helpers/wallet-protocol.ts) | Numeric step selectors, totals, payload assumptions and actor assertions change with runtime plans; retain desktop/mobile and both-host coverage. | +| Local demo state | [Makefile](../../../Makefile), sample state/key configuration, SQLite stores | Version isolation or explicit migration for old credentials/tickets/missions; update displayed labels and restart guidance without deleting state. | + +## Pattern and classification sweep + +Search live surfaces case-insensitively with both wire and .NET names: + +```text +token_endpoint / TokenEndpoint +aauth-access-token / AAuthAccessToken +AAuth-Mission / AAuthMissionHeader / MissionAware / missionAware +mission.approver / MissionClaim / mission blob / approval bytes +presented_token / PresentedToken / presented_jti / PresentedTokenId +act.agent / ActChain / ActChainsMatch / parent_agent +r3_conditional / Conditional / r3_per_call / PerCall +openapi-gateway / OpenApiGateway / service-qualified +version / Version (R3 documents, not OpenAPI/AsyncAPI or package versions) +revocation / RevokeAsync / unknown_token / TrustedPersonServers +clock_skew / ClockSkew / expires / refresh / four access modes +``` + +Every match gets a disposition: executable migration, display migration, +intentional generic signing, OIDC/other protocol, historical record, or unrelated +domain term. Do not rename OIDC endpoints, remove AP agent claims, change WSDL +service qualifiers, or scrub historical snapshots/plans. Truncated search output +cannot establish completeness. Exclude generated bin/obj and browser artifacts. + +## Verification classes + +| Class | Evidence it establishes | What it does not establish | +|---|---|---| +| Exact C# snippet compilation | Symbols, types, overloads, required members | Runtime trust, network exchange, or current UI use | +| JSON/schema/HTTP parsing | Shape, field types, expected status/carriage | Cryptographically valid placeholder tokens/signatures | +| Captured-wire endpoint tests | Actual emitted values and verification behavior | External deployment compatibility | +| Browser scenario | Action, approval, selected-step payload and rendering agree | Every SDK overload or security condition | +| Link/anchor validation | Targets exist and citations identify intended lines | Correctness of the claimed behavior | +| Semantic source review | Claims match pinned requirements and capability scope | An executed test pass | + +## Tooling prerequisites + +[SnippetCompilationTests L228](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs#L228) +targets the old docs map, and its +[L299](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs#L299) +heuristic expects `iss` in a `jti` body. Retarget the map and classify revocation +before using it as a v11 gate. Inspect +[DocumentationInventory](../../../tests/AAuth.Tests/Api/DocumentationInventory.cs) +for selected-directory exclusions; supplement it with console/server/string and +wire-pattern inventory. Do not manufacture passing counts from the v10 appendix. + +The final sweep occurs after public API freeze. Compiled callers and executable +sample flow changes occur in their code phases so the solution stays buildable. +API-dependent Markdown fences, reference tables and inventory expectations that +the existing snippet tests validate also change in those contract phases; do not +disable or suppress those tests to defer the work. +The sweep checks finished behavior and remaining static content; it does not +defer the walkthrough implementation until documentation time. + +> **Update (2026-09):** Phase 1 retargeted `Documentation_FrozenSurface` to +> this file. Set `AAUTH_UPDATE_DOCS_INVENTORY=1` only after reviewing changed +> surfaces, then rerun without it. The appendix below is regenerated from the +> draft-11 tree. `CheckSnippet` fails the test for any block it cannot +> classify, so every listed block carries a validation class. The Phase 10 +> sweep (2026-09-29) dispositions the old wire and API names found outside +> these blocks; see the implementation log. + + + +## Complete Inventory + +175 files; 707 blocks. Counts by validation class: + +- 32: API excerpt: source member/type/sealed checks; not executable +- 1: C# comment-only narrative: reviewed against the associated scenario; no executable statements +- 36: Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests +- 304: Exact C# compiled with typed prior-step/host inputs +- 1: External template: Azure.Security.KeyVault.Secrets/Azure.Core required; exportable Ed25519 secrets, not HSM signing; syntax checked only. +- 1: External template: OpenTelemetry.Extensions.Hosting and Instrumentation.AspNetCore required; syntax checked, exporter not executed. +- 3: Illustrative platform adapter: IWebAuthnService/DeviceCheck are host placeholders; IPlatformAttestor signature checked separately; no hardware or AP challenge/retry claim. +- 20: Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request +- 200: Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program +- 1: JSON member fragment parsed inside an explicit object +- 6: JSON parsed; displayed identifiers/claims are illustrative +- 29: Sequence/flow source checked; actors/order reviewed against mapped scenario +- 69: Shell syntax checked; side-effect commands not executed +- 4: SQL runtime literal: sample build and Events HTTP/persistence tests + +| File | SHA-256 | Blocks | Check | +|---|---|---|---| +| [docs/advanced/clarification-chat.md](../../../docs/advanced/clarification-chat.md) | `e7519ea5a70cd598f1ecd137c119f3d7a5b8032e1b702011e34513e38b79d9b6` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/error-handling.md](../../../docs/advanced/error-handling.md) | `1af69a6836aba7fd621ffc3c97ac7f22451a172ed3f0f999335568bcff255f66` | 17 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/interaction-chaining.md](../../../docs/advanced/interaction-chaining.md) | `8f6e2c30c95dc9f5618dce3e290dd1c41e6f3157119db8df0fb49e895ec024d0` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/key-management.md](../../../docs/advanced/key-management.md) | `518e87828d95ad9c6d148647844a5f53f9c3c58970f7993e84b2193773a1e1ff` | 8 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/mission-governance-clients.md](../../../docs/advanced/mission-governance-clients.md) | `795e0e835936a27d0437205303d6f8d3ce623dd3857b117df2b6aa3eb8c2ba19` | 8 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/missions.md](../../../docs/advanced/missions.md) | `3082b5ca14ea8edf95804423bcaf9e8db4a8f54386c2306006b94846b1979837` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/observability.md](../../../docs/advanced/observability.md) | `83b69972d4762123f232bbb5c15e0bde239c0f5e5f13034d3e00df72619beb37` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/advanced/platform-attestation.md](../../../docs/advanced/platform-attestation.md) | `8f5bb17d33a1d559187a147470778ca1c32adca06debcb9cefbd5b34d3fa74c1` | 5 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/concepts.md](../../../docs/concepts.md) | `b464768ee4f9d89030463b4c2ad025a43850c950412946bb8003fb7e851895e1` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/getting-started.md](../../../docs/getting-started.md) | `ae12a73890b7b8c6b308fcc190cd272a3c1a3d2d912cc687f8091185bba246b8` | 27 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/glossary.md](../../../docs/glossary.md) | `59f26b56ae854045dcf7f57a620d59695b33807381805deda7a99b13bb327c97` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/README.md](../../../docs/README.md) | `ca1e2b243ed4365ed376e0b906fd947ff046e0a25cb76cc39b607da6ef40718e` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/reference/configuration.md](../../../docs/reference/configuration.md) | `06ad287b0bf6bf185fd4386a79ca13f5b2bc2c89272120d7a59e2353dc793491` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/reference/dependency-injection.md](../../../docs/reference/dependency-injection.md) | `446c16e3991f2d096642789f0cd89d0f63905827e919d4f2bb5e0d34f0b0e40a` | 34 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/authn-authz.md](../../../docs/server/authn-authz.md) | `fa1e6ad0e701ff2ffc664106fd56094ea14e290b0239b16ddfe8a42d690c8ec5` | 9 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/authorization-policies.md](../../../docs/server/authorization-policies.md) | `03587128ad71eae07e799f264a44f53eb798a814322a7bb7cd54ed64ba0c66f6` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/challenge-middleware.md](../../../docs/server/challenge-middleware.md) | `64a41e75746874eefcecc11347f443a84e86a331acd8828fe001787acdf636e8` | 8 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/mission-governance.md](../../../docs/server/mission-governance.md) | `0a20fa4179bb73c91f8a6def62df23a98b0849c862899187555cd9cb2d53e4e1` | 12 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/multi-scheme-verification.md](../../../docs/server/multi-scheme-verification.md) | `da8811198edec65f59661fe5aadb3080915823a4193e79e5b2334316bfb4c834` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/replay-detection.md](../../../docs/server/replay-detection.md) | `def27bd4bd8f8efc966899bfb5b4d5cfcce57e8e5c5fc885a47f2dd0acefbca8` | 9 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/resource-metadata.md](../../../docs/server/resource-metadata.md) | `2652e46dd84a328205fc93b738b57f47e3481c896e9581b79b8e447682f6fc3f` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/token-issuance.md](../../../docs/server/token-issuance.md) | `79da18461a89c496976fda6307d2de8f06f6fdb4348fd672fe43db30862da417` | 13 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/server/verification-middleware.md](../../../docs/server/verification-middleware.md) | `0d10597559f8ad891f92c779d13cb0c55d78dfc34d1e468e26d83a045c608dcb` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/signing-modes/agent-identity-jwks-uri.md](../../../docs/signing-modes/agent-identity-jwks-uri.md) | `3b39a16276e62e9bbf89a52d19fdea29f8281bb15916940c97aff0d0eeabe212` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/signing-modes/agent-token-jwt.md](../../../docs/signing-modes/agent-token-jwt.md) | `3b180f73389c20c8954addbab5ed01a182f3c4d74ce33daff6dfde9034856558` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/signing-modes/key-rotation-jkt-jwt.md](../../../docs/signing-modes/key-rotation-jkt-jwt.md) | `1f90a9fd0d688ff266c1e61caf3c33af92c9640bfb7ee813bf4adfd03bdbda5a` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/signing-modes/overview.md](../../../docs/signing-modes/overview.md) | `c719b15fc2aa113ae9f42ab9acb800ed83c43a2a47c8abdabcb1d40bb30d27e9` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/signing-modes/pseudonymous-hwk.md](../../../docs/signing-modes/pseudonymous-hwk.md) | `a951e22eb57ab03cb3bb0a6f37bc07e2cdb8775127ae3418434b8fad658f0f51` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/bootstrap-enrollment.md](../../../docs/workflows/bootstrap-enrollment.md) | `a4b855cc8d97a4c71cb0485c0a3d2aa394df23784f3d94dcf4a6802b2985c47e` | 13 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/call-chaining.md](../../../docs/workflows/call-chaining.md) | `50c47a6e74b60cc3cbce4b4ca569f3018ed0c7e42ae0d8caa14609d95915a4c1` | 14 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/catalog-gateway.md](../../../docs/workflows/catalog-gateway.md) | `a57683c9ce79bb71de2e51a1f9f51f12cd5cdfdf5c09db0e8bc1bc349b20118a` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/deferred-consent.md](../../../docs/workflows/deferred-consent.md) | `731465d3976bbb3f47f969277ff12e8a522f6ae4bca339cd0f69a1574f99afae` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/document-release.md](../../../docs/workflows/document-release.md) | `3462f5f4fbd3dbe1ee6102ddb67ea4452204c720f6dfd9ab95fb5e8d48dbcda0` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/events.md](../../../docs/workflows/events.md) | `a1d95325d44d730bfb06dbbefb743369dbe37979d636e7787ed5a0376f4fe785` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/federated-access.md](../../../docs/workflows/federated-access.md) | `e34d1ff3cea45a332c80356a4d8db2e3e02655cd33d312cd5cc95fea460477be` | 10 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/identity-based-access.md](../../../docs/workflows/identity-based-access.md) | `dd5b512d612ecbb939b49ac2960c57e4e6631a5951f5bafc3545ca3acf2288c7` | 5 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/mission-governed-access.md](../../../docs/workflows/mission-governed-access.md) | `79af50bc11e372b666bce2527c027401e2fd6aa5b5f89d4fd138bcd8c8c6f600` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/ps-asserted-access.md](../../../docs/workflows/ps-asserted-access.md) | `4b488cfffc7f41f8626c4db67f01913d0b24e8d169bcbef872302509d618a1cb` | 5 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/resource-managed-access.md](../../../docs/workflows/resource-managed-access.md) | `15f7d04e9fb72e8522cb15fcbe846fbc8cfd4f79803bb9b63ca2f47f882eeddf` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/rich-resource-requests.md](../../../docs/workflows/rich-resource-requests.md) | `7e18bd12fbf469d713f7b65fabdba12d69b9067346fa60bce95fca6de1f79ecb` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [docs/workflows/wallet-protocol.md](../../../docs/workflows/wallet-protocol.md) | `2f01d3350e22bad70dfe67e7a8f65c0ffd7c5a6f950d22907fa77731bca534f4` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [README.md](../../../README.md) | `efe2af0975ced97b40b866e380b37c29394fb47d6ce712708b44a4a156361cfb` | 10 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/AgentConsole/README.md](../../../samples/AgentConsole/README.md) | `c21e175a15f51a47cc9dfb61b95604be87ef3d7ff07e6551c3af14c3c8cd3321` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/CatalogDemoSession.cs](../../../samples/CapabilitySupport/CatalogDemoSession.cs) | `54745a6dee95a60e7c368d16c8a339145c02451adbd2328059a3f00d69bc0db0` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/CatalogWalkthrough.razor](../../../samples/CapabilitySupport/CatalogWalkthrough.razor) | `74a82a32bde728372990369f6666b9abf1b7ed99b5608ccd2b315d5fa7e1ad02` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/DocumentDemoSession.cs](../../../samples/CapabilitySupport/DocumentDemoSession.cs) | `3cabc9b58632d8343c7cdd3d0dac00219cb6a2f7a37c036af39841b24b2876bd` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/DocumentWalkthrough.razor](../../../samples/CapabilitySupport/DocumentWalkthrough.razor) | `4a78c1a11bdfa8ebff9b98b01a32b3e8c3c466952af22223a55a827090b44437` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/ScenarioWireHandler.cs](../../../samples/CapabilitySupport/ScenarioWireHandler.cs) | `586314556b765dd1a2e3570f555c9fd2191d18410c4b3d4e3736dd67049f3224` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/WalletDemoSession.cs](../../../samples/CapabilitySupport/WalletDemoSession.cs) | `9d741fc6ec7f3d5e503e3f990eafe731317bc9fee1b5e478e66a2845ac33280a` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/WalletScenarioCode.cs](../../../samples/CapabilitySupport/WalletScenarioCode.cs) | `74e1af5dedc6c3385b552f192e521684ba407064bef541dc124a194911ddd7cc` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/CapabilitySupport/WalletWalkthrough.razor](../../../samples/CapabilitySupport/WalletWalkthrough.razor) | `048e60297c2190da7265394bc9d5a6c833f1cc59bc250abbd241fcec288415b5` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/Concierge/README.md](../../../samples/Concierge/README.md) | `dce75f6fe69725c89a96913f9e2d01f8f5fa112d71e3a24c27d50303b239458d` | 5 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventAgent/README.md](../../../samples/EventAgent/README.md) | `f08fcb576a8ffbe4e39b6171a09a416ebea1f11f3704253814f70c34c00789b1` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/BookingsEvents.cs](../../../samples/EventSupport/BookingsEvents.cs) | `41f85f55c0e6e1249f8df21293bfe6c9ffc6a77f5d8fb82b5a6334fbdfdce5fd` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/EventDemoCode.cs](../../../samples/EventSupport/EventDemoCode.cs) | `f01c558744ac72c61946bc9b6241b9d54b0e080b072470af3fa266ca1b462fd8` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/EventDemoSession.cs](../../../samples/EventSupport/EventDemoSession.cs) | `e15052d5b5fc73f8f9257971aa8abcc6c464a3c8e196dd36b3ea1f7755886d9f` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/EventWalkthrough.razor](../../../samples/EventSupport/EventWalkthrough.razor) | `711d8a40140cb7f81602918c87fd2ffcff5f217bc7bdd3568facaf4fe73dad23` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/LocalEventProvider.cs](../../../samples/EventSupport/LocalEventProvider.cs) | `8ad5db4f19672b9247295cdbabb68ebcb85082dc00b940738906c357e9b94580` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/ProtocolSequence.razor](../../../samples/EventSupport/ProtocolSequence.razor) | `d980c16356c88e74e714df0da3676b730a3ef88d3de3caa946c5ea601a94d19d` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/ProtocolSequenceModel.cs](../../../samples/EventSupport/ProtocolSequenceModel.cs) | `cbf3f5139661c5a9883d0e5596b5da42ce8ae3f589d2553e8429e136ac5409ad` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/SampleAgentEnrollment.cs](../../../samples/EventSupport/SampleAgentEnrollment.cs) | `af7efb9ede5427ea8154c2ad523cfd6e905d429737fc10bddbb72a297779a862` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/SampleAgentRegistry.cs](../../../samples/EventSupport/SampleAgentRegistry.cs) | `754f5f423e54bff18ffda08262344993c742b2a22d09674b328e7ef54a5d7378` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/SqliteEventStore.cs](../../../samples/EventSupport/SqliteEventStore.cs) | `145cd2883da927ae60c12855ccce87dcc6a7c7290565b2a7bd1fce4977dacbcd` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/EventSupport/SyntaxHighlight.razor](../../../samples/EventSupport/SyntaxHighlight.razor) | `16bf52954ed8bc0bff367e5a4cee00d34f4ce17cc6af73a1046666c73b1f93f1` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/CapturingMessageHandler.cs](../../../samples/GuidedTour/CapturingMessageHandler.cs) | `0c52e669baed3db42c7137797ac2e6bc911a18c2920407a1d86bb9acd20828d4` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/CodeSnippets.cs](../../../samples/GuidedTour/CodeSnippets.cs) | `fe58058e32be54eefc7a3d2683967a5f2dc22f75ed398f1a3930adb18413e34c` | 45 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/_Imports.razor](../../../samples/GuidedTour/Components/_Imports.razor) | `16cd64e686040450ea07f16924071266759762f1b75fba3daa9a877e0a5b525e` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/App.razor](../../../samples/GuidedTour/Components/App.razor) | `848293d6fb5463468a75591d228c60beb0b52c8c187d2fa9882d393d77f4b143` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/EntityHighlighter.cs](../../../samples/GuidedTour/Components/EntityHighlighter.cs) | `44dbe8b987a09db2021e280d3156ac5fb1b59a30854adc611f3f153d509ab829` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Pages/Catalog.razor](../../../samples/GuidedTour/Components/Pages/Catalog.razor) | `65b0bb92f51dfe8281e34ca650e433ff07a367f9c83104dae715ede505f16f22` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Pages/Documents.razor](../../../samples/GuidedTour/Components/Pages/Documents.razor) | `a6f42a694a27106615ceb68f4dc40aa7397a0b76de092bc456a6316f1441921d` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Pages/Events.razor](../../../samples/GuidedTour/Components/Pages/Events.razor) | `b43c4c6a14a5ff70dcb6388699deb591a8aa527f70a596b963ff467a63e76fda` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Pages/Home.razor](../../../samples/GuidedTour/Components/Pages/Home.razor) | `29fec65b88bc4d6a1a5874466caf1acea5a75407b7a932d32388b5761fd27038` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Pages/Tour.razor](../../../samples/GuidedTour/Components/Pages/Tour.razor) | `6ea78d842deaad652416b9ed5a294e89a7e5798e2524e4333ffcf475d62af758` | 85 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Pages/WalletProtocol.razor](../../../samples/GuidedTour/Components/Pages/WalletProtocol.razor) | `a0be8cd9ac8a448d07348b433eada06bd820d5ed47fb47100d9eba7d3e7e5585` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/PayloadInspector.razor](../../../samples/GuidedTour/Components/PayloadInspector.razor) | `c8491535ed91ad7179d4cc94a86d15508958262a121dc526b80ee5f5ae840ca3` | 5 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/Routes.razor](../../../samples/GuidedTour/Components/Routes.razor) | `80766f20fb8e8e3e09e281d2679bbeb6129eb3056e5086f66380dbcdacc78e33` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/SequenceDiagram.razor](../../../samples/GuidedTour/Components/SequenceDiagram.razor) | `4cf2a89400d5c634b45039a319d8cab18c08eb57e4d82a12bd8339bc9f42b700` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/StepList.razor](../../../samples/GuidedTour/Components/StepList.razor) | `285749e182252337b9d9b4ec67d21976a23e6f3de4ec607beb8790888654b66c` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/TokenView.razor](../../../samples/GuidedTour/Components/TokenView.razor) | `8368f2a33c1f65c6ceecc6945ab689a13a59dc26bfcf8ffc6bc2754d88e4f1ac` | 4 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Components/TourFlowSelect.razor](../../../samples/GuidedTour/Components/TourFlowSelect.razor) | `a3e26f060e3df1faf974fd3f61134b8f1cf65fed7d49177f28cff7b11b585815` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/actor-bar-visual.spec.ts](../../../samples/GuidedTour/playwright-tests/actor-bar-visual.spec.ts) | `35d1b48e2796ffaa3ce433179742365b877314123330503fd4d98690a765c4a1` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/autonomous.spec.ts](../../../samples/GuidedTour/playwright-tests/autonomous.spec.ts) | `abf25674cc2a55319c78b245ee79580b3c10b717a05dfca03885eae02d97b9fd` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/bootstrap.spec.ts](../../../samples/GuidedTour/playwright-tests/bootstrap.spec.ts) | `f2d43ca1e8fca415049ff08d0c0c834bc75aaf7dee7954e0d0edbd438964fc09` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/call-chain.spec.ts](../../../samples/GuidedTour/playwright-tests/call-chain.spec.ts) | `1499e64a4e33c58a3045e5a9a78776901c1ad691c453f6e982e7d38454de0435` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/catalog.spec.ts](../../../samples/GuidedTour/playwright-tests/catalog.spec.ts) | `e343a33e79f651e99d24a3bde266bb74cb05973b5461ef8f3ffdf53ba4e17c01` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/deferred.spec.ts](../../../samples/GuidedTour/playwright-tests/deferred.spec.ts) | `60ffe78eee07a2fc51a268528d848107e4ecd62f8f63790066c99d11ebf3e678` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/documents.spec.ts](../../../samples/GuidedTour/playwright-tests/documents.spec.ts) | `7d88591ad8133a6863fe83a6d4499f5a14e92c440d071b038e501b56d98e4c09` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/events.spec.ts](../../../samples/GuidedTour/playwright-tests/events.spec.ts) | `9a4c869dd386ef9032a2f1547e017a75fb7aec3460510afaa934889db25108c0` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/federated.spec.ts](../../../samples/GuidedTour/playwright-tests/federated.spec.ts) | `d283f10c956a1cafd8f3b06f3e172f6d6f0512f5238592e5d12f4c580f59564a` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/home.spec.ts](../../../samples/GuidedTour/playwright-tests/home.spec.ts) | `1daa94ade48970f9f8cac870642e0025f3af224589426f8bfb35300f1b27eb10` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/identity.spec.ts](../../../samples/GuidedTour/playwright-tests/identity.spec.ts) | `e534a5330a4b31d4f5bdf60629960513a215091ecb52c22fa77e77825fddfae0` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/mission-call-chain.spec.ts](../../../samples/GuidedTour/playwright-tests/mission-call-chain.spec.ts) | `48d04ea61be0cfb050fd7775bcc4da90b1f57e0cdc29ecd8571142aec7937200` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/mission.spec.ts](../../../samples/GuidedTour/playwright-tests/mission.spec.ts) | `67f57ec866c8b340a371321859e4ff1a05a59b4254894ed05453f0af577b278e` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/picker.spec.ts](../../../samples/GuidedTour/playwright-tests/picker.spec.ts) | `e4e62e3620c1408b67552088898698a1e46b2d05695c204cba4ceb0cfbff9d54` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/reset.spec.ts](../../../samples/GuidedTour/playwright-tests/reset.spec.ts) | `9748b9e15efe49ef9cf96e285962852d2915676f77ce948b9355c5456aba2492` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/resource-managed.spec.ts](../../../samples/GuidedTour/playwright-tests/resource-managed.spec.ts) | `fd5736d9031f07e78df884b1da7ca950d0fc849d8894fbf6c9ca29a725d6cbf8` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/richrequests.spec.ts](../../../samples/GuidedTour/playwright-tests/richrequests.spec.ts) | `64706e27e204bc23dd3ca6c6940e1e26e92c7e8c1787160ab186a814bab2d82d` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/smoke.spec.ts](../../../samples/GuidedTour/playwright-tests/smoke.spec.ts) | `54f5fd40ac010fc12ddf379c8e2711a73c600155a5189909248da6ea53e7226f` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/sub-agent.spec.ts](../../../samples/GuidedTour/playwright-tests/sub-agent.spec.ts) | `a0d60cfa892676f836761bc1ead48127e6e7a2de6f1e97f2d9a115835df6fd06` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/playwright-tests/wallet-protocol.spec.ts](../../../samples/GuidedTour/playwright-tests/wallet-protocol.spec.ts) | `8a89bf060af96e2fd7063d15a129b60ee57cbb9f3c5d1634d492873f6a3cc7b6` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/Program.cs](../../../samples/GuidedTour/Program.cs) | `c6070778727f3033b0b4fc6bc17a78d131c57eb927b63d9c14ed070e5ff5ae49` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/README.md](../../../samples/GuidedTour/README.md) | `936dcb891a6678f4045158fafb59673f722e29706a336f4e2cd2062f4795bba1` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/StepRecord.cs](../../../samples/GuidedTour/StepRecord.cs) | `1528521c5b98f1bd9168120dceab7bb18c766069b1a2f01eabf1e8a833c9e801` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/TourOptions.cs](../../../samples/GuidedTour/TourOptions.cs) | `f9b75a75ae8d00f4a716993fcbd49d2171dca47ae75aa95e0e34b0bc891182a3` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/TourSession.Capabilities.cs](../../../samples/GuidedTour/TourSession.Capabilities.cs) | `b202680ef4974f8b65b228584fc952b5a5ca1b9f74c710dfdfa11f1a590ed43c` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/GuidedTour/TourSession.cs](../../../samples/GuidedTour/TourSession.cs) | `7cff25645341f824367a98d240e5dbda83e4d2ef7c9387b48004a3d84d44f34d` | 8 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MissionAgent/README.md](../../../samples/MissionAgent/README.md) | `ac36366a6e7bd5b910fd655365ee10bcf76f45845fb08c08198236045ab18105` | 9 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockAccessServers/Federated/README.md](../../../samples/MockAccessServers/Federated/README.md) | `042a3de9471d495c2875ff34f061cd92f0e99c786348e022de004b257780e0cd` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockAccessServers/README.md](../../../samples/MockAccessServers/README.md) | `08b43bfc4efb0efb68d38b8c130dbb0c76a353735dc7e95193cb0d3e39220b67` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockAgentProvider/README.md](../../../samples/MockAgentProvider/README.md) | `2d2cd4debdb23d67bf76f206b0d32d90cc6b4e8c1ce3428bb1269b81cb51606d` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockPersonServer/README.md](../../../samples/MockPersonServer/README.md) | `b91c9c0c8870a6275666d7e494dea0a6695da8f8c38df562c6de5a1efe15b1c4` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Bookings/README.md](../../../samples/MockResourceServers/Bookings/README.md) | `8eaabf7d07e2495767d314907fd90cbf753addb874f756e79a257a877576f0f9` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Calendar/README.md](../../../samples/MockResourceServers/Calendar/README.md) | `406cf46eb6fa630a12d2b6dec9fc8ef4c00c57f3175c41b33c5c0c88f5485bcb` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Catalog/README.md](../../../samples/MockResourceServers/Catalog/README.md) | `b266c6531293b07b37ed652d6830c508dcff629c692da4089a538018126e7f9d` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Documents/README.md](../../../samples/MockResourceServers/Documents/README.md) | `d350af9b418ef168c945a76dcafcdd84610d09cacce7b6a9c7c3aa116f37f6ee` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Inbox/README.md](../../../samples/MockResourceServers/Inbox/README.md) | `a07af2ea6326622bc6b57ab46075d31738e2c1bc977d8f059b8e69d6a65f2893` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Profile/README.md](../../../samples/MockResourceServers/Profile/README.md) | `7f557fa60b22c87701128caeeabfec4da1a37ce0b7249441fd35bfa0e21c3511` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/README.md](../../../samples/MockResourceServers/README.md) | `384560afe7b5ac16ae5377e86084865d1d20103adc5905b3c53af9d8ac2d4ce0` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Trips/README.md](../../../samples/MockResourceServers/Trips/README.md) | `cfc34f623eef77ec41c54959f1f7c13f251c0679e5956f7b4e620e457c800666` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/MockResourceServers/Wallet/README.md](../../../samples/MockResourceServers/Wallet/README.md) | `211b19afe98ef47d20c0a61de690db2ec4b1fe722e6d3ac3e4e4bdeb5d1f948d` | 2 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/README.md](../../../samples/README.md) | `1bd1e1a46c3ac04072a577197afd1e687f9d0a50cef7f09c016b6e6748e3ae0b` | 25 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/_Imports.razor](../../../samples/SampleApp/Components/_Imports.razor) | `b7b03c630e075d1c783acff669ceb9e9de268daf31740a988a4f5945f477c030` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/App.razor](../../../samples/SampleApp/Components/App.razor) | `e28bc9f11a4329d2689a64520db6550c34aaf9c042c478ef46b88398fe6e707a` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/ConsentProgress.razor](../../../samples/SampleApp/Components/ConsentProgress.razor) | `7b525cdb5ea92267e0b5ea5d8ff1196694e203ff18459338f8f86f0952143ff4` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Layout/MainLayout.razor](../../../samples/SampleApp/Components/Layout/MainLayout.razor) | `9612f8b0086834d92cd7d8e4765febd14baf89f5b7aa8f2661fcd1b380296439` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Layout/NavMenu.razor](../../../samples/SampleApp/Components/Layout/NavMenu.razor) | `6d6cd8f53e0c1a6d77068839c27423538e1a6609f96bab3828fe293dabda57d4` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Layout/ReconnectModal.razor](../../../samples/SampleApp/Components/Layout/ReconnectModal.razor) | `e1c8308c1ec6656c8f5cd50df3f1879b614e43109ad6b1e23ab26d6f1007c6db` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Bookings.razor](../../../samples/SampleApp/Components/Pages/Bookings.razor) | `8e29aa02e8774f4cf3ded5ff7013c45c7cd3cd66fff60ce48ef1451bbb4fdd4b` | 17 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/CallChain.razor](../../../samples/SampleApp/Components/Pages/CallChain.razor) | `9d8156b747f90f35014807a4b8951ed2142c9dbacc541d243a1324707b476c9f` | 13 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Catalog.razor](../../../samples/SampleApp/Components/Pages/Catalog.razor) | `df6f9ce0cd9882f8a6b37c06317144ed358243c60a3e3eec2965bfe79c0c6ebb` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Deferred.razor](../../../samples/SampleApp/Components/Pages/Deferred.razor) | `4885c622e8985d2149f00b45adf5fbc52cbcaa16451d2e2ce89bda96d6950825` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Documents.razor](../../../samples/SampleApp/Components/Pages/Documents.razor) | `da426700ace55e9931a0af23c3be4771847ce9146ffe993f99689d5fd2df373f` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Error.razor](../../../samples/SampleApp/Components/Pages/Error.razor) | `e77473780e53f2ba6d42105b745d3eca7cdbdaec1d407bc46a8ce9338b43eb29` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Events.razor](../../../samples/SampleApp/Components/Pages/Events.razor) | `de61f8c0eab3b9d0030f66d697c27ee853f3b1fffdde4cbfe759197e66eb9a3b` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Federated.razor](../../../samples/SampleApp/Components/Pages/Federated.razor) | `ee76157edfeae03e3b13aaee8b4021d36d252f465c900a59b716f9fa2a7fa42b` | 15 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Home.razor](../../../samples/SampleApp/Components/Pages/Home.razor) | `511f70ec90da2751132c29bf19e0fbba515ba636dabd5ae8bff5409923b9462c` | 27 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Hwk.razor](../../../samples/SampleApp/Components/Pages/Hwk.razor) | `8479bafb9a943f3367652b3829b0c5a19cc329d6c3ea2030783d3b038a2bddc9` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Inbox.razor](../../../samples/SampleApp/Components/Pages/Inbox.razor) | `a5537f5e98a6f55e5620f471cf29a7ff36214cddd732535525365d8223490697` | 7 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/JktJwt.razor](../../../samples/SampleApp/Components/Pages/JktJwt.razor) | `a085b5981e9db7ad5cf97d9899ffa64d9351ce52afd231e2aee364db5042f8d7` | 11 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/JwksUri.razor](../../../samples/SampleApp/Components/Pages/JwksUri.razor) | `28d0f5c7e8157fe0a4133c9a0cbea8c891dc5c8c362792eff50a876ddd9501bb` | 5 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Jwt.razor](../../../samples/SampleApp/Components/Pages/Jwt.razor) | `bb1b6aad3488e942727f44fd3ebbec8f002d379f0f36ad3b92e18c8cbe916d05` | 6 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/Mission.razor](../../../samples/SampleApp/Components/Pages/Mission.razor) | `bb8eb60cc0526f9bc247e9e356ed063474a68bebc9a25ee1616cac95af2cd4a7` | 13 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor) | `687a5a57110af596e375e7ae38b48912a5f29401522f20461ec8cce7c5ab284b` | 11 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/NotFound.razor](../../../samples/SampleApp/Components/Pages/NotFound.razor) | `c267b98a248a516f8ca8c79dd8410d9f09d9ad302466e65c6b9b959b5ffc7cbd` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/SubAgent.razor](../../../samples/SampleApp/Components/Pages/SubAgent.razor) | `e603b3206fe31f7dceb29f5563b636cbc37b8fab6caa7670099a59c971db512d` | 13 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Pages/WalletProtocol.razor](../../../samples/SampleApp/Components/Pages/WalletProtocol.razor) | `9f6337cbcf5380b14bc8788eb24c8e819c5a5a403fce98d4c63671441f044e77` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Components/Routes.razor](../../../samples/SampleApp/Components/Routes.razor) | `d8ad5bf563c9a858dc9d74bddb4a437f4347cd1cfce5fc81147d324668100c4e` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/EnrollmentService.cs](../../../samples/SampleApp/EnrollmentService.cs) | `e9f47ea1e4977088309d0a0aebe193c8f3552d56a79181249418b7b029463882` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/bookings.spec.ts](../../../samples/SampleApp/playwright-tests/bookings.spec.ts) | `a0637f3d7f3cf1e43f4e89ec5c1a217e22ea9016b7f0e5c7157d1edbe02800f2` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/call-chain-deferred.spec.ts](../../../samples/SampleApp/playwright-tests/call-chain-deferred.spec.ts) | `278010dcb4ffbff1ce74453897e461d45dbbc11d14cae1b6719b60f1a60ec6d9` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/call-chain.spec.ts](../../../samples/SampleApp/playwright-tests/call-chain.spec.ts) | `7a03beb14180eb82947e33b0303b0e4919a7f84efc6f10b394ce4adb775f90ae` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/catalog.spec.ts](../../../samples/SampleApp/playwright-tests/catalog.spec.ts) | `a8aa5cbfe3fe167a71d37a9f3b999fdc3d57b993e5f99ddb10669942372dadb6` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/deferred.spec.ts](../../../samples/SampleApp/playwright-tests/deferred.spec.ts) | `1aa5e535a6e784805b3891f4a9241ad9b2b16e0fa7c02436125c75bded116e3b` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/documents.spec.ts](../../../samples/SampleApp/playwright-tests/documents.spec.ts) | `18ac07458d76047bae73270f6e2d3f3a7b5b8d0d9784eaa834c6fd00035ed2cc` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/events.spec.ts](../../../samples/SampleApp/playwright-tests/events.spec.ts) | `a0eece5b0bcb3d5820d7af9916b634f88fc4111ff5e9d147a9639b50f400d04b` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/federated-deferred.spec.ts](../../../samples/SampleApp/playwright-tests/federated-deferred.spec.ts) | `9dbd1f26af1c17c01bdd45e7709ac781ef14006c6a8d6a364e37e2b89c6ed3f8` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/federated.spec.ts](../../../samples/SampleApp/playwright-tests/federated.spec.ts) | `2ff963f9dbf0c2995bb0b7d287ec704d9912b83a130328498023e6e2040550d4` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/home.spec.ts](../../../samples/SampleApp/playwright-tests/home.spec.ts) | `e12c1b904452433807520bdd4dda5f4f28487e80f95fc6a5d4a94f1a96473b0f` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/hwk.spec.ts](../../../samples/SampleApp/playwright-tests/hwk.spec.ts) | `1cec5f9bc0f6b83f7bd14fbaa9700be8f5fba8b12295425061efb2f7dc817bc6` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/inbox.spec.ts](../../../samples/SampleApp/playwright-tests/inbox.spec.ts) | `4b4dff54b25a8441c2f71eb196a37796b1061929493c2408c73ba769e73346ea` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/jkt-jwt.spec.ts](../../../samples/SampleApp/playwright-tests/jkt-jwt.spec.ts) | `b33f16fa5447b2b1fa1839adf377126365db36ffbd3e2d87a51f19076f93161a` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/jwks-uri.spec.ts](../../../samples/SampleApp/playwright-tests/jwks-uri.spec.ts) | `808c40e51b76da1513745b86960c5edd6d572d6273943f7dd16b074de7f18ba7` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/jwt.spec.ts](../../../samples/SampleApp/playwright-tests/jwt.spec.ts) | `b4c5fba811531ab06056794a6f3ca69d9342a5b7df6ae38546f1fbb643360626` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/mission-call-chain.spec.ts](../../../samples/SampleApp/playwright-tests/mission-call-chain.spec.ts) | `c972615098e70e9979b8d2c91bbd26dff481bbd6581755b12a2dc2d06d09158a` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/mission.spec.ts](../../../samples/SampleApp/playwright-tests/mission.spec.ts) | `f5cbc43d37b9a44588b5dbd06c7c2672dec813a5f8bb71e678a7498062b5020a` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/sub-agent.spec.ts](../../../samples/SampleApp/playwright-tests/sub-agent.spec.ts) | `9ee8394cb9a46ea7e4061423cad188259ff36c2bba667055e14125590228bb9b` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/playwright-tests/wallet-protocol.spec.ts](../../../samples/SampleApp/playwright-tests/wallet-protocol.spec.ts) | `72feebcce6d52c060d9d837a461779cdbf05147f30d57120d49d54bacf7ffadb` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/Program.cs](../../../samples/SampleApp/Program.cs) | `3b2356ae2a3aa088c48faef723a9a29415cfb4bb79f8a63bf579d7f1a84eec03` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/README.md](../../../samples/SampleApp/README.md) | `8a7da108b20e46525c4001b6e106e0065306639f0d82b6aad2ef62bcbd00e94d` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/SampleAgents.cs](../../../samples/SampleApp/SampleAgents.cs) | `933e70e0552cc0ff946619c8b0d4130abc7542cc1303a16a3a7665356cc90f0f` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [samples/SampleApp/SelfIssuedIdentity.cs](../../../samples/SampleApp/SelfIssuedIdentity.cs) | `88edd595b97a4a0110fc3e14e640fe2b4ea3971eb345a5331b42935e2f84c558` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [src/AAuth.Events/README.md](../../../src/AAuth.Events/README.md) | `a89e7436734af4d17f904e9ea966097910bb181be2566dfd6ac052eaae4cdf18` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [src/AAuth.R3/README.md](../../../src/AAuth.R3/README.md) | `29a2660effdfcf0d2ccc1ae883051f9aa0f6f8b060ee767a759fb682580d7366` | 1 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | +| [src/AAuth/README.md](../../../src/AAuth/README.md) | `718bbdfa36ec3110ca62f25035b26e0b027d7f442c0445c8ff488e3ba835fc30` | 3 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence | + +| Source Block | Format | SHA-256 | Result | Source and Behavior Evidence | +|---|---|---|---|---| +| [docs/advanced/clarification-chat.md:fence-1](../../../docs/advanced/clarification-chat.md#L28) | csharp | `a4ed80747fcef5395f5f9cfb302f76b08708fd8bb257519412c80aff6ac5f387` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/clarification-chat.md:fence-2](../../../docs/advanced/clarification-chat.md#L45) | csharp | `3d5cbcd26619b1aeb62ae58e331a72d34d6d1f3488027a939d16ecb6e615b854` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/clarification-chat.md:fence-3](../../../docs/advanced/clarification-chat.md#L74) | csharp | `88101c0ba4e7c971b98b7567eafccbfb7bb8382add0a8d507a16565c140f605b` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/clarification-chat.md:fence-4](../../../docs/advanced/clarification-chat.md#L97) | csharp | `09245ab8937e93acd07c41116a7ea334fff2f49159c68ca5af667c020fbe502e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/clarification-chat.md:fence-5](../../../docs/advanced/clarification-chat.md#L117) | csharp | `f85cb5ce6f340363232864cf8ae5776d14a058fd2f85a9465d6e324e74939ba4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/clarification-chat.md:fence-6](../../../docs/advanced/clarification-chat.md#L151) | csharp | `0cf257cfa82c7d74333f774a676f6db651632fc19000dd49a90f213c02561867` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/clarification-chat.md:fence-7](../../../docs/advanced/clarification-chat.md#L178) | csharp | `996af329c55564613fa136c5e9c5c5ad9594397241eb5139232d00be3f6d68ae` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-1](../../../docs/advanced/error-handling.md#L15) | csharp | `0da7955b51f916e402fdad8b511d4c622819c1c363b465db5fbc17dd28823110` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-2](../../../docs/advanced/error-handling.md#L43) | csharp | `1262881969320aa29a9d1adad3e844168712b65832a3ec6a20a821fe806ef292` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-3](../../../docs/advanced/error-handling.md#L93) | http | `ccbecd7fad970b88c55c4a28c314eefed987d3f3d3664015fd07b1f64bf48ff9` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-4](../../../docs/advanced/error-handling.md#L105) | csharp | `3a6c5d82a4e62716479118a81bb5ad0ed4a74c6617c28876779dd1378d54a455` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-5](../../../docs/advanced/error-handling.md#L134) | csharp | `34641fa7133b5b9efcdb52fa47cd28a1aef8d37d2f5de70a34a8415c1259b6b5` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-6](../../../docs/advanced/error-handling.md#L180) | csharp | `841cf2031834dd4de7d47dd02d959a4b57316647e0f783cb4756f6bb46b20482` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-7](../../../docs/advanced/error-handling.md#L190) | csharp | `39bce319b6e892ab26528937c4f70f52be89dd1b5a49ccd0ef43acc5ed68109b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-8](../../../docs/advanced/error-handling.md#L216) | csharp | `501ef76775d373fd0e3255fd299f9b35aa070650476a22fd1dd52ab507aec559` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-9](../../../docs/advanced/error-handling.md#L249) | csharp | `94a7f0fb2b0814a0f756979f2d24419fb08f55fdff25175952ad69960b412120` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-10](../../../docs/advanced/error-handling.md#L266) | csharp | `eddc2fe9541aad40debf8ee09e8e63661d1aa4123777b19600a65a1e3fd4aebe` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-11](../../../docs/advanced/error-handling.md#L285) | csharp | `5a5ccd42790bf4f7b9f633db917b884021350cfdc655daa4592db49b8cc49f83` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-12](../../../docs/advanced/error-handling.md#L297) | csharp | `8906ec5cd5900725d63e1205dde7c4be5e15f077694b5a9a13cddcaa1555fba9` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-13](../../../docs/advanced/error-handling.md#L333) | csharp | `a1a073f6cdda6beb18ef1f062b2b3dd794a2f274fcd4baf1bae76d67e05a6ff0` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-14](../../../docs/advanced/error-handling.md#L344) | csharp | `59b1f1823de44da0b78dbc97c7d8301f51fd511b80aee783355ac4ebd4680281` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-15](../../../docs/advanced/error-handling.md#L371) | csharp | `1d857fef0e313b9c8ae9797157cb0cc0f7bef3fae7334d3267fd5a773d7ca9ea` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-16](../../../docs/advanced/error-handling.md#L400) | csharp | `f20b4e55cd9acef5619bdd7b500b1daf34893d76e3a18ed2dc2404127b7bbd80` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/error-handling.md:fence-17](../../../docs/advanced/error-handling.md#L412) | csharp | `69087d67b02e6bffbca2985aa9578940aa1fd60a49359e576c260b7cc71ce79b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/interaction-chaining.md:fence-1](../../../docs/advanced/interaction-chaining.md#L28) | mermaid | `3834648481beaeeb67f090a6fbc243b579153e41effc18b4a1b82d75d5674539` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/interaction-chaining.md:fence-2](../../../docs/advanced/interaction-chaining.md#L64) | csharp | `8c3eb5aedfebd7a40212875a7ced3e6c273bee9c3c3beb92d55a1ff60d8f1b32` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/interaction-chaining.md:fence-3](../../../docs/advanced/interaction-chaining.md#L119) | csharp | `1ea823e517bd34cb510a02f7a07f4ec5e8fa4e8f2fd4037cfabc31bd2301dc3d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/interaction-chaining.md:fence-4](../../../docs/advanced/interaction-chaining.md#L138) | csharp | `caa6deff7c69980217869804676714fe45b699559d9def52cb6400e40232e15e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/interaction-chaining.md:fence-5](../../../docs/advanced/interaction-chaining.md#L176) | csharp | `ce74991bce79ecccc39532cfcf3804a0896e5ce502f4feefd152547769c3f318` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/interaction-chaining.md:fence-6](../../../docs/advanced/interaction-chaining.md#L207) | csharp | `dc6a5ae381c23460fbeb8876da427a7590fe81366505c41a79fd665c3ff7760c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-1](../../../docs/advanced/key-management.md#L36) | csharp | `e9793b79d5fe459380b892beaec00598c2e90f9abf1dc1e36a726939de72eae1` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-2](../../../docs/advanced/key-management.md#L52) | csharp | `6fd5ae59073ba7176ae15702664b8a8436c545c2ebbd0778e4c53f5c9c770a83` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-3](../../../docs/advanced/key-management.md#L62) | csharp | `b0b8acd9af234ff216fee116a9388a52ba3da03bb610d050974c8d6d333aaff5` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-4](../../../docs/advanced/key-management.md#L85) | csharp | `25b46fad5d4d904f30f3969f61036abe22383373aa0cb94b7e586ae57c437f41` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-5](../../../docs/advanced/key-management.md#L108) | | `4e741cb30ff3eeea904fba1e234782666f9823610c5e7d9d5b2b550c945be62c` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-6](../../../docs/advanced/key-management.md#L131) | csharp | `9a68e5eb6f399467d8311ab25c23c159c27d20c4cf76e9c60b2eec28714f2f1a` | External template: Azure.Security.KeyVault.Secrets/Azure.Core required; exportable Ed25519 secrets, not HSM signing; syntax checked only. | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-7](../../../docs/advanced/key-management.md#L186) | csharp | `01d577b3a2d92812b9c2c4de9749f6209607beadedf467101f243c964862244d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/key-management.md:fence-8](../../../docs/advanced/key-management.md#L217) | csharp | `c6cbfb6ea03e9563e8137310d773fbe6c1de7eabdb0d10d885d12cd30d98d0d5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-1](../../../docs/advanced/mission-governance-clients.md#L33) | csharp | `efdbe174b33afb74f569257eb3d4c8d184bc9ea975fc766084feda203cf031b4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-2](../../../docs/advanced/mission-governance-clients.md#L46) | csharp | `6f3135e9e2d7ea058beec05e9530df7a7cb123190d71215d855b317337f616d9` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-3](../../../docs/advanced/mission-governance-clients.md#L62) | csharp | `271896f3c861513b66ee87780eb6c9f2a55025794240b84e03641ca0fcb2fda5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-4](../../../docs/advanced/mission-governance-clients.md#L99) | csharp | `c45de5a19044c70a10502a5f99d1abeb60354731308355d16488a1c3d05d39c6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-5](../../../docs/advanced/mission-governance-clients.md#L121) | csharp | `b1417da973f9289c33568cc86ea925de70ae438e7846c915bb92f5e871ef3a91` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-6](../../../docs/advanced/mission-governance-clients.md#L135) | csharp | `028bd539ef3847cb7f3254967acf57da1229a2b561f0ed696803e1eec9c641d9` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-7](../../../docs/advanced/mission-governance-clients.md#L150) | csharp | `2c4094ccd7dd2e0f47dd0c5ca3536a1eebe822cf60b176b2d53419e6930a3de7` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/mission-governance-clients.md:fence-8](../../../docs/advanced/mission-governance-clients.md#L179) | csharp | `1418a3bf2ae5c4b9348579678d017d88dcbef097e81d53247dc318a3c55fe250` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-1](../../../docs/advanced/missions.md#L33) | csharp | `8e373f003e1e4cf97c040f07b68b81343e697bc27c08323dfd6956180853198a` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-2](../../../docs/advanced/missions.md#L79) | csharp | `42b19367f78e6c128326f793c91f51d6fec422ab46b7a37048158bc8eed1f772` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-3](../../../docs/advanced/missions.md#L131) | csharp | `3bbac70c83af7b550b948c6568dec6d7b612881bcad96e1e1bed77681d8ea3f1` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-4](../../../docs/advanced/missions.md#L158) | csharp | `5d659639cf3b9edde32634360e24d54414ec623acab789fadb24f2cecaf22f31` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-5](../../../docs/advanced/missions.md#L189) | csharp | `033a001fc048ef531c0f7847aee177a3bc2a0e53557a2f99c6eebb576c66786b` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-6](../../../docs/advanced/missions.md#L202) | mermaid | `408ccc0ea6364dc4955f6ee954fb93ebe907b138497850466ee9fee3ebfc2b08` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/missions.md:fence-7](../../../docs/advanced/missions.md#L241) | csharp | `6225ff50be926d324d33cb765b9e4ace8575482b1f25c9e06563458c070a8227` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/observability.md:fence-1](../../../docs/advanced/observability.md#L10) | csharp | `580bf5eab70345ad556ffd28294e727760cc4b6bade60b040fd7cc7a491ac0b5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/observability.md:fence-2](../../../docs/advanced/observability.md#L20) | csharp | `3151e23b6f0031bcded6574b4f3da255f5341ca4391e780911527181a1030771` | External template: OpenTelemetry.Extensions.Hosting and Instrumentation.AspNetCore required; syntax checked, exporter not executed. | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/observability.md:fence-3](../../../docs/advanced/observability.md#L31) | csharp | `25b1b23779eaa0dcb630c16f0ea4f691c319e71d421aed46730c9be5f89b8e0a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/observability.md:fence-4](../../../docs/advanced/observability.md#L90) | csharp | `eb1a6a82740b1e2340ee0a0790a7265aed0ed14da30eb5080b1349d164a08336` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/platform-attestation.md:fence-1](../../../docs/advanced/platform-attestation.md#L14) | csharp | `5f0a5359571fd1461426619bc4d32f13764043fc5e24ee4bc8f15217c827fae1` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/platform-attestation.md:fence-2](../../../docs/advanced/platform-attestation.md#L28) | csharp | `9b313bcd8558ce1251841ebbc6c6b2c2e37b4a3a03c5f019224544b9069fc86b` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/platform-attestation.md:fence-3](../../../docs/advanced/platform-attestation.md#L45) | csharp | `1dc43d75de0eb95c1f32b908f357d85a1d9ad32bfcf60c431d70dfabee7a8158` | Illustrative platform adapter: IWebAuthnService/DeviceCheck are host placeholders; IPlatformAttestor signature checked separately; no hardware or AP challenge/retry claim. | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/platform-attestation.md:fence-4](../../../docs/advanced/platform-attestation.md#L65) | csharp | `9232f368dc3371617c75a4b84ff7f4b80b99c009bb5453b17b9f60fa62792e98` | Illustrative platform adapter: IWebAuthnService/DeviceCheck are host placeholders; IPlatformAttestor signature checked separately; no hardware or AP challenge/retry claim. | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/advanced/platform-attestation.md:fence-5](../../../docs/advanced/platform-attestation.md#L87) | csharp | `2d5f0b4c92a5fe1c59331dce06dace510e5ca73a4a49b73403ba109f6be1cd8e` | Illustrative platform adapter: IWebAuthnService/DeviceCheck are host placeholders; IPlatformAttestor signature checked separately; no hardware or AP challenge/retry claim. | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-1](../../../docs/getting-started.md#L11) | bash | `ef50764cc25e3e18dd0b4c55c31a13f834f879894febe875678dac6074841afa` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-2](../../../docs/getting-started.md#L24) | bash | `0cc8bf77419b3cf5842a01e5350d865905b39fbe124a4b0fc90be9e8e4336218` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-3](../../../docs/getting-started.md#L30) | bash | `e50a89f02b3bad70993b022f4c22f61a62dbe565d12e9bdc6b486b7583a2ea2c` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-4](../../../docs/getting-started.md#L36) | csharp | `fdd60869af1dfb8ab381603e337611198f55a2506ad74889aebebed5316140bb` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-5](../../../docs/getting-started.md#L50) | csharp | `e39ae84ba1b8c3819aef5926b5d5ebd84a1e8fc6cf02948b611202ad115bd63d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-6](../../../docs/getting-started.md#L70) | csharp | `0ea3e6805ef7a90688ffc97b13131d560d567f310360c431021125756b9bcd9a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-7](../../../docs/getting-started.md#L76) | csharp | `457daeef0b57b066e2a4eaa1e3c0593dae145db2f9bf4cdf014985c378d92a5b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-8](../../../docs/getting-started.md#L165) | mermaid | `9a1bd9203bd3a1a01c9087640f1e37649f806dc3cf7eb3b60237dd632aa57db6` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-9](../../../docs/getting-started.md#L201) | | `eb01c7967541362e3afb1cecff31a8713c18e716466e0234012e6611606576fa` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-10](../../../docs/getting-started.md#L215) | http | `79074879ad574184b262707663665a9d0833439451e15240bbc27cfeea393b5f` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-11](../../../docs/getting-started.md#L227) | http | `943e17a5d370f752fe13193e0e1a10d257325a59a22304a0184e48a11ccacc37` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-12](../../../docs/getting-started.md#L243) | http | `796510cd83737405961d312e837821dfd82d88a473e829c801086b827f74b68e` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-13](../../../docs/getting-started.md#L261) | http | `48d6fb39e4dc579ef29f14e50612784f39408696587c2e23011298b2eb5b75d0` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-14](../../../docs/getting-started.md#L277) | http | `496840f7b3eaba0a801f19c0047323393f54b21ab6d7f748f7a38f021c5b1c44` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-15](../../../docs/getting-started.md#L301) | http | `23ca9c47c8570f1943880cf9c43c7b2892f8b84d958595cdaf1cc18630080885` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-16](../../../docs/getting-started.md#L316) | http | `03a1e0f628907ed30af88b5b66c2a9e615756d8ac29c39c78e0e5292b7d050c1` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-17](../../../docs/getting-started.md#L346) | | `cd698a34a22c0b50bcb6803b9f9ed6b74ee8c3950951156c11904c9718e68b11` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-18](../../../docs/getting-started.md#L374) | csharp | `7b0b9eaef2ee6971d279243925df0273c1cd0e92270b3473508d5b543c2e8abe` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-19](../../../docs/getting-started.md#L409) | csharp | `53de0a4a41d8c30f4d4c322ad14824146d58808a0ce405b4170908346b07ad47` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-20](../../../docs/getting-started.md#L462) | csharp | `dfa4ddd9f5f82dc68acfa979bffd00b7e7cf30b1089e11496ad2c97ffb183572` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-21](../../../docs/getting-started.md#L499) | csharp | `c7e55b35db9cc239045a5b55c3a6ba5da77a3293007945e7db7cbc5edfa733f2` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-22](../../../docs/getting-started.md#L523) | csharp | `a3578b058c85b34ae5d793bbe166b6d3d28645d0c28b2bc55b88fb987e3dbfd4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-23](../../../docs/getting-started.md#L550) | csharp | `842dfef2e85d1763e1042a9e57be29e8782732e70cc0854bc919efc70de631d2` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-24](../../../docs/getting-started.md#L567) | csharp | `3d5788b2c78f5b0c3185a807f45cf2b16719d32047639719e2781f5b5cc77849` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-25](../../../docs/getting-started.md#L589) | csharp | `3e472b560545dca1df07338fb1f26d953846633f898e4ff6d3b962ec09e0e7b6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-26](../../../docs/getting-started.md#L599) | csharp | `83299b5e1a81413e1fb64034d4014ed4bb1e6253c6357322d97dee95bdc0494f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/getting-started.md:fence-27](../../../docs/getting-started.md#L612) | csharp | `27e3bc8f8bd2ce3431b48a1d1680ccf323334d65e0521312cdaff3ffe2b6a729` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/configuration.md:fence-1](../../../docs/reference/configuration.md#L842) | csharp | `8c2e2e7562ff9d197d7a388fd79cd4561a8cd85e0238f27b667c267a6a5ff09d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/configuration.md:fence-2](../../../docs/reference/configuration.md#L869) | csharp | `63204663adc8e435dab41296a8802ea77df9054c8f0e0f882e804b078fe8c6e6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/configuration.md:fence-3](../../../docs/reference/configuration.md#L894) | csharp | `af7db519e5583c3878cf69a855a53a47b8aa1f585bfe1c500ec9f6b6afe6fd21` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-1](../../../docs/reference/dependency-injection.md#L14) | mermaid | `f3ff1562c325b2828ab666d1bef3ecc0f23ee629569ab79f3797278f29325f16` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-2](../../../docs/reference/dependency-injection.md#L46) | csharp | `84f096cee89ba9fe59620db3f3d4f8d8d8467db43f559b4da46b78fb4e62599c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-3](../../../docs/reference/dependency-injection.md#L64) | csharp | `c1f19fd0777ce3714c99ca8bebf42d7655739ea7fc3b7e889df6ebdbc84b1f5b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-4](../../../docs/reference/dependency-injection.md#L92) | csharp | `341dec6667019d76359c1cddc1bef821d28de60a857e8c8b97c34230dfbc8a99` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-5](../../../docs/reference/dependency-injection.md#L111) | csharp | `c8e87de8ad278daefc0a1585a4ac2897757a1825cabd0d38fb967fbad634e795` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-6](../../../docs/reference/dependency-injection.md#L126) | csharp | `78ade4b2692330baabd28388141d95a5ab89aade3d183bcca380dfc54fe55126` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-7](../../../docs/reference/dependency-injection.md#L155) | csharp | `e1a1ec111486e3bcc083d28422a7a1827cb2fa8ab21a77413cb4bfb9897f9dbb` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-8](../../../docs/reference/dependency-injection.md#L172) | csharp | `3dd7d184007724509dc3e3da0f189988e0f47c503b9fd59ef2b3946ade896b4e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-9](../../../docs/reference/dependency-injection.md#L177) | json | `e0e52f9d808b8b3dfb2e5607a9ef1328adb9a0a3b1969bdc8e944cf72d672bad` | JSON parsed; displayed identifiers/claims are illustrative | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-10](../../../docs/reference/dependency-injection.md#L211) | csharp | `b7e37e547193a573c5f366dd882d44f98b7cbd65205ad0ae2922dc3872912929` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-11](../../../docs/reference/dependency-injection.md#L227) | csharp | `0b92941ad98f06f698a9ffae39532c12941293708f288b7eba1eece009ed7998` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-12](../../../docs/reference/dependency-injection.md#L251) | csharp | `1cb1dbf4085bb56ef2d7983b7dd9005e1224e9afb1c887b0efa8e82c820440e7` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-13](../../../docs/reference/dependency-injection.md#L287) | csharp | `c4f1d3b698fdfc0cc22983a873836946e0df9f3c4caf72d85a8185aff5d06964` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-14](../../../docs/reference/dependency-injection.md#L309) | csharp | `198b6467ce8bcac52f8b8e719ab21ec65ebb0b11a3163a9f4522d5fad45fc73f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-15](../../../docs/reference/dependency-injection.md#L332) | csharp | `0561d313df71a5e6ba6fb1ad5ced26a754eaec2fc6aabb5bc766bd06bac9782e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-16](../../../docs/reference/dependency-injection.md#L362) | csharp | `dd6961c7c02d11eb158877fc28438f3788f50c3976913ff05bd99f149f292bfb` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-17](../../../docs/reference/dependency-injection.md#L402) | csharp | `7679f84ae0484423e6390b189bc90d7446c697bcc12a9c29c2bc944dacca3bf0` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-18](../../../docs/reference/dependency-injection.md#L425) | csharp | `8d8c6f46dfb63a1e4f9319b2460520998d11e16d02e386562aa0af36e5791ea5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-19](../../../docs/reference/dependency-injection.md#L464) | csharp | `4237002abb226ad9343117b3050b10ba5da05235b796048390a01e55a0ef030d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-20](../../../docs/reference/dependency-injection.md#L491) | csharp | `b82171ff02e50768c603fc302e82982b649166d165cde07d00234e3b2f3ff477` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-21](../../../docs/reference/dependency-injection.md#L522) | csharp | `52c614d1f0229a1aefb6e611ee41f03f966b7d3b0fc60c1e91483267638257fa` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-22](../../../docs/reference/dependency-injection.md#L543) | csharp | `20795dbc040193610fb7b534015e930810356c7600d0a890b532cd146515c0f2` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-23](../../../docs/reference/dependency-injection.md#L717) | csharp | `96ba19a19570f52f6c4aacef087ea698418df8cfd4c12ea3acfe64c16abe18f0` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-24](../../../docs/reference/dependency-injection.md#L758) | csharp | `f0228c6d33fc93503ec7f7e5cb5411bedef13ac4235085ab3a0705fbac2ade67` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-25](../../../docs/reference/dependency-injection.md#L775) | csharp | `36332bd1f0cb2b64c873f3fa4fcdcc10a9525dee3af912e4d298384193de2d62` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-26](../../../docs/reference/dependency-injection.md#L800) | csharp | `ec41bcb8faccf47f73ad64a763c4feeaca99f8392c9e0ce9c418b541ff7c87a0` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-27](../../../docs/reference/dependency-injection.md#L813) | csharp | `9b61e69cc0fc8753d11df420a0ae2df048a01cd71ddf91cdf2305b3b9cfd0b4d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-28](../../../docs/reference/dependency-injection.md#L840) | csharp | `7e8f72401530bc52c472a3252e3c02edafddc9289e8dfc5bd39dbfc5d826a00b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-29](../../../docs/reference/dependency-injection.md#L860) | csharp | `0e2540c58700a37bbaa7bba57d9852237ab55259f43453a714df57cc6ec1ccd6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-30](../../../docs/reference/dependency-injection.md#L928) | csharp | `609312cff9032e9bd02aa4b30cd7614492721563fe670aec01c6ccf5341675ef` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-31](../../../docs/reference/dependency-injection.md#L970) | csharp | `85834fc5b64d943f346000ea2dd43b3dc99c018e287eb2e2979aa56f572133e1` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-32](../../../docs/reference/dependency-injection.md#L979) | json | `0549b02e682a9ab5f5e89e80a6a222878ad6422480bdcb81eb6e4c05dd94fc08` | JSON parsed; displayed identifiers/claims are illustrative | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-33](../../../docs/reference/dependency-injection.md#L1004) | csharp | `f354d9e21dfcdf186f496a9a9ff8c739d57238e2525e9678abb02241aac5a465` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/reference/dependency-injection.md:fence-34](../../../docs/reference/dependency-injection.md#L1031) | csharp | `2ee230ec8e1a5b778b83c9420662917818b73e370059b76401f163c6afce45c6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-1](../../../docs/server/authn-authz.md#L34) | mermaid | `d197919ce3abea990d4f9c2ca62e5650d7ea77d0e878be657f0a1ca2d0241bab` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-2](../../../docs/server/authn-authz.md#L57) | csharp | `5472a8be5ce3bb0e492ff871f76c53ca662acc6b66a2075170a02e88ccd8569e` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-3](../../../docs/server/authn-authz.md#L103) | csharp | `eb6fcaf141e4f97505db349dea6c2c0113db2b1ea167f7009646392f1a48c8c5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-4](../../../docs/server/authn-authz.md#L128) | csharp | `d1fa9ca98be2df94a2308aceac3d8098ca549cc24f232d9bb3aea88aa78e0eca` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-5](../../../docs/server/authn-authz.md#L177) | csharp | `0cd89e3ac03857a431eb81cc291f4b9b1d1b1c0e8d838e519e54ffb05bf685e4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-6](../../../docs/server/authn-authz.md#L191) | csharp | `3e091f95700925d1f0e3c1053aa7967a96eab7e403ff1f803af1e2d9402e0530` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-7](../../../docs/server/authn-authz.md#L227) | csharp | `591e07eb234b1154a5130aa3ca111af3e492b3cf6a233be66ecf063d8345f512` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-8](../../../docs/server/authn-authz.md#L259) | csharp | `54842442ab19383c32a3f9f0763f4fc4a1af8f3b9799a370b1f8ec7be2e52ac4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authn-authz.md:fence-9](../../../docs/server/authn-authz.md#L266) | csharp | `219d3274d5f0f2a3d01ce75584efe09b8eb4b6b1ab4ca806c54f82589f14316b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authorization-policies.md:fence-1](../../../docs/server/authorization-policies.md#L11) | csharp | `7663a483fc0213bff88f5f3e7fc7839d2c5d09f3deb588b05ee5b6e301cd7a9d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authorization-policies.md:fence-2](../../../docs/server/authorization-policies.md#L31) | csharp | `638fab5b8fedda1ee1e0153d94b0483ba3e02a26f1ac019db46930c860c81ca7` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authorization-policies.md:fence-3](../../../docs/server/authorization-policies.md#L60) | csharp | `a1f44e6cd873f214de2fa964908a5d2547c3489c869deb059da16d06b0cd8204` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authorization-policies.md:fence-4](../../../docs/server/authorization-policies.md#L92) | csharp | `e9803d626789b8d500301dea49ee10028d17304ce4e2263e71ec1e025408b280` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authorization-policies.md:fence-5](../../../docs/server/authorization-policies.md#L156) | csharp | `5472a8be5ce3bb0e492ff871f76c53ca662acc6b66a2075170a02e88ccd8569e` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/authorization-policies.md:fence-6](../../../docs/server/authorization-policies.md#L171) | csharp | `a9a040d2a0a4d1a4fc0243322d78fe318bccdebd65e305eae07484cc26e576cd` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-1](../../../docs/server/challenge-middleware.md#L16) | csharp | `e68960d72e2d88027fa369bc0d3a5f6cc8a60d411344e8d42371fc03f20c5a47` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-2](../../../docs/server/challenge-middleware.md#L30) | csharp | `a672cffcb03fbcbfc7cb8fde9a36217708a9f6c843c4232bff8a9bbff2b1d786` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-3](../../../docs/server/challenge-middleware.md#L87) | csharp | `aa8c00b570dd823b59761c2ac4df6519340bb3337b8c03fd441fa075863ddffc` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-4](../../../docs/server/challenge-middleware.md#L128) | csharp | `85f2ff6e1be09c6ec8082d718e601ed35a8c48b333ad8e4a40a85aab51cf2107` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-5](../../../docs/server/challenge-middleware.md#L149) | csharp | `de3d520d967fed854a6ba51122a156c018a1e597c7e352beb9140c1bba67ff4d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-6](../../../docs/server/challenge-middleware.md#L171) | csharp | `da1d0b52dc6f4dd67914b929707ad9ec13e7041a273e91b70c94f510c68ca9c8` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-7](../../../docs/server/challenge-middleware.md#L207) | csharp | `1fffd89f1d03d7fd8194f015b83aff2a4cc51a6933202e060ec10dcc08710824` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/challenge-middleware.md:fence-8](../../../docs/server/challenge-middleware.md#L241) | csharp | `c9c1196d9370633095573bcec028931eec041512f20a862154bb6c4e837ce588` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-1](../../../docs/server/mission-governance.md#L33) | csharp | `19bd2109cbb13bb579bc6eb78bc83fd7ff346c66aca14e6d570cbc4bb5fb050a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-2](../../../docs/server/mission-governance.md#L50) | csharp | `a97d18d8a094ac7df090cb7e5e5a185c45d5be1104b0c4c418004caa13c4c0c4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-3](../../../docs/server/mission-governance.md#L79) | csharp | `a8404246de3f1e7822cc33ef206f7512eafcca57fd8531c9327cdc86d5aea309` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-4](../../../docs/server/mission-governance.md#L90) | csharp | `0dd502d4dcff96e5dc8fc970b1be5d72dc70c7d03ee4d5b3c16652849a45e916` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-5](../../../docs/server/mission-governance.md#L113) | csharp | `99aa685c946a67cd2bf8f889d0cc4593181a3aa1ee6949b8e3436c41484cd90e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-6](../../../docs/server/mission-governance.md#L171) | csharp | `2ced1b6524b176e5f4c72331b1f7da1b86abd548365522ccded2b1fa0e4b5ee8` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-7](../../../docs/server/mission-governance.md#L220) | csharp | `ff61a4f014c19d671805c98c29d468c08b85b0c2b3c05f386d844ddb5544458d` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-8](../../../docs/server/mission-governance.md#L243) | csharp | `06d6aed8c72e0cfd6bc641610c71c7280ba8548cbfe3ce7f9810af1e98fe5e42` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-9](../../../docs/server/mission-governance.md#L275) | csharp | `105b916146711aced92d7d80074212c2b7537948bed94bd7c106df8c0279b7c6` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-10](../../../docs/server/mission-governance.md#L295) | csharp | `4a38c76ee367ab8e097684082127e198773a57bfc5b61469230144c7775a70f8` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-11](../../../docs/server/mission-governance.md#L338) | csharp | `85f820564ddcc3f19409284be46ee79463093e684a3031bf92f4c46d51376cf6` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/mission-governance.md:fence-12](../../../docs/server/mission-governance.md#L368) | csharp | `77c02cb01ca3646d32f3b0e1df0618b4a7c14c77149c0ccb654a147f5f35df20` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/multi-scheme-verification.md:fence-1](../../../docs/server/multi-scheme-verification.md#L14) | csharp | `d47326c8f583921a5a758bb70cbaba643890fe4e3b7827e5a37cf8e77b18e694` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/multi-scheme-verification.md:fence-2](../../../docs/server/multi-scheme-verification.md#L40) | csharp | `799e3239e247f8bd21b34e346c9a65653fc065ee280bea168a753a27aaac23a5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/multi-scheme-verification.md:fence-3](../../../docs/server/multi-scheme-verification.md#L56) | csharp | `8ea2a3f1b867980cc9fff7f4083ef131bbfb94997be4faca791d096ae5a8246d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/multi-scheme-verification.md:fence-4](../../../docs/server/multi-scheme-verification.md#L91) | csharp | `2fd963cca92d08fe87336a9fa576385627b4d13833f41cd2efe25109f66d364d` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/multi-scheme-verification.md:fence-5](../../../docs/server/multi-scheme-verification.md#L112) | csharp | `7988c76d587db53e9754b9b9d05ca8d8bd26c7279353e332bfc08049778ce471` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/multi-scheme-verification.md:fence-6](../../../docs/server/multi-scheme-verification.md#L149) | csharp | `5e3ba2110e896250941db72a0628d360f15168554b96d61cfaedd35a5281675a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-1](../../../docs/server/replay-detection.md#L29) | csharp | `bcf41a71ded36b20fea73c7f00c54fec47892762fce10775639d7adcafca1ba0` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-2](../../../docs/server/replay-detection.md#L75) | csharp | `09fc840faab6a4f6c6d86016024907f0fc9a0c084f2da2f296932de402854ae3` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-3](../../../docs/server/replay-detection.md#L89) | csharp | `2eae1d7ccfa3ba21366c8958bec052401e1e0d57f8352842eea7f2ac14ad2a0e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-4](../../../docs/server/replay-detection.md#L127) | csharp | `bae6a0c46814f4301388675000f91c1758b009edd3007ce019914f3075cbb4ed` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-5](../../../docs/server/replay-detection.md#L143) | http | `abdebc1dd2adf480c54ee184c06429301d845216a232edf872955f8a292d49a9` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-6](../../../docs/server/replay-detection.md#L166) | http | `d1100c533be61c546e801269d4ebbb04ed249f1cf3dd1ac4316d47a0e5dde039` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-7](../../../docs/server/replay-detection.md#L186) | csharp | `715508afb86f52de1fe059838f5d5a5c88ce4e47626722fed94d47c8af63766c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-8](../../../docs/server/replay-detection.md#L208) | csharp | `acd75d0a104f6a44c31d00bdbb0fff141201721b3633abcfcf8835923e5f9675` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/replay-detection.md:fence-9](../../../docs/server/replay-detection.md#L269) | csharp | `f8c630d5b8f07945a94f78e616a59529e9679cf20af80c508de200f808293d7f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/resource-metadata.md:fence-1](../../../docs/server/resource-metadata.md#L11) | csharp | `b74987e1b9562d30ee1aac6ed9efe8086c4ea3ea3792ca3cc14b30db6a1ef1b6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/resource-metadata.md:fence-2](../../../docs/server/resource-metadata.md#L39) | csharp | `baac923140413804b9ab0207d73f4ebd097ab94922239203f1b9a35a6d6e4f8b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/resource-metadata.md:fence-3](../../../docs/server/resource-metadata.md#L102) | json | `9fdd0af20a2802254242f88d95b635822fca5e4fac4ea61813861a4254268e63` | JSON parsed; displayed identifiers/claims are illustrative | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/resource-metadata.md:fence-4](../../../docs/server/resource-metadata.md#L136) | csharp | `286a4f0f82b594d89f9f203a706a1df50a2c78bebd5b419c572f16ac5cb34065` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-1](../../../docs/server/token-issuance.md#L32) | csharp | `2afec6a65228885f70b3975a04bd402870f054a326e58add1b8cd672ef6f296e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-2](../../../docs/server/token-issuance.md#L47) | csharp | `d85cdcdfd7778d4b0e2d031f39665e82edc85a7c2b3be7baa654801bcf89e36b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-3](../../../docs/server/token-issuance.md#L103) | csharp | `69779ce358cf37f0018c88542fd1c00a6dd6b7f4618ec07d28fff8ead66e50ec` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-4](../../../docs/server/token-issuance.md#L123) | csharp | `8248d050bf5fa379bc24fd3071a7eb614a8cd05d88982095eadfbecb0f2d6265` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-5](../../../docs/server/token-issuance.md#L196) | csharp | `64a76f617b1a61a7d6f805cca548d7281b75007c36b1b2cc7687a0044fea445d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-6](../../../docs/server/token-issuance.md#L212) | csharp | `58cb1d6df1ea973408e7a6ff98c6a27bb6a85db2ad4b9008f4f71d52318f6fe4` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-7](../../../docs/server/token-issuance.md#L229) | csharp | `ae5aae41c209ce641bf7a061697c1cf0ad53aed4363c0b7b85137a2177748881` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-8](../../../docs/server/token-issuance.md#L267) | csharp | `ae6e114401da6e719c9e0045ad58787dd075b66e735e843b7feba0cf63c22f93` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-9](../../../docs/server/token-issuance.md#L288) | csharp | `85e1933040f2080547a35a8928be87f443eb40ce3de9393a38163bd1a6ba300c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-10](../../../docs/server/token-issuance.md#L333) | csharp | `2b5dc280772dc606bfaed7fb5558a436205f2528d9049ef5c7fed7a47127de05` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-11](../../../docs/server/token-issuance.md#L383) | csharp | `13053e414786295023479e82e54acc36e6b14743b30150ad5e9b8cfb11b124ab` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-12](../../../docs/server/token-issuance.md#L456) | csharp | `f9993e59c9e46eadb1304b38b7510e9399e60c2676f435769496be0c2fe3262a` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/token-issuance.md:fence-13](../../../docs/server/token-issuance.md#L500) | csharp | `ddf9f2c84fc614ffb585470d89848da172f86400ebd7d8966651379fdb7dbc4f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/verification-middleware.md:fence-1](../../../docs/server/verification-middleware.md#L17) | csharp | `3728ed51ad1f3a222d16625c58920f39163d8a79fd37c7580b318c4d43e60a9a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/verification-middleware.md:fence-2](../../../docs/server/verification-middleware.md#L54) | csharp | `a49c1071cdbed65c5509dfef537e66c6d4fa8ff2076a7dd7e2a23608a180d3d7` | API excerpt: source member/type/sealed checks; not executable | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/verification-middleware.md:fence-3](../../../docs/server/verification-middleware.md#L118) | csharp | `d4a92db85ce602e5d19314595589029f91109ac81f61e980238fbec4eeb1cdb5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/verification-middleware.md:fence-4](../../../docs/server/verification-middleware.md#L160) | csharp | `a7bcca5a34fa1938d534765033c11ab525f31b097a08fd4d127d29d9bbddb91a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/verification-middleware.md:fence-5](../../../docs/server/verification-middleware.md#L190) | csharp | `9bd92b509b7f8466eb7fed64fbe99204a520c3115146e97e53980f769dd5ae3b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/server/verification-middleware.md:fence-6](../../../docs/server/verification-middleware.md#L245) | csharp | `3037f733a93c015dcc11328a0ba8638c928bfcd8a96c6ee73cd64589b36c80d6` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-identity-jwks-uri.md:fence-1](../../../docs/signing-modes/agent-identity-jwks-uri.md#L22) | csharp | `b308f836d1fe6f6a25ea3f0113306456b31c0c6abe55f4187c11c7c602ff7289` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-identity-jwks-uri.md:fence-2](../../../docs/signing-modes/agent-identity-jwks-uri.md#L39) | csharp | `b6366bf919b5fd3cc21722061239ad1173cbff6e167cc605f2d063f78b846bc7` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-identity-jwks-uri.md:fence-3](../../../docs/signing-modes/agent-identity-jwks-uri.md#L60) | csharp | `b9c803845e5283b67cb01d4d3524408a990c1dc6672e357910977a12213b39ad` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-identity-jwks-uri.md:fence-4](../../../docs/signing-modes/agent-identity-jwks-uri.md#L85) | csharp | `abf057745fe363090532bc47768818aab2bdaff66b83278b8867e056dfc64d59` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-token-jwt.md:fence-1](../../../docs/signing-modes/agent-token-jwt.md#L24) | csharp | `c10eb026f7c8df657a6bfc2a458e7e401d496357bcd27c091320a2d55cbe4314` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-token-jwt.md:fence-2](../../../docs/signing-modes/agent-token-jwt.md#L46) | csharp | `728c22ab8da0e7523bfe37fd32f7bb3d7b796ada3f7dee4bbb0bfe8f7e3425ec` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-token-jwt.md:fence-3](../../../docs/signing-modes/agent-token-jwt.md#L68) | csharp | `3dbaf7b7f5375054d5406f64fa3dd6c03554a44e7039fe30fcdea1720a583e3c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/agent-token-jwt.md:fence-4](../../../docs/signing-modes/agent-token-jwt.md#L89) | csharp | `17101ce39f4ff4888e183f96e17a8e852df6ce560ae7b9e62fa7f5e9167e5c81` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/key-rotation-jkt-jwt.md:fence-1](../../../docs/signing-modes/key-rotation-jkt-jwt.md#L43) | csharp | `01d577b3a2d92812b9c2c4de9749f6209607beadedf467101f243c964862244d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/key-rotation-jkt-jwt.md:fence-2](../../../docs/signing-modes/key-rotation-jkt-jwt.md#L64) | csharp | `dd129dddb2d94604aaeb7ec05993685d33b9242e2dd1ef3d51b022381e2fe142` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/key-rotation-jkt-jwt.md:fence-3](../../../docs/signing-modes/key-rotation-jkt-jwt.md#L85) | csharp | `04327cca8366e276fd1337dbcb79fcf47819481b276f52df4b36700f5955c98b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/key-rotation-jkt-jwt.md:fence-4](../../../docs/signing-modes/key-rotation-jkt-jwt.md#L100) | text | `16a09af4ae9cb0eea1e74ecf411de5e7a22ff9600f0327b2ebb59b12e52ad43d` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/overview.md:fence-1](../../../docs/signing-modes/overview.md#L54) | csharp | `179e6ae8b6bce76ecc625f3c1732bb75f178fb11792201908a13efcd48b42bad` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/overview.md:fence-2](../../../docs/signing-modes/overview.md#L80) | csharp | `1d769c370aa814e2932d3de390a798c042ed238109c47593b006f2b0791e53cc` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/overview.md:fence-3](../../../docs/signing-modes/overview.md#L144) | | `c51bb14941dfd2a974e72632c58335e69b75b8f7612c11645caa6015050ab34f` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/overview.md:fence-4](../../../docs/signing-modes/overview.md#L176) | csharp | `08355b2f712a866dbd50ba1e95900117d717d6ac1a7fcda33e0217e5cc0f7a50` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/pseudonymous-hwk.md:fence-1](../../../docs/signing-modes/pseudonymous-hwk.md#L18) | csharp | `80e97e819c897b4eb2baf4919deea3d7d9f41d1df50a48ef27029c875ea5a487` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/signing-modes/pseudonymous-hwk.md:fence-2](../../../docs/signing-modes/pseudonymous-hwk.md#L34) | csharp | `6180f36672020803592c51fe80cc39688a1184f384f09831c6b67401fe8f6d80` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-1](../../../docs/workflows/bootstrap-enrollment.md#L14) | mermaid | `8fb4b02275077260579d2028c2cda955a4fe48bdb8f45bb5e95e1b7b19ee2990` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-2](../../../docs/workflows/bootstrap-enrollment.md#L44) | mermaid | `7142634eed351a62e930ee0485ed027fce72b482014c378ed77fc25a5ca3bf07` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-3](../../../docs/workflows/bootstrap-enrollment.md#L69) | csharp | `38008f85054b932a20cc36b398dd11f20f8bb3a2bb1615a63af2270b04153d4f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-4](../../../docs/workflows/bootstrap-enrollment.md#L96) | csharp | `54499e9034430e599dd493f6c52bea0f2d28c8c2e398bdecb7dab6ee70f31cac` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-5](../../../docs/workflows/bootstrap-enrollment.md#L119) | csharp | `5208ecc5a173baab18e0a0d4ffd6582d011b2b77e31f02c7b5683162cb24d871` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-6](../../../docs/workflows/bootstrap-enrollment.md#L182) | mermaid | `95dfdccdd8cda2b23fcfefc9af509cdbe2eb62bf680bb01d44e49ffe25f42241` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-7](../../../docs/workflows/bootstrap-enrollment.md#L192) | csharp | `22b03aa23061769b68bae6209ccd5f258d4065492e454f5b88a79a0949582c8b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-8](../../../docs/workflows/bootstrap-enrollment.md#L210) | mermaid | `fc8f19771e35b4161d35675af383be5516ca2bb2be5e3623f8ed735a653bbbef` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-9](../../../docs/workflows/bootstrap-enrollment.md#L224) | csharp | `7928feaaa791cb35ad327ec776bf8d470d765f34fbee67fa352b70ae77a060e0` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-10](../../../docs/workflows/bootstrap-enrollment.md#L244) | csharp | `3f213f776a663b92ef688d0503ba8cf46cd4f9a5ab59155cbc45587b5f9c2f1a` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-11](../../../docs/workflows/bootstrap-enrollment.md#L273) | mermaid | `3fe7545f5cd256a4702adac9235d14b20209444fcef6f729fab593f851153b2e` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-12](../../../docs/workflows/bootstrap-enrollment.md#L288) | mermaid | `3e0e987681d6988fedd5040fd0097b24becfbaf40b5b9554818d4caac13b8364` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/bootstrap-enrollment.md:fence-13](../../../docs/workflows/bootstrap-enrollment.md#L313) | csharp | `3e4b4fd76315e664050db12f58b3a7077fca7debe8ab150ac056280e3f5b7b26` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-1](../../../docs/workflows/call-chaining.md#L11) | mermaid | `21941aa682df062523996e525c0786bdaf42c85c90b13149285888dcd44ef444` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-2](../../../docs/workflows/call-chaining.md#L58) | bash | `f826b23722d400413cdbf16e7703e572d9e318bd1554c6e09394ab98ef3568da` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-3](../../../docs/workflows/call-chaining.md#L72) | csharp | `8307a3c5f32a578e8f1ae733bf0d24bd1e26e2996bc999ac772ad9eb25ea3c6e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-4](../../../docs/workflows/call-chaining.md#L106) | csharp | `8ab8874b7867ded4fe03f13f2e52c199d27931a66e8be3d4630c3288a8f83a9c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-5](../../../docs/workflows/call-chaining.md#L147) | csharp | `f23bb6ef0d5d231cf3367891e21166ee47d882b8407df7f414c51b0ac9021664` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-6](../../../docs/workflows/call-chaining.md#L197) | csharp | `38afbc7c432079021ef070ea021709c13cc1fb18af96f3616890d3035c75bf5d` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-7](../../../docs/workflows/call-chaining.md#L214) | csharp | `f52fb5be2c96d78148064c595b62f2c5f1e33358cddee9950ad3c8baead62ab0` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-8](../../../docs/workflows/call-chaining.md#L245) | csharp | `5a1004efde56f4b4bd582acbb9c791695e2a7b68e05a06424127878bf27d7830` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-9](../../../docs/workflows/call-chaining.md#L268) | json | `d2000275cef2cb3f874f046d72b6ae1f2e6b1c5969be4200277c1cf57ccb44ea` | JSON parsed; displayed identifiers/claims are illustrative | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-10](../../../docs/workflows/call-chaining.md#L283) | csharp | `2c6bdef05c55da2226972582700f89b8fb025067727cb5b1416f0e2bdfede533` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-11](../../../docs/workflows/call-chaining.md#L304) | bash | `584c7ab06338eba6c7c88794909d17a2f2dbc4fca04948a7eb4a17c45f5c5b1d` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-12](../../../docs/workflows/call-chaining.md#L312) | bash | `35620666721b67e7a7edbce46bfc3b8451b13f68f922020b71826907b6890d95` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-13](../../../docs/workflows/call-chaining.md#L336) | csharp | `7c9633bdfee513e0cdeea7531550937d780732c875209af5fd02c568f47d3b83` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/call-chaining.md:fence-14](../../../docs/workflows/call-chaining.md#L387) | csharp | `92d695d50666ca53491f029fe04428c8f10f46713315a0361657ca70c55cb62c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/catalog-gateway.md:fence-1](../../../docs/workflows/catalog-gateway.md#L34) | mermaid | `367fcb5803b1bbcd08d973b2d25567d165ad725961c4a99d45fe8529be5bdf0a` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [docs/workflows/deferred-consent.md:fence-1](../../../docs/workflows/deferred-consent.md#L7) | mermaid | `facef28cce19d0488885dfdbad9bb2740c257e19a58c435313cd0ea27338f235` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/deferred-consent.md:fence-2](../../../docs/workflows/deferred-consent.md#L35) | http | `8dc00c28314748acf8f17c808a49e1eb44a414fd9926c7f6ebd54bef770d3149` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/deferred-consent.md:fence-3](../../../docs/workflows/deferred-consent.md#L43) | csharp | `9185411a0ff93c09cd8c3a01713786a37e06e7d838008f8ad59c620f3ca8ea18` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/deferred-consent.md:fence-4](../../../docs/workflows/deferred-consent.md#L87) | csharp | `86e9b5204062fa7eb4a1b7990be5dfc23b7229589847614d5dc3a5860f6d03ac` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/deferred-consent.md:fence-5](../../../docs/workflows/deferred-consent.md#L116) | csharp | `063c73c0a0a821deda6b8639d9df09fd1a485f25165f065f22092f814a10198f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/deferred-consent.md:fence-6](../../../docs/workflows/deferred-consent.md#L138) | csharp | `c624bc304e7f322d7cfef00b96931dc2a0688e7d3ef3cdd5d6c2e61e503f8c06` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/deferred-consent.md:fence-7](../../../docs/workflows/deferred-consent.md#L158) | csharp | `3dc790ffa4a55afd73987c32be1b7d4efa855a25523f59970c0c505059ab2f5f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/events.md:fence-1](../../../docs/workflows/events.md#L36) | csharp | `f8ee06c47af075ac9f7a8eed6c8c4a06658f4049de3767c974d9b9513c265328` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [docs/workflows/federated-access.md:fence-1](../../../docs/workflows/federated-access.md#L7) | mermaid | `75c9b92b3d256139677058f9a03cbb553ba097a48c636351f9c6f92bb0f65d03` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-2](../../../docs/workflows/federated-access.md#L31) | csharp | `a430f214b52bdef6f5d2d25fdd17fcbe6754c0e3e3dd23560e4fa392b6f6c2ba` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-3](../../../docs/workflows/federated-access.md#L54) | csharp | `fdafe33d68c847023e6f1763f736035b333a71e0500efde44bfaebf3baf0b02e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-4](../../../docs/workflows/federated-access.md#L86) | csharp | `e00466a78b27c36162492d47f704fa9aff7ea6c8f6f31b5a79fad2a42953bd75` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-5](../../../docs/workflows/federated-access.md#L121) | csharp | `dd95cb3913da9710eeb7935e495e5bffabe479d025b6bb92da9b88b2a1b45520` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-6](../../../docs/workflows/federated-access.md#L197) | mermaid | `155b8c6c4e0df3ca7477bf166b1be6b89b44b2c1a8490df99385c161c1f31064` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-7](../../../docs/workflows/federated-access.md#L248) | csharp | `cd38c0e99c53ffe84190dd666b504dbf69d44f7f9250536ae9b85b75b49b9801` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-8](../../../docs/workflows/federated-access.md#L285) | csharp | `47d27b26548a074f1c539e3d490388cd72814abe7a24cd6d63718615f3ff11d1` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-9](../../../docs/workflows/federated-access.md#L317) | http | `22aec37b68e452690f11ee6d60cf25ce0063c8169fffd25be48ffa46479d0aee` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/federated-access.md:fence-10](../../../docs/workflows/federated-access.md#L335) | csharp | `d0c279fbc2700f9d9468ab5253de70adc1afdc7bd3d3c3149725c2ea590b381f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/identity-based-access.md:fence-1](../../../docs/workflows/identity-based-access.md#L11) | mermaid | `05705880d5a1938205c0a95e3241250182cf0102c13c3b66bd9715d351e16984` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/identity-based-access.md:fence-2](../../../docs/workflows/identity-based-access.md#L27) | csharp | `b7347af7fa4d88284f1da087b9960f252ae9c246d2ae11395f63b4c944784986` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/identity-based-access.md:fence-3](../../../docs/workflows/identity-based-access.md#L45) | csharp | `1677d4a34da1385bc723d166277e91448b495349c8e148713b673a3a39715f35` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/identity-based-access.md:fence-4](../../../docs/workflows/identity-based-access.md#L55) | csharp | `9860b42e6febfed67b1253cc4ebfc311a9b0dca243ef3dabddfe75de9ecbbcc9` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/identity-based-access.md:fence-5](../../../docs/workflows/identity-based-access.md#L71) | csharp | `72e50cf2fe707311bb8427ee63c59835526636de1119d6d72aff2a683ed4dedf` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/mission-governed-access.md:fence-1](../../../docs/workflows/mission-governed-access.md#L24) | mermaid | `0e078f0f518499ce18619fd4ae9893d44a2b647426756855d4e1c05f501374e2` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/mission-governed-access.md:fence-2](../../../docs/workflows/mission-governed-access.md#L56) | csharp | `23c1049e9c9015053481a7e9ec77f311809af5c3c62dee01ad82913df7253696` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/mission-governed-access.md:fence-3](../../../docs/workflows/mission-governed-access.md#L80) | csharp | `8a49e2770e3bd185cf0c02280a88c7ab1b933f33a2aa5a8ae53bfd4d59167283` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/mission-governed-access.md:fence-4](../../../docs/workflows/mission-governed-access.md#L105) | csharp | `e9bbc09ff3262b214ea68cbeae056c26db455c1da75808b800e961da3af6d91f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/mission-governed-access.md:fence-5](../../../docs/workflows/mission-governed-access.md#L125) | csharp | `028bd539ef3847cb7f3254967acf57da1229a2b561f0ed696803e1eec9c641d9` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/mission-governed-access.md:fence-6](../../../docs/workflows/mission-governed-access.md#L138) | csharp | `2ad504c204f703dc94c79261fecb7b28df99e162bd38dcd18c414851efa6293e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/ps-asserted-access.md:fence-1](../../../docs/workflows/ps-asserted-access.md#L16) | mermaid | `db9b9ad5955ea57432064ced62ae97bf9b242dfb74831e167dfcba05bf7e9b77` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/ps-asserted-access.md:fence-2](../../../docs/workflows/ps-asserted-access.md#L37) | csharp | `144fa53e6340f40a95dcf1d93b3986e15a6d947cfeaf977a2d60fe5981132049` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/ps-asserted-access.md:fence-3](../../../docs/workflows/ps-asserted-access.md#L63) | csharp | `d6cd0f5518385b5fa0262d252fd2d5b7697e3b81000b6d20598c67e376810885` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/ps-asserted-access.md:fence-4](../../../docs/workflows/ps-asserted-access.md#L90) | csharp | `763868a684ff734431d382b531111534c79ac806b00c184a6cf2020f5e600fd8` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/ps-asserted-access.md:fence-5](../../../docs/workflows/ps-asserted-access.md#L130) | csharp | `007204ac1041f904d85d2015693115701574285c9617f58f41acdf17ef795667` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/resource-managed-access.md:fence-1](../../../docs/workflows/resource-managed-access.md#L34) | mermaid | `76d468e3ba98dc36bd0639d22dd280fa2dfebfbaa18de73f3ab6359b99d298c9` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/resource-managed-access.md:fence-2](../../../docs/workflows/resource-managed-access.md#L56) | csharp | `7f0ec7a69205f1e716983aeaf4f9e52d393b42db0a3fa73d515c6ec980f978b5` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/resource-managed-access.md:fence-3](../../../docs/workflows/resource-managed-access.md#L98) | csharp | `64ec36e83d909461d39bb8acfdb8a4dbf25d115bcd32e46d767420c8cd02267e` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/resource-managed-access.md:fence-4](../../../docs/workflows/resource-managed-access.md#L119) | csharp | `987273c606821e20fff6f796d60462663109227ccf232e9adb988cf6ea3c206c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/resource-managed-access.md:fence-5](../../../docs/workflows/resource-managed-access.md#L156) | csharp | `f3b86f57cd6edf98200db21ab9c1f0bfa57bc5d342dbd4733070017f0df8fe73` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/resource-managed-access.md:fence-6](../../../docs/workflows/resource-managed-access.md#L174) | csharp | `aaa524d98d13bf9baf413231bc8d1f405927765f00af1ecd176aa449c3e4ef50` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/rich-resource-requests.md:fence-1](../../../docs/workflows/rich-resource-requests.md#L15) | mermaid | `6ded5eeff662e5a954f2477648b0573a7b99030dbaccf879112378c8bd05d37a` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/rich-resource-requests.md:fence-2](../../../docs/workflows/rich-resource-requests.md#L109) | csharp | `929c79d26f922d89b5c7a02d5d92dcb1f3e05b5720877077d77b39ca62e57e83` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/rich-resource-requests.md:fence-3](../../../docs/workflows/rich-resource-requests.md#L162) | csharp | `6278e2b96ef1684ce602105347913ba10ff00316c8e74752f3b3e911d43eb10b` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/rich-resource-requests.md:fence-4](../../../docs/workflows/rich-resource-requests.md#L207) | bash | `5816e2b6cfa2efce01d8b78f1ca2d84a83a16ee8faf044f01f941977d846e722` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [docs/workflows/wallet-protocol.md:fence-1](../../../docs/workflows/wallet-protocol.md#L40) | mermaid | `afc0768e14c398227659f3ef07df2f95b7caae17bd98458a99d160190eedbcb4` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [docs/workflows/wallet-protocol.md:fence-2](../../../docs/workflows/wallet-protocol.md#L84) | mermaid | `f7ce8e505e74c9bacecda5517a29e911cd46224c8daa4ead815da094276313b1` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [docs/workflows/wallet-protocol.md:fence-3](../../../docs/workflows/wallet-protocol.md#L131) | mermaid | `da5e6ae785bf060d41dcb49e66840d22093e76da8d199946ad013c17bbe6f553` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [README.md:fence-1](../../../README.md#L54) | bash | `ef50764cc25e3e18dd0b4c55c31a13f834f879894febe875678dac6074841afa` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-2](../../../README.md#L88) | bash | `cf73836166aa56ef6ccc87b2f6e6fdb73f959c9b7c34b4a0b29e1063f00e1775` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-3](../../../README.md#L94) | bash | `0cc8bf77419b3cf5842a01e5350d865905b39fbe124a4b0fc90be9e8e4336218` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-4](../../../README.md#L106) | csharp | `bac6e655a77d637c9087c68c5c7cb823821acb0c1f1df96c5c1d29ddfb4ca8d2` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-5](../../../README.md#L132) | mermaid | `ec4debac90db3f06f392c1bbf17f149a96f405fb60e033d7c2896f8d48fab67c` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-6](../../../README.md#L155) | csharp | `03fc179bb24c5831d3f889d646db4ae4c5166c997a660e1b39459359402a7b94` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-7](../../../README.md#L201) | csharp | `d64d8d1b86cff9c5d7c4b8eb276b80f02e774492d04f1c2387e43bc7d7e0709c` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-8](../../../README.md#L239) | csharp | `52359eedcd1c620c2e48efce61fcbc54ea6ceb03e3ec610c882ae49e40417d61` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-9](../../../README.md#L254) | csharp | `3a08c889801aad072136008295575e90391eace51459c0cf8432e440a3fec6c3` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [README.md:fence-10](../../../README.md#L301) | bash | `be9b05c3b3e1ca81497243c1dd96e2bdecc5e5d6dbea5feecf5ed021abe834a0` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/AgentConsole/README.md:fence-1](../../../samples/AgentConsole/README.md#L21) | bash | `da6dcde217b6c8f0a2407ed7d9108862f287daee9657046af43413a46152c472` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/AgentConsole/README.md:fence-2](../../../samples/AgentConsole/README.md#L60) | bash | `d05e133ab359ba8ab93d947b4612eae422d4efb66d48d006d9a8630ecba7c533` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/AgentConsole/README.md:fence-3](../../../samples/AgentConsole/README.md#L106) | bash | `eaf7d044a746e16e1235bdde143fc734a158006b49ff1625372406396c57dbd1` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:pre-1](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L61) | dynamic | `f6681b8cd4bf54cf386ff594c5b078bad752d3962ddaa6f7a7ba49c5783c4108` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:pre-2](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L66) | dynamic | `4c53b6a936934792c2af6215e2db6b9e045011808ac175948963fbddaf0ce6a5` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:pre-3](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L69) | dynamic | `633543aca320bce45c6e82b8d3aa56136e73f9de186c0a154d2361f43a6245af` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:inline-1](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L25) | inline-code | `a330395cc0a53ad1207736546afff4735940937564bbf75ce1edad40780d9139` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:inline-2](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L30) | inline-code | `7cf9f4f50bcd47161585ba8b14f346271a1a72ece2ba49649773f3ca37266335` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:inline-3](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L30) | inline-code | `156b8612eaa4b1a093bac8d53d925d5ae82f779c196390dacaafebc15a95e0db` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/CatalogWalkthrough.razor:Example-1](../../../samples/CapabilitySupport/CatalogWalkthrough.razor#L93) | csharp | `b403a6de813a33217eac75a7ffba35d4d086a4a987a170fbc5836f71b72c13b1` | Exact C# compiled with typed prior-step/host inputs | [Catalog session](../../../samples/CapabilitySupport/CatalogDemoSession.cs), [both-app Catalog wrapper](../../../tests/e2e/helpers/catalog.ts), R3VocabularyTests | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:pre-1](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L55) | dynamic | `f6681b8cd4bf54cf386ff594c5b078bad752d3962ddaa6f7a7ba49c5783c4108` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:pre-2](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L60) | dynamic | `4c53b6a936934792c2af6215e2db6b9e045011808ac175948963fbddaf0ce6a5` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:pre-3](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L67) | dynamic | `dfdfda84161e2e8725e2ce590f9aa2bf725c9c57b76fbdda94658d9495ccd100` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:EnrollExample-1](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L92) | csharp | `a617ca5c1b09b237d30560d3c5f0765861cd683f13a1a3ea03a807a59f3304d8` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:ChallengeExample-2](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L100) | csharp | `b905d5ae68ea808f63c575a7abf0a4c7f7474d42cc25e756191cbc0e2dca46f1` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:AuthorizeExample-3](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L126) | csharp | `52e7bac09dbe0e0bea7255d884f1eb915055a8b7d9d394255898234848ba0f96` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/DocumentWalkthrough.razor:DownloadExample-4](../../../samples/CapabilitySupport/DocumentWalkthrough.razor#L141) | csharp | `240c1a4bc3f3e21a3ebe7d0b269f6506594e2bfee4af57604cf86cef2d34793f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/CapabilitySupport/WalletScenarioCode.cs:Clarification-1](../../../samples/CapabilitySupport/WalletScenarioCode.cs#L12) | csharp | `638e2d66ea2bb65f7f483b274f1c0014e69f4c735641fb5f976decd5e35818fb` | Exact C# compiled with typed prior-step/host inputs | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/CapabilitySupport/WalletScenarioCode.cs:AsGrantChaining-2](../../../samples/CapabilitySupport/WalletScenarioCode.cs#L32) | csharp | `7bd0c3014055affe8a104b19847d0036a74a5d65fbfd4b64cf0bc4de0f274dfc` | Exact C# compiled with typed prior-step/host inputs | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/CapabilitySupport/WalletScenarioCode.cs:Revocation-3](../../../samples/CapabilitySupport/WalletScenarioCode.cs#L46) | csharp | `3f74deef8a7429938a594c8109f1b9780c4dafa57fc92ef64ffc23fdeb11cf84` | Exact C# compiled with typed prior-step/host inputs | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/CapabilitySupport/WalletWalkthrough.razor:pre-1](../../../samples/CapabilitySupport/WalletWalkthrough.razor#L79) | dynamic | `f6681b8cd4bf54cf386ff594c5b078bad752d3962ddaa6f7a7ba49c5783c4108` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/CapabilitySupport/WalletWalkthrough.razor:pre-2](../../../samples/CapabilitySupport/WalletWalkthrough.razor#L86) | dynamic | `4c53b6a936934792c2af6215e2db6b9e045011808ac175948963fbddaf0ce6a5` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/CapabilitySupport/WalletWalkthrough.razor:pre-3](../../../samples/CapabilitySupport/WalletWalkthrough.razor#L91) | dynamic | `d8351c60920cb4b0703b309a35758b978d7662ccf01f6f7eca10183cbf9344d1` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/Concierge/README.md:fence-1](../../../samples/Concierge/README.md#L20) | mermaid | `7c096fa280c9896c37b03a688ef43844365cde3dce0b07f83da4f81e48167f86` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/Concierge/README.md:fence-2](../../../samples/Concierge/README.md#L47) | json | `77cccae9185619b0b7b5743042b54017a62a6364298ef22f1a181fab50344459` | JSON parsed; displayed identifiers/claims are illustrative | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/Concierge/README.md:fence-3](../../../samples/Concierge/README.md#L68) | bash | `46f8207a3d5d546392406e73b274d1452d11ae3ba32335923e51aec841a493b3` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/Concierge/README.md:fence-4](../../../samples/Concierge/README.md#L74) | bash | `a9d9984ea1a54ebd2e00a96a2fbf0b35b241a95ba3daf27b5dff57cef5193177` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/Concierge/README.md:fence-5](../../../samples/Concierge/README.md#L91) | bash | `959040f0ddf0c8885eecc319426933702020aa35b7c7317eb3ca803c8322bda3` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/EventSupport/EventDemoCode.cs:Discover-1](../../../samples/EventSupport/EventDemoCode.cs#L6) | csharp | `5b258ce7cddd75784a45739428d11b903ad67a81a4382885b2886c2eb08a45c5` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventDemoCode.cs:SubscriptionUrl-2](../../../samples/EventSupport/EventDemoCode.cs#L20) | csharp | `cde3f3c7649cbcdc775940aaa1107b23c68c01ab6d6c732b878c6c6db76a1b38` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventDemoCode.cs:SubscribeToken-3](../../../samples/EventSupport/EventDemoCode.cs#L44) | csharp | `b9d46a407f0f8959746908cb93d0f2520b5189a40588b3ccbefafa162441c7bf` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventDemoCode.cs:Registration-4](../../../samples/EventSupport/EventDemoCode.cs#L60) | csharp | `c2207e6bb8015eb67fc810766c926af147f9851d764d6ff211f4e3a8376fef14` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventDemoCode.cs:Delivery-5](../../../samples/EventSupport/EventDemoCode.cs#L71) | csharp | `a1c61f248f9e1742ce7a6bba17861618919d1dd717f034059fb97fda0afd65a8` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventDemoCode.cs:Receipt-6](../../../samples/EventSupport/EventDemoCode.cs#L97) | csharp | `8464d2ce8518b0c0b2c9d217dfbfa1da635e06f94c5a1298f03bfd0f5b7bc467` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventDemoCode.cs:Example-7](../../../samples/EventSupport/EventDemoCode.cs#L119) | csharp | `9c8735d4786edb6a83ae7a397ca8d1e95829fd09cb8d383cb01544170a6cb4c8` | Exact C# compiled with typed prior-step/host inputs | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventWalkthrough.razor:pre-1](../../../samples/EventSupport/EventWalkthrough.razor#L85) | dynamic | `801c99dd70e212a2b17e7bef517927c061c6f650fbc0fc7526bd3bf70afa91ad` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventWalkthrough.razor:pre-2](../../../samples/EventSupport/EventWalkthrough.razor#L93) | dynamic | `fb55299e105f11677a32e496c23df4d92552088c9bf98a73c2d7d1226e2852b4` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventWalkthrough.razor:pre-3](../../../samples/EventSupport/EventWalkthrough.razor#L101) | dynamic | `7e478bdbf354aa600e437516377ec7b9af4a4d6db522189c3d14d5fe536f8c90` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventWalkthrough.razor:inline-1](../../../samples/EventSupport/EventWalkthrough.razor#L105) | inline-code | `863bf7c94f3f72b6c318b98a9b92f2df1af6be67a28853c0d8effa70e1d4f112` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventWalkthrough.razor:inline-2](../../../samples/EventSupport/EventWalkthrough.razor#L106) | inline-code | `5b1288bdb86ccf33cc0158da1a1f405c4095d9c00fe9dadd9c58af82ff2abae5` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/EventWalkthrough.razor:inline-3](../../../samples/EventSupport/EventWalkthrough.razor#L106) | inline-code | `5b1288bdb86ccf33cc0158da1a1f405c4095d9c00fe9dadd9c58af82ff2abae5` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/SampleAgentRegistry.cs:string-1](../../../samples/EventSupport/SampleAgentRegistry.cs#L23) | string | `e285f5757f47cd7faea567da3f3bafde6f93f10a26f6cc007cfcef4ed5ec8626` | SQL runtime literal: sample build and Events HTTP/persistence tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/SampleAgentRegistry.cs:Enrol-2](../../../samples/EventSupport/SampleAgentRegistry.cs#L42) | string | `56f5b25760b3ebe246dfcfa4a359265395bacc50074c0841692c1c4a0d30e8c5` | SQL runtime literal: sample build and Events HTTP/persistence tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/SqliteEventStore.cs:string-1](../../../samples/EventSupport/SqliteEventStore.cs#L23) | string | `5c3c2ccb3ddf3714cb03b98fa311461ff0ad3038486b366cc2a2aa524199041d` | SQL runtime literal: sample build and Events HTTP/persistence tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/EventSupport/SqliteEventStore.cs:command-2](../../../samples/EventSupport/SqliteEventStore.cs#L104) | string | `ead256ccd2524c1a0fc689ba067018a7b4b0a1cb9b2a64d3d31c433b1ab7a5a1` | SQL runtime literal: sample build and Events HTTP/persistence tests | [Event session](../../../samples/EventSupport/EventDemoSession.cs), [both-app Events wrapper](../../../tests/e2e/helpers/events.ts), EventHttpTests / EventPersistenceTests | +| [samples/GuidedTour/CodeSnippets.cs:GenerateKey-1](../../../samples/GuidedTour/CodeSnippets.cs#L9) | csharp | `21b946b214898fb08303f7addd03cd0ec1300e57e9c637a3289d4ee4115c94fd` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:SelfSignAgentToken-2](../../../samples/GuidedTour/CodeSnippets.cs#L15) | csharp | `c22678c5a0864fe6c3fd84a1afc2debdaaf9d3639c0014c0b38d995059bafeb3` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:DiscoverAp-3](../../../samples/GuidedTour/CodeSnippets.cs#L27) | csharp | `e4535d607db2cddd19acf208ac3fd8ddd42b481ce296bd5dfbb2e6fe96843b88` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:EnrolWithAp-4](../../../samples/GuidedTour/CodeSnippets.cs#L35) | csharp | `423655dcce44e5b30f92577991b1cf79687be59c14fb0a03d76338b691cb2aab` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:DiscoverResource-5](../../../samples/GuidedTour/CodeSnippets.cs#L52) | csharp | `788ac9129f217dd6a79107f10ba403ecea3d9a3a6d633bae351a1280ea00dae4` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:SignedGetHwk-6](../../../samples/GuidedTour/CodeSnippets.cs#L59) | csharp | `8a48f86d17c688ceb7567f354d106c97112bbd7b42859d8f3f9889333d3239bb` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:SignedGetJwksUri-7](../../../samples/GuidedTour/CodeSnippets.cs#L68) | csharp | `caeb3471e20f665be3e757e44224925dabf456ace5887216a15b55c7055d8188` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:SignedGetJwt-8](../../../samples/GuidedTour/CodeSnippets.cs#L81) | csharp | `ba35e32577e927ad2e98210de65810a7f4e08c3fd3b2ccb76e59facf231599bf` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:SignedGetJktJwt-9](../../../samples/GuidedTour/CodeSnippets.cs#L91) | csharp | `376af60f5ba2b8df82318b627a9274eafde62e392175e5cd7f2a828a7f13b019` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:ParseChallenge-10](../../../samples/GuidedTour/CodeSnippets.cs#L111) | csharp | `15881d90251c2c58f3a22f93c968ab754903d109a2db3bf1f754e171d7bc7899` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:DiscoverPs-11](../../../samples/GuidedTour/CodeSnippets.cs#L121) | csharp | `b3f42f484c1c49a87224b3cc598ab557049810bd290e1fc3e8303457378d6b4e` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:RequestPersonToken-12](../../../samples/GuidedTour/CodeSnippets.cs#L130) | csharp | `c998b45c87cf728fc3db57d6127261d64a36dcfc6abf6bb3bcf558a58204a3a8` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:PresentPersonToken-13](../../../samples/GuidedTour/CodeSnippets.cs#L138) | csharp | `7c23734574f8b0813d8101149db14e307722792d5a2c9164125bd48d424de229` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:TokenExchangeDirect-14](../../../samples/GuidedTour/CodeSnippets.cs#L147) | csharp | `934dff7a1ee6e547b439f168a2c16f6d4509929ac83febd3de16fa074260fb64` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:TokenExchangeDeferred-15](../../../samples/GuidedTour/CodeSnippets.cs#L162) | csharp | `62a28247f9bf92d7f284512444777ff55e7f0577af8e45eaa709aa56ae461cd0` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:DirectUserToInteraction-16](../../../samples/GuidedTour/CodeSnippets.cs#L182) | csharp | `95fc36701315dcff5b35384bc8bd9b7ff998ebd5cfa9a39fa583f5d4782b3134` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:PollPending-17](../../../samples/GuidedTour/CodeSnippets.cs#L197) | csharp | `86183d2c380d999addcc32f9e6e926c8f47b9f53ac0f5929dd6486aae5524e3d` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:ReplayWithAuthToken-18](../../../samples/GuidedTour/CodeSnippets.cs#L212) | csharp | `4c0f6df68d81abb61221e2c37e15ed0ee2e0236b4e049153552eecfe2add479b` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:R3AccountRequest-19](../../../samples/GuidedTour/CodeSnippets.cs#L221) | csharp | `e4e9698a61f941c0b7fcacd33b5362c39b76d77f4eab946e1169b96d4aaa2fb0` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:R3ConfirmPerCall-20](../../../samples/GuidedTour/CodeSnippets.cs#L233) | csharp | `8c64af70014fbc3d2174d7123bb6a13bbde10804cdc1f91b540af5add664b29a` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:ResourceManagedSignedGet-21](../../../samples/GuidedTour/CodeSnippets.cs#L273) | csharp | `ff7ad264b6da27507878ac0f431a7e0b7cf55bac284707535019f808949312b7` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:ResourceManagedPoll-22](../../../samples/GuidedTour/CodeSnippets.cs#L302) | csharp | `b0dce400615b7271f131d9778d8c87a422fa37c64ca36de5103b236f51c7fe54` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:ResourceManagedReplay-23](../../../samples/GuidedTour/CodeSnippets.cs#L316) | csharp | `c10c25d374c0171a1c3bb0c00667a29ebd241741c19fd63f7c751d4ebbc3c822` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:CallChainRetry-24](../../../samples/GuidedTour/CodeSnippets.cs#L330) | csharp | `6c952c763b474cd226f032df29c5bb35398c2cc072f61fffcee8969ed3a02a19` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:CallChainConvenience-25](../../../samples/GuidedTour/CodeSnippets.cs#L347) | csharp | `c9b36239bafc33243431e889adc67ee3e1ef3b4a749656fdafbe142f2af8d2ca` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:FullAutomatic-26](../../../samples/GuidedTour/CodeSnippets.cs#L371) | csharp | `bbe4a1c83731df429349e13ff4352249d195b407e0dc634ec82ec162c5649520` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionDiscoverPs-27](../../../samples/GuidedTour/CodeSnippets.cs#L397) | csharp | `3f34465da2cf6d3038bda4c151f7f01a50c3888291f21a501f8edf34a6957af2` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionPropose-28](../../../samples/GuidedTour/CodeSnippets.cs#L408) | csharp | `5f4feb3b02c01cf9338cb108dee6c77ef5b1788bf8073dc6d9b3e60ea299e720` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionPollCreate-29](../../../samples/GuidedTour/CodeSnippets.cs#L426) | csharp | `c3f266a06c4dd32bcc6edb24b1aa7b5076c06408a928e120ab3a64e362571f5d` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionPersonToken-30](../../../samples/GuidedTour/CodeSnippets.cs#L434) | csharp | `5fcbb8851414bc4d22fecb4e1ad5fbc5d7ac1571e7e716cdddf658398fe30a98` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionChallenge-31](../../../samples/GuidedTour/CodeSnippets.cs#L442) | csharp | `5c77f9274f00dab985b90d0a77859ee02588ff82d3e45c8bff0466bfc8384aea` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionExchange-32](../../../samples/GuidedTour/CodeSnippets.cs#L453) | csharp | `a53878a4a96fedab8c0ab79c2f0e4843cc3c483032126bc3c7932acd5d3f1934` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionReplay-33](../../../samples/GuidedTour/CodeSnippets.cs#L460) | csharp | `23f9243a5240d8be933a6e49f8453c954c0ab9b31e437cba9fcf33aea4b10bf9` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionElevatedChallenge-34](../../../samples/GuidedTour/CodeSnippets.cs#L467) | csharp | `a59e5ab4667e28335c8a1ac0a7f308112580aeb5ec13e42b7faf531ad75af79f` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionElevatedExchange-35](../../../samples/GuidedTour/CodeSnippets.cs#L478) | csharp | `e06e76e8c228c064759e2b2a410601a874abfafac89e5fdf11317b92475560d9` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionElevatedPoll-36](../../../samples/GuidedTour/CodeSnippets.cs#L486) | csharp | `d0943b292cace3708e9546a0fe28194ae94aebda9e63113de7425028e12207ad` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionElevatedReplay-37](../../../samples/GuidedTour/CodeSnippets.cs#L496) | csharp | `bfd0882c359730d8c408475e1dc63858377d161e7d112e5844aaaf2592d66449` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionPreApproved-38](../../../samples/GuidedTour/CodeSnippets.cs#L503) | csharp | `d554532907c41959dcd47c56cad5954081adac9c7e832aeb0008e084687b90c2` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionPermissionPrompt-39](../../../samples/GuidedTour/CodeSnippets.cs#L511) | csharp | `cd84784c47a1affafef70fd9c53a7b035b809833c61944175bcac24beab5eeeb` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionPollPermission-40](../../../samples/GuidedTour/CodeSnippets.cs#L519) | csharp | `a50291cf55b31f787b975a04781f08adf784330ae608476b4e8a05ca11e863e2` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionInspect-41](../../../samples/GuidedTour/CodeSnippets.cs#L528) | csharp | `dac0f90d3f97a247e7dead703e272fc493147c3071e2d443e9bb38c0db9beec2` | C# comment-only narrative: reviewed against the associated scenario; no executable statements | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionChainClarify-42](../../../samples/GuidedTour/CodeSnippets.cs#L540) | csharp | `29ef4e8546f4f35335503f29dd52b7093b6701cce1ffeddf77a50fd2d2e39e2f` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionChainAnswer-43](../../../samples/GuidedTour/CodeSnippets.cs#L557) | csharp | `6f4af29f39cac9cbcf07379e858c6e762554ed60d68f1ca8320967730817672f` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionChainForward-44](../../../samples/GuidedTour/CodeSnippets.cs#L575) | csharp | `b209e518e1f4af27ee4db5e21e526f38f788c8c8c58463392aa6ee27f5cef464` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/CodeSnippets.cs:MissionChainLog-45](../../../samples/GuidedTour/CodeSnippets.cs#L591) | csharp | `3de43cfef093fc4c63c7c0929f4dc86ac9d636107c056acb94848903e120061d` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Home.razor:inline-1](../../../samples/GuidedTour/Components/Pages/Home.razor#L42) | inline-code | `dcaadad1cfce437735b81ab025f776e5857e48558c47f6960e6a5f2595664a85` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:pre-1](../../../samples/GuidedTour/Components/Pages/Tour.razor#L118) | dynamic | `f6681b8cd4bf54cf386ff594c5b078bad752d3962ddaa6f7a7ba49c5783c4108` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-1](../../../samples/GuidedTour/Components/Pages/Tour.razor#L138) | inline-code | `84e925d67edae8780e32bf145b35353d9aa74a63c3a6cbd96e75d468e11e3996` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-2](../../../samples/GuidedTour/Components/Pages/Tour.razor#L140) | inline-code | `85a84e034c5b9248758c500f6c1f2b8bb99c9818ce7902ee5bc702c07ecda5a0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-3](../../../samples/GuidedTour/Components/Pages/Tour.razor#L155) | inline-code | `fc93cb07e1ad92898527100e58a1cf1d1e7f65e9a266a6f87f3c84feb541c7b3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-4](../../../samples/GuidedTour/Components/Pages/Tour.razor#L159) | inline-code | `c14492aa4fa622a3e58d6cc105b23e6e1ec2231cfcc905f4d86f52082a5b4bfa` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-5](../../../samples/GuidedTour/Components/Pages/Tour.razor#L162) | inline-code | `955397113a3ffe4b79dd6934ed974eb571732b022b60e3bb5207b902fe7cac41` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-6](../../../samples/GuidedTour/Components/Pages/Tour.razor#L162) | inline-code | `5a8b62d7eba85f3852843ab71ee21fd8953f7d758209640e73af66a60c744b28` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-7](../../../samples/GuidedTour/Components/Pages/Tour.razor#L162) | inline-code | `0ce6f90588bf21bd3aa8bbf29b811d4ecf1b4c20a18077a6787695ceb513796e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-8](../../../samples/GuidedTour/Components/Pages/Tour.razor#L163) | inline-code | `27badc983df1780b60c2b3fa9d3a19a00e46aac798451f0febdca52920faaddf` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-9](../../../samples/GuidedTour/Components/Pages/Tour.razor#L168) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-10](../../../samples/GuidedTour/Components/Pages/Tour.razor#L191) | inline-code | `fc93cb07e1ad92898527100e58a1cf1d1e7f65e9a266a6f87f3c84feb541c7b3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-11](../../../samples/GuidedTour/Components/Pages/Tour.razor#L195) | inline-code | `15f5cae60e1bf3d5506ee18bfdf7fa27058133366c46eac160e394adea092e95` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-12](../../../samples/GuidedTour/Components/Pages/Tour.razor#L196) | inline-code | `c17edaae86e4016a583e098582f6dbf3eccade8ef83747df9ba617ded9d31309` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-13](../../../samples/GuidedTour/Components/Pages/Tour.razor#L198) | inline-code | `0176343e4a437b2b37db94a36274da651d05b5e009cde3cb7a367b5d6feb6300` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-14](../../../samples/GuidedTour/Components/Pages/Tour.razor#L199) | inline-code | `acac590c4e2b13cb3afae05af5a41ead9867cd270976158334fa2144173ce7f4` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-15](../../../samples/GuidedTour/Components/Pages/Tour.razor#L200) | inline-code | `cbb82ebec6051b780ad26655ee48b5b42658c4ac49438888aac829e82195584f` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-16](../../../samples/GuidedTour/Components/Pages/Tour.razor#L210) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-17](../../../samples/GuidedTour/Components/Pages/Tour.razor#L213) | inline-code | `f1be11be19f0e03ab64a4ed1883802c6d3aeef0e2d229b407a595c9769aa94ef` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-18](../../../samples/GuidedTour/Components/Pages/Tour.razor#L213) | inline-code | `54e8f4ba91aebfca72fb8d9c166a43df9e44b55890456414a04c0295bd48a53b` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-19](../../../samples/GuidedTour/Components/Pages/Tour.razor#L214) | inline-code | `f56fd11d3eda52adebfa8ec502df94fdbf7218ff80c98a4bc75dfe145125e8e7` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-20](../../../samples/GuidedTour/Components/Pages/Tour.razor#L216) | inline-code | `847d2cc70f450deb2a4280c1ef0af9c041d7517c5c94216996d9fe34d7efc6fc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-21](../../../samples/GuidedTour/Components/Pages/Tour.razor#L216) | inline-code | `3acc7a4e21ee88dd49a6ca6db38d390c0f8fad073bdf3fee4d85dec81e5fd339` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-22](../../../samples/GuidedTour/Components/Pages/Tour.razor#L217) | inline-code | `27badc983df1780b60c2b3fa9d3a19a00e46aac798451f0febdca52920faaddf` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-23](../../../samples/GuidedTour/Components/Pages/Tour.razor#L217) | inline-code | `b00171bacea319da2f65495e86d96c717707642f52b7273a7b1f8536d6728904` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-24](../../../samples/GuidedTour/Components/Pages/Tour.razor#L218) | inline-code | `6527c9361a2f469c5275afcb5d06e53013367cd231995de13dc7218711388382` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-25](../../../samples/GuidedTour/Components/Pages/Tour.razor#L218) | inline-code | `ddc6e2b224d0fd821669202258386936fc9ce2899e215eec6322b95f8dd96d6a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-26](../../../samples/GuidedTour/Components/Pages/Tour.razor#L219) | inline-code | `27badc983df1780b60c2b3fa9d3a19a00e46aac798451f0febdca52920faaddf` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-27](../../../samples/GuidedTour/Components/Pages/Tour.razor#L227) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-28](../../../samples/GuidedTour/Components/Pages/Tour.razor#L229) | inline-code | `f56fd11d3eda52adebfa8ec502df94fdbf7218ff80c98a4bc75dfe145125e8e7` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-29](../../../samples/GuidedTour/Components/Pages/Tour.razor#L230) | inline-code | `847d2cc70f450deb2a4280c1ef0af9c041d7517c5c94216996d9fe34d7efc6fc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-30](../../../samples/GuidedTour/Components/Pages/Tour.razor#L231) | inline-code | `772e10a0c0a795b97d1391d2d7c4b0cb1fde19ac5027c48de6008e10dede67e3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-31](../../../samples/GuidedTour/Components/Pages/Tour.razor#L233) | inline-code | `b00171bacea319da2f65495e86d96c717707642f52b7273a7b1f8536d6728904` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-32](../../../samples/GuidedTour/Components/Pages/Tour.razor#L242) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-33](../../../samples/GuidedTour/Components/Pages/Tour.razor#L246) | inline-code | `cbdd8637f090e7de25403ed8482aae56b66be61046629696f01c8ca3d3a03d63` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-34](../../../samples/GuidedTour/Components/Pages/Tour.razor#L247) | inline-code | `6527c9361a2f469c5275afcb5d06e53013367cd231995de13dc7218711388382` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-35](../../../samples/GuidedTour/Components/Pages/Tour.razor#L248) | inline-code | `ddc6e2b224d0fd821669202258386936fc9ce2899e215eec6322b95f8dd96d6a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-36](../../../samples/GuidedTour/Components/Pages/Tour.razor#L249) | inline-code | `f83f07be16e270186d35b876916c461995ebc3af5b1798f898c33285a1847dbc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-37](../../../samples/GuidedTour/Components/Pages/Tour.razor#L261) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-38](../../../samples/GuidedTour/Components/Pages/Tour.razor#L263) | inline-code | `0926d7734e784737b4b462e2daa3c6db041ee5c01b75a7a2b3ba9463d2efc8cc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-39](../../../samples/GuidedTour/Components/Pages/Tour.razor#L265) | inline-code | `4275d71e90f7f09f9dcbba2aeeaafb3f30576780bc4d5419ff086d1c6f02a654` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-40](../../../samples/GuidedTour/Components/Pages/Tour.razor#L266) | inline-code | `3acc7a4e21ee88dd49a6ca6db38d390c0f8fad073bdf3fee4d85dec81e5fd339` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-41](../../../samples/GuidedTour/Components/Pages/Tour.razor#L267) | inline-code | `1c070c9accb1b9877eb7211654cfab9da4864d973942a4a088c992d71880b900` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-42](../../../samples/GuidedTour/Components/Pages/Tour.razor#L268) | inline-code | `1744bb6c1da2e55193e9eb4afe485e275c8cc30a2b1d1b9c100170d36fe9e520` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-43](../../../samples/GuidedTour/Components/Pages/Tour.razor#L268) | inline-code | `c68c500e222872c83bbfe1cd0ccbb6a060bb88f1c53092a46ca9d182f0071362` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-44](../../../samples/GuidedTour/Components/Pages/Tour.razor#L269) | inline-code | `6527c9361a2f469c5275afcb5d06e53013367cd231995de13dc7218711388382` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-45](../../../samples/GuidedTour/Components/Pages/Tour.razor#L269) | inline-code | `ddc6e2b224d0fd821669202258386936fc9ce2899e215eec6322b95f8dd96d6a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-46](../../../samples/GuidedTour/Components/Pages/Tour.razor#L272) | inline-code | `a6ef89c2e28ae06c35306edd800dc0258b1243653636e119527a5e6da515b605` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-47](../../../samples/GuidedTour/Components/Pages/Tour.razor#L273) | inline-code | `f55a0838018af0b222392c581b4cea6e096822c40b20aaad4b477534b29d3105` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-48](../../../samples/GuidedTour/Components/Pages/Tour.razor#L282) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-49](../../../samples/GuidedTour/Components/Pages/Tour.razor#L286) | inline-code | `2336af25ca724d260446e47a636db7453efc335df448c2a57d4c67ac9965dbbe` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-50](../../../samples/GuidedTour/Components/Pages/Tour.razor#L286) | inline-code | `1b926447cdc6ac734336c3f96612a4ebb43930848e698b46dbb925a3deadfdd0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-51](../../../samples/GuidedTour/Components/Pages/Tour.razor#L287) | inline-code | `2336af25ca724d260446e47a636db7453efc335df448c2a57d4c67ac9965dbbe` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-52](../../../samples/GuidedTour/Components/Pages/Tour.razor#L289) | inline-code | `1b926447cdc6ac734336c3f96612a4ebb43930848e698b46dbb925a3deadfdd0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-53](../../../samples/GuidedTour/Components/Pages/Tour.razor#L303) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-54](../../../samples/GuidedTour/Components/Pages/Tour.razor#L306) | inline-code | `39158e0110cbcadec00557639c5ff0adf32f6285c46c235eb259dc13c8d31b45` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-55](../../../samples/GuidedTour/Components/Pages/Tour.razor#L308) | inline-code | `fd8abb915cb6b7b4241439d7d6ee2eb1bde2e21ba93940838c879f61e44c4723` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-56](../../../samples/GuidedTour/Components/Pages/Tour.razor#L309) | inline-code | `59874580919614e8a19e5d82d568d118a39d1c77aa0deaae1aa37369d3aacdf3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-57](../../../samples/GuidedTour/Components/Pages/Tour.razor#L310) | inline-code | `362ffea7eba1c3fb91e988f6a8e6c90e6d34adc562b19a9ec247ad4872b6c2a7` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-58](../../../samples/GuidedTour/Components/Pages/Tour.razor#L312) | inline-code | `7c1709777753420426f1975bc36fbd5af8835ea2185d922da2f4f17c69385f51` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-59](../../../samples/GuidedTour/Components/Pages/Tour.razor#L321) | inline-code | `cc74afc5e8c7a8fd5f31a335420d47cad94f36907a0b45ca5a11e56d66588894` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-60](../../../samples/GuidedTour/Components/Pages/Tour.razor#L323) | inline-code | `59874580919614e8a19e5d82d568d118a39d1c77aa0deaae1aa37369d3aacdf3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-61](../../../samples/GuidedTour/Components/Pages/Tour.razor#L327) | inline-code | `39158e0110cbcadec00557639c5ff0adf32f6285c46c235eb259dc13c8d31b45` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-62](../../../samples/GuidedTour/Components/Pages/Tour.razor#L328) | inline-code | `cbdd8637f090e7de25403ed8482aae56b66be61046629696f01c8ca3d3a03d63` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-63](../../../samples/GuidedTour/Components/Pages/Tour.razor#L328) | inline-code | `cbe370481704cef068c18bdcbe262329c59824d6c87e96510a53f022e899ab04` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-64](../../../samples/GuidedTour/Components/Pages/Tour.razor#L329) | inline-code | `fd8abb915cb6b7b4241439d7d6ee2eb1bde2e21ba93940838c879f61e44c4723` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-65](../../../samples/GuidedTour/Components/Pages/Tour.razor#L345) | inline-code | `95948aaf48cdbe9be781310fec6efeeda040176c315d86bfee702bc8d3e5e45e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-66](../../../samples/GuidedTour/Components/Pages/Tour.razor#L346) | inline-code | `f56fd11d3eda52adebfa8ec502df94fdbf7218ff80c98a4bc75dfe145125e8e7` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-67](../../../samples/GuidedTour/Components/Pages/Tour.razor#L347) | inline-code | `9b573f58833b299cb4b692346359185025c5cab22f6e67526bc5b6cd7f59ca34` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-68](../../../samples/GuidedTour/Components/Pages/Tour.razor#L347) | inline-code | `ba79d78489fdedf4e02a150155d8a5e17973473e3dd143af4475d1c9a67ba2e7` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-69](../../../samples/GuidedTour/Components/Pages/Tour.razor#L348) | inline-code | `b4faf09bff5df62d00ae465b5a857212c546f28af498bb268f524646cbdf07d2` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-70](../../../samples/GuidedTour/Components/Pages/Tour.razor#L349) | inline-code | `847d2cc70f450deb2a4280c1ef0af9c041d7517c5c94216996d9fe34d7efc6fc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-71](../../../samples/GuidedTour/Components/Pages/Tour.razor#L351) | inline-code | `3acc7a4e21ee88dd49a6ca6db38d390c0f8fad073bdf3fee4d85dec81e5fd339` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-72](../../../samples/GuidedTour/Components/Pages/Tour.razor#L351) | inline-code | `9b573f58833b299cb4b692346359185025c5cab22f6e67526bc5b6cd7f59ca34` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-73](../../../samples/GuidedTour/Components/Pages/Tour.razor#L352) | inline-code | `cbdd8637f090e7de25403ed8482aae56b66be61046629696f01c8ca3d3a03d63` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-74](../../../samples/GuidedTour/Components/Pages/Tour.razor#L352) | inline-code | `b00171bacea319da2f65495e86d96c717707642f52b7273a7b1f8536d6728904` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-75](../../../samples/GuidedTour/Components/Pages/Tour.razor#L353) | inline-code | `6527c9361a2f469c5275afcb5d06e53013367cd231995de13dc7218711388382` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-76](../../../samples/GuidedTour/Components/Pages/Tour.razor#L353) | inline-code | `ddc6e2b224d0fd821669202258386936fc9ce2899e215eec6322b95f8dd96d6a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-77](../../../samples/GuidedTour/Components/Pages/Tour.razor#L367) | inline-code | `b84ae5920ec091ac9e58b853814bc0d25979b8d189393804403e75c31ded35b7` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-78](../../../samples/GuidedTour/Components/Pages/Tour.razor#L371) | inline-code | `2665cd7fb9fc39559d84e417ae8450398fdccc29029f900d9343ce6e9d0ea4c5` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-79](../../../samples/GuidedTour/Components/Pages/Tour.razor#L396) | inline-code | `b61fe81808bb554aeebb0d0885588458f59c1b90223178afd4a8fcd75ac26ce0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-80](../../../samples/GuidedTour/Components/Pages/Tour.razor#L396) | inline-code | `167d4b09d014f218c42abf5ebb397a2fc819401fe709223fbd729f1f8e9e790e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-81](../../../samples/GuidedTour/Components/Pages/Tour.razor#L407) | inline-code | `a330395cc0a53ad1207736546afff4735940937564bbf75ce1edad40780d9139` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-82](../../../samples/GuidedTour/Components/Pages/Tour.razor#L409) | inline-code | `7cf9f4f50bcd47161585ba8b14f346271a1a72ece2ba49649773f3ca37266335` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-83](../../../samples/GuidedTour/Components/Pages/Tour.razor#L410) | inline-code | `156b8612eaa4b1a093bac8d53d925d5ae82f779c196390dacaafebc15a95e0db` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/Pages/Tour.razor:inline-84](../../../samples/GuidedTour/Components/Pages/Tour.razor#L427) | inline-code | `b62fca272b30c6783890e46edbd8a46fd17b5343cd41aa68c156d33eec5b7ada` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/PayloadInspector.razor:pre-1](../../../samples/GuidedTour/Components/PayloadInspector.razor#L13) | dynamic | `93ce3c571d3be894c314890526bdcfaa4ff712bdf926c77384aefdf4f386fcb4` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/PayloadInspector.razor:pre-2](../../../samples/GuidedTour/Components/PayloadInspector.razor#L21) | dynamic | `c392fc249d5c363963d8429cc3214d264dd6683149bb15527db80c78bacd91b6` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/PayloadInspector.razor:pre-3](../../../samples/GuidedTour/Components/PayloadInspector.razor#L29) | dynamic | `9a8b8a8d428b6572da32a11966d6c8adbbeb92b83b491c00d83e9eb33d70df3b` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/PayloadInspector.razor:pre-4](../../../samples/GuidedTour/Components/PayloadInspector.razor#L37) | dynamic | `dd36f4e108d50c7908bccb7ce5ea5d538acf630f10394bcb26850931f5a14e52` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/PayloadInspector.razor:inline-1](../../../samples/GuidedTour/Components/PayloadInspector.razor#L109) | inline-code | `999e6f1c71d8fb109e79cac42809ddb374b7ce24c6aff52d6f71414fd4eef76e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/TokenView.razor:pre-1](../../../samples/GuidedTour/Components/TokenView.razor#L8) | dynamic | `b647944b0992dae104a63d5191b89d56bf8ccd1211fc0cb0159aa5d44dc22d25` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/TokenView.razor:pre-2](../../../samples/GuidedTour/Components/TokenView.razor#L16) | dynamic | `2a9cf719f0118d2ba42f093d45dd765b8b75b8c0e19578553b1d4e151706fbd6` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/TokenView.razor:pre-3](../../../samples/GuidedTour/Components/TokenView.razor#L24) | dynamic | `e211148e496440f8f241df3d0f9ac95252208e89ee216db3a968d0a8d3aa9868` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/Components/TokenView.razor:pre-4](../../../samples/GuidedTour/Components/TokenView.razor#L32) | dynamic | `a4c1637eefc9eb85bcc4a14d77b9063bc5d5820fb8d67067d71adcc0eb523f00` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/README.md:fence-1](../../../samples/GuidedTour/README.md#L79) | json | `b887277671e7f7911bc43eec0cbe331eab6dc1b9c064e9e110d10b34c0d6b89f` | JSON member fragment parsed inside an explicit object | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/README.md:fence-2](../../../samples/GuidedTour/README.md#L269) | bash | `549ee4073d83ddc3114327176a7908e2a284a36b8fdd273b15c32ea6b359ee88` | Shell syntax checked; side-effect commands not executed | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/README.md:fence-3](../../../samples/GuidedTour/README.md#L282) | bash | `d3b117fad44b49be910b5b785b9667134d31745c4121e8a4d158f153f13231fe` | Shell syntax checked; side-effect commands not executed | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:RunLiveWorkerStepAsync-1](../../../samples/GuidedTour/TourSession.cs#L1873) | csharp | `8fb8fe0098ae33953818583eef1955374ef5ad55ec6909c938d650793d652743` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:RunLiveWorkerStepAsync-2](../../../samples/GuidedTour/TourSession.cs#L1879) | csharp | `67829faba3363cd6e67e6304ca9339256f103925e4cfc3ac9725f1bb5d1f153d` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:RunLiveWorkerStepAsync-3](../../../samples/GuidedTour/TourSession.cs#L1885) | csharp | `5d0604bbf2d7e2ace4995c6a97f0f7468653b54c5e3d60f8b435d353db7f2358` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:RunLiveWorkerStepAsync-4](../../../samples/GuidedTour/TourSession.cs#L1891) | csharp | `10d4d1c166a479ca9327ce12181d035f6c9ea78f68b5428c2641b0d291a18ccc` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:RunLiveWorkerStepAsync-5](../../../samples/GuidedTour/TourSession.cs#L1895) | csharp | `bbb3d57fc273f0fb85dfb3afc18980d77a5ea9509c77d6ecfdb181fe894be11b` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:RunLiveWorkerStepAsync-6](../../../samples/GuidedTour/TourSession.cs#L1900) | csharp | `04b49a4d7dc5dbfff8937ede6e6d56930c86d999cc881b664c934c643687d9c9` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:SubAgentParentTokenSnippet-7](../../../samples/GuidedTour/TourSession.cs#L1914) | csharp | `1a024c2cf845b807a719cda2b14fe8fc704ccae6a655e62c853c1d55c2f4aa8c` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/GuidedTour/TourSession.cs:SubAgentWorkerTokenSnippet-8](../../../samples/GuidedTour/TourSession.cs#L1943) | csharp | `434903506c6b92708791b81861cfa59d212ff3bc3788fdd89c1aaa44b1c4f9a8` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/MissionAgent/README.md:fence-1](../../../samples/MissionAgent/README.md#L40) | text | `bcfaa4e9d3e305a2c818fcbfca9803e27514aa234d9b78737d3575890844c00c` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-2](../../../samples/MissionAgent/README.md#L75) | mermaid | `1ca0e1be89083b0bc748a17ee080284d2ad9a3f257b686798feaefe97c3dd54f` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-3](../../../samples/MissionAgent/README.md#L160) | mermaid | `233ff267d646e521caa316320736714ff16fffe3426974918fa5524f39a2356d` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-4](../../../samples/MissionAgent/README.md#L197) | bash | `838a32c5ef76042a5f120e1f45b698ecf8377cd4d8a2797d4aafeaf178054fd3` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-5](../../../samples/MissionAgent/README.md#L205) | bash | `bd7ab6ab70caf732d08b4223362ea66441a16561ceb9deccc923f1a4ec55000e` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-6](../../../samples/MissionAgent/README.md#L214) | bash | `0aefdf441df667f5b30966946bae9b51f0d985202c7733e922153372f3dc9db4` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-7](../../../samples/MissionAgent/README.md#L220) | bash | `65bda3d6cd1ce8e88a9e5b1713b70a5f5adf9e38fc952dd112e43bc0ffe45d13` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-8](../../../samples/MissionAgent/README.md#L244) | bash | `427b1ed2e66a5a4f6a0aefc63af97fb7302faca5732b5075e0221597f6026f7e` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MissionAgent/README.md:fence-9](../../../samples/MissionAgent/README.md#L256) | bash | `484a6b139145eb4a4d9af3a00a3a49cd05ceffb2b2aa6551766927ee693ffb90` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAccessServers/Federated/README.md:fence-1](../../../samples/MockAccessServers/Federated/README.md#L58) | bash | `32f77f60c1f6fc0cf6fa4bb1475f12e200abe5ff78c303c1d000148c91436309` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAccessServers/Federated/README.md:fence-2](../../../samples/MockAccessServers/Federated/README.md#L103) | bash | `ef23884b8e86b32a20334a454f384e08564ead9deb5ecd297febd6a6b34b5400` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAccessServers/Federated/README.md:fence-3](../../../samples/MockAccessServers/Federated/README.md#L109) | bash | `481ed1eda6a4d531693df0199810be3eaa64e4a006cdcf7a12a2b68cc47ceb5b` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAccessServers/README.md:fence-1](../../../samples/MockAccessServers/README.md#L52) | bash | `84bc1a5edb19022f5b273a7dca7a5110fa0986a0083c40d53de78ec7d1483348` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAgentProvider/README.md:fence-1](../../../samples/MockAgentProvider/README.md#L25) | bash | `016d1fa45df9833e0ba49e8da141e5bee17880475b58e33588eee4276e2a00d8` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAgentProvider/README.md:fence-2](../../../samples/MockAgentProvider/README.md#L33) | bash | `db82207af68a01be6c3d5a244232b509e1723c3af0e3697b2e9aaf0b55dd38bd` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockAgentProvider/README.md:fence-3](../../../samples/MockAgentProvider/README.md#L44) | json | `720b972c0fd1f4f7a5a82ba89556a3173dbe83aa8408ed64d96e91252eb11012` | JSON parsed; displayed identifiers/claims are illustrative | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockPersonServer/README.md:fence-1](../../../samples/MockPersonServer/README.md#L151) | bash | `b183ed4a8dfcaa44c29c99bc03fdfbd48a243beb13c4c5fa866387c24c5fd988` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockPersonServer/README.md:fence-2](../../../samples/MockPersonServer/README.md#L159) | bash | `07d9570f472918f18e9d0ce724b66b667dce93392f42cc8e6361efb29bd9a33a` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Bookings/README.md:fence-1](../../../samples/MockResourceServers/Bookings/README.md#L73) | bash | `e985208fee44b1458815a5da292860d021ea36083336c8ef45496787bda7e1a9` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Calendar/README.md:fence-1](../../../samples/MockResourceServers/Calendar/README.md#L33) | bash | `26cd5505c29422ddb1032d5c73126f4d17fd74dafedcc90f62ea708a60ef4748` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Calendar/README.md:fence-2](../../../samples/MockResourceServers/Calendar/README.md#L39) | bash | `b796154a6bf6f11e544824eff3272f406c0d9201ec8c294ccafd658c6e4c0039` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Inbox/README.md:fence-1](../../../samples/MockResourceServers/Inbox/README.md#L42) | mermaid | `7a71808473223e00cb7c9984355f08a6b9606b1c89f49408f2b0b4e99c06aad3` | Sequence/flow source checked; actors/order reviewed against mapped scenario | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Inbox/README.md:fence-2](../../../samples/MockResourceServers/Inbox/README.md#L63) | bash | `c790576af4dcd14a1537ae6fa6674f2ab50661541b9fbdb9af096688ec51ba86` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Inbox/README.md:fence-3](../../../samples/MockResourceServers/Inbox/README.md#L69) | bash | `4350c348d8bcc4f8e36b66ded270a9b4a50bf6579e46d60d7196cec10c668997` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Profile/README.md:fence-1](../../../samples/MockResourceServers/Profile/README.md#L40) | bash | `c2d4c4475e969b89e1c03350f8f072993a747c1e6d8eb829872baa69596ecca2` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Profile/README.md:fence-2](../../../samples/MockResourceServers/Profile/README.md#L49) | bash | `99b4b4891c12309a5d1cb10008a5be793de0af11699f30271ef428ad74f4b4a2` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/README.md:fence-1](../../../samples/MockResourceServers/README.md#L76) | bash | `916b5235d2fe61a422594a603f3bb8044a31ce2e224831e131fb4939ff260ea8` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/README.md:fence-2](../../../samples/MockResourceServers/README.md#L82) | bash | `721fe8dc2df254017febc2383bc5571d05b647334bcb9caf675f05984ec9b7b8` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Trips/README.md:fence-1](../../../samples/MockResourceServers/Trips/README.md#L29) | bash | `8a22349beae27d0015ed2fcc8bbd9ee011ae7d305193b3ce3b02123596fb4ca0` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/MockResourceServers/Wallet/README.md:fence-1](../../../samples/MockResourceServers/Wallet/README.md#L30) | bash | `1ad360b8e2259599187dedb9b3fcf3cddef1d0affeab8b21d9f355dabd3ab059` | Shell syntax checked; side-effect commands not executed | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/MockResourceServers/Wallet/README.md:fence-2](../../../samples/MockResourceServers/Wallet/README.md#L39) | bash | `1c9e9ac5481e479bb2dc17031eb320f334638bf434050b2ae7e5596db71364d6` | Shell syntax checked; side-effect commands not executed | [Wallet session](../../../samples/CapabilitySupport/WalletDemoSession.cs), [both-app Wallet wrapper](../../../tests/e2e/helpers/wallet-protocol.ts), DeferredFederationTests / RevocationLifecycleTests | +| [samples/README.md:fence-1](../../../samples/README.md#L59) | csharp | `2b712ecb3492998075ff420dbe306e24d9301a11115d40ec85698f19c7c05f8f` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-2](../../../samples/README.md#L128) | bash | `549ee4073d83ddc3114327176a7908e2a284a36b8fdd273b15c32ea6b359ee88` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-3](../../../samples/README.md#L155) | bash | `6483e1a97b8691a784209ca40d7c0637d35249ea0b6efea72f8611406ff21604` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-4](../../../samples/README.md#L168) | bash | `4621bc905177f723f5e0ff904d1c513d983efbdbd51e2827ae6e63acfd896ff3` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-5](../../../samples/README.md#L179) | bash | `c2d4c4475e969b89e1c03350f8f072993a747c1e6d8eb829872baa69596ecca2` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-6](../../../samples/README.md#L193) | bash | `26cd5505c29422ddb1032d5c73126f4d17fd74dafedcc90f62ea708a60ef4748` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-7](../../../samples/README.md#L205) | bash | `8a22349beae27d0015ed2fcc8bbd9ee011ae7d305193b3ce3b02123596fb4ca0` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-8](../../../samples/README.md#L216) | bash | `1ad360b8e2259599187dedb9b3fcf3cddef1d0affeab8b21d9f355dabd3ab059` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-9](../../../samples/README.md#L228) | bash | `8b523bb4e46c0fdd3ada382ff8237f95c4118aae3abf9578b598ee9bec6b475c` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-10](../../../samples/README.md#L246) | bash | `73a53d75067b1a3aa5eac127f6b0d7a625f83713fb06ee4e3bea1cdf9671abe5` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-11](../../../samples/README.md#L262) | bash | `cee4e3957fc6fb00091a113fa578f12d62cfe47afe312878af61b4c516d91fc7` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-12](../../../samples/README.md#L268) | bash | `e3ec86108ef1216233056686189a69f34847e9529f1a69ea1ac6435fae7d9e91` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-13](../../../samples/README.md#L275) | bash | `be7b50ef7791ff23eeacd6d1dad02cdcd6157b6e078b368c7b50f4f5473d3ee3` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-14](../../../samples/README.md#L282) | bash | `548a4c130e36f0e540cea77d08cfe6f58c46fa9c9a59dcc0609d6cb13e608178` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-15](../../../samples/README.md#L289) | bash | `002a217633241d5cc6fc83782796cbcbb767589845ca154c25ad4b01c70bf80d` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-16](../../../samples/README.md#L296) | bash | `12e0b452b94aa11c170fda876cc292cbaf09dae6d866a1a999cff725c83caf50` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-17](../../../samples/README.md#L303) | bash | `83238081ecaf4bd0cedbbba71f255837877b6616abfef5690d922265ca760f56` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-18](../../../samples/README.md#L310) | | `e67e2bfc97e30b3dcb7664e75f45a04a3291072f9e7d35e9218698e9cfd59143` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-19](../../../samples/README.md#L317) | bash | `57d37b25e0c69f2937389103209b47d1afdd0921ded21c9ced1e56b125d0abb4` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-20](../../../samples/README.md#L337) | bash | `686dc78fa36af733b25698df0c76b97922036ec767388988bc60f99f2cc0c37d` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-21](../../../samples/README.md#L345) | bash | `016d1fa45df9833e0ba49e8da141e5bee17880475b58e33588eee4276e2a00d8` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-22](../../../samples/README.md#L353) | bash | `4478cd8fcf98e455297048a70cec99c07521e8e69d842c61bd638e0e8fe88bc7` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-23](../../../samples/README.md#L361) | bash | `a16fd99e6ab5da9ec0b66842bdc6152550bf7bd67ef6d1b4ca224e61c720dd9c` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-24](../../../samples/README.md#L369) | bash | `5f98072a1cdb9576b409814e096a5af4ca63bbdfd249a81fc467957c5bbcf196` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/README.md:fence-25](../../../samples/README.md#L383) | bash | `14414eb9995e01d8a1e9044be7f06cb3b8b5086e2831d7a5eb3de253369731b3` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [samples/SampleApp/Components/ConsentProgress.razor:pre-1](../../../samples/SampleApp/Components/ConsentProgress.razor#L9) | dynamic | `c2c8df5449e6308ee027ab4b9009a22c76e20762fa53dcaf4f54bc7204b7ea5e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:pre-1](../../../samples/SampleApp/Components/Pages/Bookings.razor#L49) | csharp | `6d6644a6334936599b2095c6f993c464849caaef5accb9ed5e527cac7857134f` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:pre-2](../../../samples/SampleApp/Components/Pages/Bookings.razor#L77) | csharp | `eafe50ea1bb4e5fb384c9eaa3f445c0d15748fea2c2188676c034fb59373553a` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:pre-3](../../../samples/SampleApp/Components/Pages/Bookings.razor#L166) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-1](../../../samples/SampleApp/Components/Pages/Bookings.razor#L31) | inline-code | `cd869f23e81edb60a56a30664392dfa85a99877b8fdea1753211a758a16afe3b` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-2](../../../samples/SampleApp/Components/Pages/Bookings.razor#L31) | inline-code | `a41941b8b4af1fefc5445fd387a888c3269536a4c34522df43edfda817a03d10` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-3](../../../samples/SampleApp/Components/Pages/Bookings.razor#L32) | inline-code | `3efa7ace7b9668a034412e0aa7e728a6429c90434498efb6ca434c322bf6d866` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-4](../../../samples/SampleApp/Components/Pages/Bookings.razor#L33) | inline-code | `e3b900eb6f07c4ede76833b00261f2e84f3b807cfc786eee52a4874fac589877` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-5](../../../samples/SampleApp/Components/Pages/Bookings.razor#L33) | inline-code | `a3ff5c0910d2437fb70ae2c71df3adc8371f90ab4d7c9d06d78d5f79cca36fb6` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-6](../../../samples/SampleApp/Components/Pages/Bookings.razor#L34) | inline-code | `2336af25ca724d260446e47a636db7453efc335df448c2a57d4c67ac9965dbbe` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-7](../../../samples/SampleApp/Components/Pages/Bookings.razor#L34) | inline-code | `1b926447cdc6ac734336c3f96612a4ebb43930848e698b46dbb925a3deadfdd0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-8](../../../samples/SampleApp/Components/Pages/Bookings.razor#L40) | inline-code | `dcaadad1cfce437735b81ab025f776e5857e48558c47f6960e6a5f2595664a85` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-9](../../../samples/SampleApp/Components/Pages/Bookings.razor#L41) | inline-code | `4275d71e90f7f09f9dcbba2aeeaafb3f30576780bc4d5419ff086d1c6f02a654` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-10](../../../samples/SampleApp/Components/Pages/Bookings.razor#L104) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-11](../../../samples/SampleApp/Components/Pages/Bookings.razor#L107) | inline-code | `43a66baa0fa981612952995435339ac081139751b16cdfbe52a30976c9dfe020` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-12](../../../samples/SampleApp/Components/Pages/Bookings.razor#L134) | inline-code | `2336af25ca724d260446e47a636db7453efc335df448c2a57d4c67ac9965dbbe` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-13](../../../samples/SampleApp/Components/Pages/Bookings.razor#L135) | inline-code | `1b926447cdc6ac734336c3f96612a4ebb43930848e698b46dbb925a3deadfdd0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Bookings.razor:inline-14](../../../samples/SampleApp/Components/Pages/Bookings.razor#L136) | inline-code | `dcaadad1cfce437735b81ab025f776e5857e48558c47f6960e6a5f2595664a85` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:pre-1](../../../samples/SampleApp/Components/Pages/CallChain.razor#L60) | csharp | `5e1ebbd72779d5d3215d0a3d6accf98e8915b0a578ec0f84f4048408fa77c03e` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:pre-2](../../../samples/SampleApp/Components/Pages/CallChain.razor#L74) | csharp | `ada4b14d6c40147ee4a5d7be6f147fad3d312bde6c8880052e63d3fd6edc9b57` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:pre-3](../../../samples/SampleApp/Components/Pages/CallChain.razor#L174) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-1](../../../samples/SampleApp/Components/Pages/CallChain.razor#L31) | inline-code | `cbe370481704cef068c18bdcbe262329c59824d6c87e96510a53f022e899ab04` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-2](../../../samples/SampleApp/Components/Pages/CallChain.razor#L33) | inline-code | `2505b184cfaffd55bf75d2cd98718f94d14d4924b1773eab7f072a1fcb6bdf9b` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-3](../../../samples/SampleApp/Components/Pages/CallChain.razor#L34) | inline-code | `c17edaae86e4016a583e098582f6dbf3eccade8ef83747df9ba617ded9d31309` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-4](../../../samples/SampleApp/Components/Pages/CallChain.razor#L46) | inline-code | `39158e0110cbcadec00557639c5ff0adf32f6285c46c235eb259dc13c8d31b45` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-5](../../../samples/SampleApp/Components/Pages/CallChain.razor#L47) | inline-code | `f029e50fcd09f511f8ca991cde2a36568dd18f8e021939e4ddbd46079e021e06` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-6](../../../samples/SampleApp/Components/Pages/CallChain.razor#L48) | inline-code | `6527c9361a2f469c5275afcb5d06e53013367cd231995de13dc7218711388382` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-7](../../../samples/SampleApp/Components/Pages/CallChain.razor#L49) | inline-code | `39158e0110cbcadec00557639c5ff0adf32f6285c46c235eb259dc13c8d31b45` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-8](../../../samples/SampleApp/Components/Pages/CallChain.razor#L51) | inline-code | `cbdd8637f090e7de25403ed8482aae56b66be61046629696f01c8ca3d3a03d63` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-9](../../../samples/SampleApp/Components/Pages/CallChain.razor#L123) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/CallChain.razor:inline-10](../../../samples/SampleApp/Components/Pages/CallChain.razor#L150) | inline-code | `772e10a0c0a795b97d1391d2d7c4b0cb1fde19ac5027c48de6008e10dede67e3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Deferred.razor:pre-1](../../../samples/SampleApp/Components/Pages/Deferred.razor#L33) | csharp | `d2cf8d52a72dcc3125d20b9a25af67ad12b9ee840c686403db7363d821b8d501` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Deferred.razor:pre-2](../../../samples/SampleApp/Components/Pages/Deferred.razor#L51) | csharp | `89b1010f45dc274e277c21612e25c5701aacf0588b97b865de1ab46b45718b99` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Deferred.razor:pre-3](../../../samples/SampleApp/Components/Pages/Deferred.razor#L133) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Deferred.razor:inline-1](../../../samples/SampleApp/Components/Pages/Deferred.razor#L26) | inline-code | `772e10a0c0a795b97d1391d2d7c4b0cb1fde19ac5027c48de6008e10dede67e3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Deferred.razor:inline-2](../../../samples/SampleApp/Components/Pages/Deferred.razor#L103) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Deferred.razor:inline-3](../../../samples/SampleApp/Components/Pages/Deferred.razor#L121) | inline-code | `772e10a0c0a795b97d1391d2d7c4b0cb1fde19ac5027c48de6008e10dede67e3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Error.razor:inline-1](../../../samples/SampleApp/Components/Pages/Error.razor#L12) | inline-code | `ac5f3f7e302eed0ed97a7591c4980581b7b37562919913daf30e670ed54fb7cd` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:pre-1](../../../samples/SampleApp/Components/Pages/Federated.razor#L55) | csharp | `ff2e213078a4c32ec947dfb940176fecd067f2fd8c305b555d98fbd0c9eeaa0d` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:pre-2](../../../samples/SampleApp/Components/Pages/Federated.razor#L70) | csharp | `e05075e5b88f43ce9d8cf568f5692ddb069738852e8f94d7a4ef5c4ead296514` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:pre-3](../../../samples/SampleApp/Components/Pages/Federated.razor#L136) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-1](../../../samples/SampleApp/Components/Pages/Federated.razor#L26) | inline-code | `0926d7734e784737b4b462e2daa3c6db041ee5c01b75a7a2b3ba9463d2efc8cc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-2](../../../samples/SampleApp/Components/Pages/Federated.razor#L27) | inline-code | `4275d71e90f7f09f9dcbba2aeeaafb3f30576780bc4d5419ff086d1c6f02a654` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-3](../../../samples/SampleApp/Components/Pages/Federated.razor#L29) | inline-code | `c795c4789217dcc6ad0187a39fe6d68c950ca3e9538cd95f768478b8ab143a09` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-4](../../../samples/SampleApp/Components/Pages/Federated.razor#L31) | inline-code | `1744bb6c1da2e55193e9eb4afe485e275c8cc30a2b1d1b9c100170d36fe9e520` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-5](../../../samples/SampleApp/Components/Pages/Federated.razor#L31) | inline-code | `c68c500e222872c83bbfe1cd0ccbb6a060bb88f1c53092a46ca9d182f0071362` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-6](../../../samples/SampleApp/Components/Pages/Federated.razor#L43) | inline-code | `7b546c362b786ab04a8a813810b1bb0ac4d1490fd17a19817fa34f194b83d785` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-7](../../../samples/SampleApp/Components/Pages/Federated.razor#L48) | inline-code | `a6ef89c2e28ae06c35306edd800dc0258b1243653636e119527a5e6da515b605` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-8](../../../samples/SampleApp/Components/Pages/Federated.razor#L49) | inline-code | `f55a0838018af0b222392c581b4cea6e096822c40b20aaad4b477534b29d3105` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-9](../../../samples/SampleApp/Components/Pages/Federated.razor#L90) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-10](../../../samples/SampleApp/Components/Pages/Federated.razor#L93) | inline-code | `989020bbf9c19ec30fec31a0ab554af489a28fc4b00a76bdc0ef448f80e801de` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-11](../../../samples/SampleApp/Components/Pages/Federated.razor#L107) | inline-code | `5f75aa4b29c22ccdf79fe3d835306792ff8b0a3bbb2c46657d2a0c0b8885820e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Federated.razor:inline-12](../../../samples/SampleApp/Components/Pages/Federated.razor#L107) | inline-code | `b4acf3cd196a669e73b99e5ad4852599295d624976af968417e561186ae77832` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:pre-1](../../../samples/SampleApp/Components/Pages/Home.razor#L349) | | `a6ef89c2e28ae06c35306edd800dc0258b1243653636e119527a5e6da515b605` | Illustrative text/HTTP fragment: placeholder bytes, current contract check; not a signed request | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-1](../../../samples/SampleApp/Components/Pages/Home.razor#L30) | inline-code | `3a5a5f5512f1031d566b8fdf9d61785652b7a69301861e1aacbb1f7bfd424e8a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-2](../../../samples/SampleApp/Components/Pages/Home.razor#L79) | inline-code | `0176343e4a437b2b37db94a36274da651d05b5e009cde3cb7a367b5d6feb6300` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-3](../../../samples/SampleApp/Components/Pages/Home.razor#L156) | inline-code | `cbdd8637f090e7de25403ed8482aae56b66be61046629696f01c8ca3d3a03d63` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-4](../../../samples/SampleApp/Components/Pages/Home.razor#L157) | inline-code | `d4f0bc5a29de06b510f9aa428f1eedba926012b591fef7a518e776a7c9bd1824` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-5](../../../samples/SampleApp/Components/Pages/Home.razor#L157) | inline-code | `f83f07be16e270186d35b876916c461995ebc3af5b1798f898c33285a1847dbc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-6](../../../samples/SampleApp/Components/Pages/Home.razor#L178) | inline-code | `9b573f58833b299cb4b692346359185025c5cab22f6e67526bc5b6cd7f59ca34` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-7](../../../samples/SampleApp/Components/Pages/Home.razor#L179) | inline-code | `d4f0bc5a29de06b510f9aa428f1eedba926012b591fef7a518e776a7c9bd1824` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-8](../../../samples/SampleApp/Components/Pages/Home.razor#L179) | inline-code | `f83f07be16e270186d35b876916c461995ebc3af5b1798f898c33285a1847dbc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-9](../../../samples/SampleApp/Components/Pages/Home.razor#L218) | inline-code | `2336af25ca724d260446e47a636db7453efc335df448c2a57d4c67ac9965dbbe` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-10](../../../samples/SampleApp/Components/Pages/Home.razor#L220) | inline-code | `1b926447cdc6ac734336c3f96612a4ebb43930848e698b46dbb925a3deadfdd0` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-11](../../../samples/SampleApp/Components/Pages/Home.razor#L334) | inline-code | `a330395cc0a53ad1207736546afff4735940937564bbf75ce1edad40780d9139` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-12](../../../samples/SampleApp/Components/Pages/Home.razor#L351) | inline-code | `cd4728d5cf48bc8d687a147bc5fe05e0f907ac21804aeab209c793f833833f2d` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-13](../../../samples/SampleApp/Components/Pages/Home.razor#L352) | inline-code | `c7c9a7b1edf63900776b727b3e12dbdedffbaa14254a17de169efc2a54818c54` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-14](../../../samples/SampleApp/Components/Pages/Home.razor#L353) | inline-code | `8a6f8ac0599cd4d532d5ba25f815f48b4688531b5af2817668c6749cb20084ca` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-15](../../../samples/SampleApp/Components/Pages/Home.razor#L353) | inline-code | `12d3c95d85cd6faf3db71816f21fa650174ad30e6ec847f0778da67f36db5393` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-16](../../../samples/SampleApp/Components/Pages/Home.razor#L354) | inline-code | `e75f0d0205e21282d33679d1a7f131cd1b4409fd57deaf23ebbe6f7971415637` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-17](../../../samples/SampleApp/Components/Pages/Home.razor#L354) | inline-code | `9a0186e0172d33985dcb96809703b61b4cea0e30fd57639e5e0feec0a37ac8e6` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-18](../../../samples/SampleApp/Components/Pages/Home.razor#L354) | inline-code | `0785ba6aeb30c3e2a9b516f698b005fad8810fecc3ac8200f279d5ce6d7141c3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-19](../../../samples/SampleApp/Components/Pages/Home.razor#L355) | inline-code | `f8c2282bbbd055ac029944e9cbf3eccc48957b5652f33b8b12072394dd8c9888` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-20](../../../samples/SampleApp/Components/Pages/Home.razor#L355) | inline-code | `0be22b55514bc91928b54bf5dbb584d385576784e09510633f7246b6b8df5217` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-21](../../../samples/SampleApp/Components/Pages/Home.razor#L356) | inline-code | `41f10ba2d18523e4296b3560cf0604161195f2e4a075014c61539ce47f9ca97e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-22](../../../samples/SampleApp/Components/Pages/Home.razor#L357) | inline-code | `3f596db8aec3b34c95272b2c1f41b6d561752f433e5b00c8511718ad0463dafb` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-23](../../../samples/SampleApp/Components/Pages/Home.razor#L358) | inline-code | `433b76c7e0a8d1efce3e6009e16107f9c26c5f68b52712277e393828e7919ac8` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-24](../../../samples/SampleApp/Components/Pages/Home.razor#L358) | inline-code | `b7780cd609447ab9003df45ac23755cf4002106f6e0d2a2604d5df3e487a1467` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-25](../../../samples/SampleApp/Components/Pages/Home.razor#L359) | inline-code | `9a5c9b9b5223bf6e237ee67d70af31e504d65b2e16109807f484751c03d22b2c` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Home.razor:inline-26](../../../samples/SampleApp/Components/Pages/Home.razor#L359) | inline-code | `3a5a5f5512f1031d566b8fdf9d61785652b7a69301861e1aacbb1f7bfd424e8a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Hwk.razor:pre-1](../../../samples/SampleApp/Components/Pages/Hwk.razor#L29) | csharp | `d098fe99f7410d213dcd4ef6f94486c26266e3ed0d91ee784cef72707f1a71d3` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Hwk.razor:pre-2](../../../samples/SampleApp/Components/Pages/Hwk.razor#L37) | csharp | `c74a0c707c62028ce19e23e99423ace33d336ff0485eae8056e1a1b7500ce742` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Hwk.razor:pre-3](../../../samples/SampleApp/Components/Pages/Hwk.razor#L88) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:pre-1](../../../samples/SampleApp/Components/Pages/Inbox.razor#L40) | csharp | `66c55ffa77889aa99807dbfdefc44de0e484979afc237dc5cb7b520b9812a4f9` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:pre-2](../../../samples/SampleApp/Components/Pages/Inbox.razor#L69) | csharp | `9bfecb471f09181f48033ae0def5d093e359765d2edd22dd94ebce996540f3f4` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:pre-3](../../../samples/SampleApp/Components/Pages/Inbox.razor#L150) | dynamic | `d3b7c288e3cfe16288f740c3b04341f355cf6e192bf783430075a0258d82dbd2` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:inline-1](../../../samples/SampleApp/Components/Pages/Inbox.razor#L29) | inline-code | `84e925d67edae8780e32bf145b35353d9aa74a63c3a6cbd96e75d468e11e3996` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:inline-2](../../../samples/SampleApp/Components/Pages/Inbox.razor#L31) | inline-code | `c17edaae86e4016a583e098582f6dbf3eccade8ef83747df9ba617ded9d31309` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:inline-3](../../../samples/SampleApp/Components/Pages/Inbox.razor#L32) | inline-code | `0176343e4a437b2b37db94a36274da651d05b5e009cde3cb7a367b5d6feb6300` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Inbox.razor:inline-4](../../../samples/SampleApp/Components/Pages/Inbox.razor#L34) | inline-code | `447e8542e794f80343c28c05e0dde8feeb4fad5353534f25ffd4860ec5122e09` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:pre-1](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L31) | csharp | `5e38d824aa0df318956fd1cf5f0870bb3240fcb35e746efd2ad74e29d605484a` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:pre-2](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L109) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-1](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L24) | inline-code | `d645cdbfc5f3d9722c4081aef9ec1a2bc76ffb9f7588025ae985bf0def67f78f` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-2](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L51) | inline-code | `82a9a4369a2190e4225be7f0bb6dd1963beb23980dafa403fbac425b8c411c30` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-3](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L53) | inline-code | `3f0632bd4ff1ba4d46ae32269286141675ef248cc2dfa5366be1756c2c9f367a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-4](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L60) | inline-code | `0366839a6940219eb210f6eaa73e25226905fa630a23576abfc705d898b76bdc` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-5](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L61) | inline-code | `82a9a4369a2190e4225be7f0bb6dd1963beb23980dafa403fbac425b8c411c30` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-6](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L62) | inline-code | `bc8c83a50192cc548ba210f1821e59f1900042570d06e906c9edeb8a8a4b1395` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-7](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L76) | inline-code | `ab0cc234202e566249566a8b3b90d3161892b5609fc452d6fbc7375a85aee4bd` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-8](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L77) | inline-code | `9f5cdbec39e36cd5c59e121b33c60bee4e76a9c0993d15dae0183cd9483698f2` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JktJwt.razor:inline-9](../../../samples/SampleApp/Components/Pages/JktJwt.razor#L89) | inline-code | `391ecdbfde78db0002d4927b6080eb417b873ae25f48eeecbd815e9c9d207596` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JwksUri.razor:pre-1](../../../samples/SampleApp/Components/Pages/JwksUri.razor#L29) | csharp | `0db0e8adb061c0229f84adff9cc7f6296b22739ac7859ccf8ea0a5401f8f8b03` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JwksUri.razor:pre-2](../../../samples/SampleApp/Components/Pages/JwksUri.razor#L39) | csharp | `97940e11299f5d55eff058613ade97c30b89f91eb362d97a5aff9facc4391af9` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JwksUri.razor:pre-3](../../../samples/SampleApp/Components/Pages/JwksUri.razor#L107) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JwksUri.razor:inline-1](../../../samples/SampleApp/Components/Pages/JwksUri.razor#L91) | inline-code | `ab0cc234202e566249566a8b3b90d3161892b5609fc452d6fbc7375a85aee4bd` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/JwksUri.razor:inline-2](../../../samples/SampleApp/Components/Pages/JwksUri.razor#L92) | inline-code | `6e66c138122fe819ec59154052552f23628df6545b9ce4e4c8ce0c50b54dbe7f` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Jwt.razor:pre-1](../../../samples/SampleApp/Components/Pages/Jwt.razor#L32) | csharp | `12966857ddaa13927498f148eeccd3e4b886937aa90f940a92c0ecbab95c88f2` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Jwt.razor:pre-2](../../../samples/SampleApp/Components/Pages/Jwt.razor#L48) | csharp | `3a09376aa987066cb2e818182a89f0dcaa5027e078b3485b075ef7b4efdae7af` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Jwt.razor:pre-3](../../../samples/SampleApp/Components/Pages/Jwt.razor#L115) | dynamic | `031f5bdf4c2be7d2ebe51bf0bfe5931c404f567cad8704483cb4a0514a3b5d8e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Jwt.razor:inline-1](../../../samples/SampleApp/Components/Pages/Jwt.razor#L23) | inline-code | `84e925d67edae8780e32bf145b35353d9aa74a63c3a6cbd96e75d468e11e3996` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Jwt.razor:inline-2](../../../samples/SampleApp/Components/Pages/Jwt.razor#L24) | inline-code | `fc93cb07e1ad92898527100e58a1cf1d1e7f65e9a266a6f87f3c84feb541c7b3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Jwt.razor:inline-3](../../../samples/SampleApp/Components/Pages/Jwt.razor#L101) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:pre-1](../../../samples/SampleApp/Components/Pages/Mission.razor#L48) | csharp | `8fed14a0582d608b9c0c3af4b559438bc5999c41723c5985c846c42f640b2f5d` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:pre-2](../../../samples/SampleApp/Components/Pages/Mission.razor#L130) | csharp | `de000b06bd2838af82897bdff4597878fa89cd2dcbaebca0e190aecc864839d1` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:pre-3](../../../samples/SampleApp/Components/Pages/Mission.razor#L188) | csharp | `80bda3eff6569eb60e9b335fe2848cfe89b9fe8f39e2fd2b6635504afe5db6e6` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:pre-4](../../../samples/SampleApp/Components/Pages/Mission.razor#L273) | dynamic | `da7167bfacd9b3d919e7d7ff01a69040d9678c8aec63eddf8e18a2fa7d18b5ec` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-1](../../../samples/SampleApp/Components/Pages/Mission.razor#L24) | inline-code | `fd8abb915cb6b7b4241439d7d6ee2eb1bde2e21ba93940838c879f61e44c4723` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-2](../../../samples/SampleApp/Components/Pages/Mission.razor#L25) | inline-code | `59874580919614e8a19e5d82d568d118a39d1c77aa0deaae1aa37369d3aacdf3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-3](../../../samples/SampleApp/Components/Pages/Mission.razor#L207) | inline-code | `39158e0110cbcadec00557639c5ff0adf32f6285c46c235eb259dc13c8d31b45` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-4](../../../samples/SampleApp/Components/Pages/Mission.razor#L212) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-5](../../../samples/SampleApp/Components/Pages/Mission.razor#L213) | inline-code | `f9cf0053edea40a3e65b65d3b779b453933832f0c84739cba9b8fbbfcbbbb59e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-6](../../../samples/SampleApp/Components/Pages/Mission.razor#L222) | inline-code | `59874580919614e8a19e5d82d568d118a39d1c77aa0deaae1aa37369d3aacdf3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-7](../../../samples/SampleApp/Components/Pages/Mission.razor#L223) | inline-code | `7c1709777753420426f1975bc36fbd5af8835ea2185d922da2f4f17c69385f51` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-8](../../../samples/SampleApp/Components/Pages/Mission.razor#L242) | inline-code | `39158e0110cbcadec00557639c5ff0adf32f6285c46c235eb259dc13c8d31b45` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/Mission.razor:inline-9](../../../samples/SampleApp/Components/Pages/Mission.razor#L287) | inline-code | `772e10a0c0a795b97d1391d2d7c4b0cb1fde19ac5027c48de6008e10dede67e3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:pre-1](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L67) | csharp | `d4cea35c63ff2c8bccdf7354172735824834be0173044ee298e4d76d1867614a` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:pre-2](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L91) | csharp | `de06d1076ba44fcd6250fcfb806c5fc5966a2243a751b991d524b64c640ad34b` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:pre-3](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L171) | dynamic | `da7167bfacd9b3d919e7d7ff01a69040d9678c8aec63eddf8e18a2fa7d18b5ec` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-1](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L40) | inline-code | `431cc3752e9daffd910425faeb6f90404e65e6a92dcfccb67deaddec2ab998c4` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-2](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L41) | inline-code | `a1ea09992888a04b5006bbaad7eea6389498d5b4f4c403edc7c0e5e52ea8435a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-3](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L42) | inline-code | `21109c3154adf851060b57837dd23358ff93abbe6858bf2f0c629d0b581e2e6b` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-4](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L47) | inline-code | `bdcafa0c6ca1072d52a76716254345351ef51e8709a5bdccba6f3103b1923099` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-5](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L110) | inline-code | `5cc17726782872bd0c1afe0afe7a75ab11881a254e9b70fbb52f519584f27129` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-6](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L111) | inline-code | `f9cf0053edea40a3e65b65d3b779b453933832f0c84739cba9b8fbbfcbbbb59e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-7](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L185) | inline-code | `772e10a0c0a795b97d1391d2d7c4b0cb1fde19ac5027c48de6008e10dede67e3` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/MissionCallChain.razor:inline-8](../../../samples/SampleApp/Components/Pages/MissionCallChain.razor#L208) | inline-code | `d626fe542fb67064bc9bc31cf95eb9bcf87bc99de451075c5509a39cffe32a33` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:pre-1](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L50) | csharp | `c7acc6b47b2dded7537507ee810d3ce134c9566bf0211de39889d1daa154f3e0` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:pre-2](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L72) | csharp | `21b7e68d328e67f1f2f1f69a63746fcd7d3d2d7cf404b86d821271988b5f9ca5` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:pre-3](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L96) | csharp | `5a769b8335bc265a308165bbcb0d74eb697b2ecdcbf1323111ef7904a0075421` | Exact C# compiled with typed prior-step/host inputs | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:pre-4](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L142) | dynamic | `0fd11ce2743d0c0f7474efe3f703c346a5c9db816a6c2317dc252d7312f992a9` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:pre-5](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L171) | dynamic | `0e38c745211e6384dc6ea75bf9e9d67d01f53fd11afd460999e9a89ea297eb3e` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:pre-6](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L184) | dynamic | `c0b22e0bc547334c1efbdac9458c4c6e9a7a4e585af9384df4c51b7945ea3475` | Dynamic Razor binding: build plus mapped scenario browser/captured-wire tests | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-1](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L31) | inline-code | `95948aaf48cdbe9be781310fec6efeeda040176c315d86bfee702bc8d3e5e45e` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-2](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L34) | inline-code | `9b573f58833b299cb4b692346359185025c5cab22f6e67526bc5b6cd7f59ca34` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-3](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L37) | inline-code | `6527c9361a2f469c5275afcb5d06e53013367cd231995de13dc7218711388382` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-4](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L37) | inline-code | `ddc6e2b224d0fd821669202258386936fc9ce2899e215eec6322b95f8dd96d6a` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-5](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L170) | inline-code | `84e925d67edae8780e32bf145b35353d9aa74a63c3a6cbd96e75d468e11e3996` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-6](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L178) | inline-code | `1744bb6c1da2e55193e9eb4afe485e275c8cc30a2b1d1b9c100170d36fe9e520` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [samples/SampleApp/Components/Pages/SubAgent.razor:inline-7](../../../samples/SampleApp/Components/Pages/SubAgent.razor#L180) | inline-code | `82a9a4369a2190e4225be7f0bb6dd1963beb23980dafa403fbac425b8c411c30` | Inline Razor label/expression: source inventory, build and scenario display checks; not a standalone program | [capability-to-flow/spec map](capability-scenarios.md), [tour state](../../../samples/GuidedTour/TourSession.cs), [app specs](../../../samples/SampleApp/playwright-tests/), [tour specs](../../../samples/GuidedTour/playwright-tests/) | +| [src/AAuth.R3/README.md:fence-1](../../../src/AAuth.R3/README.md#L38) | csharp | `61faed3823429dc92bfb2d287a28084a48b874ae946c645108ba23f1f4390f30` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [src/AAuth/README.md:fence-1](../../../src/AAuth/README.md#L9) | bash | `0cc8bf77419b3cf5842a01e5350d865905b39fbe124a4b0fc90be9e8e4336218` | Shell syntax checked; side-effect commands not executed | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [src/AAuth/README.md:fence-2](../../../src/AAuth/README.md#L18) | csharp | `bac6e655a77d637c9087c68c5c7cb823821acb0c1f1df96c5c1d29ddfb4ca8d2` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | +| [src/AAuth/README.md:fence-3](../../../src/AAuth/README.md#L55) | csharp | `03fc179bb24c5831d3f889d646db4ae4c5166c997a660e1b39459359402a7b94` | Exact C# compiled with typed prior-step/host inputs | [API owning-source map](api-surface-map.md), [section-specific source/tests](conformance-ledger.md), [exact compiler](../../../tests/AAuth.Tests/Api/SnippetCompilationTests.cs) | diff --git a/.agent/plans/2026-09-11-aauth-v11-spec-migration/implementation-log.md b/.agent/plans/2026-09-11-aauth-v11-spec-migration/implementation-log.md new file mode 100644 index 00000000..41c48725 --- /dev/null +++ b/.agent/plans/2026-09-11-aauth-v11-spec-migration/implementation-log.md @@ -0,0 +1,1810 @@ +--- +description: Decisions, evidence and closure record for the completed AAuth draft-11 migration. +--- + +# Implementation log - AAuth draft-11 + +Append-only log. Status: **complete** (2026-09-29); see the closure entry at the +end of "Decisions taken". Earlier entries keep their original context. + +## Decisions taken + +### [2026-09-11] [Phase 0] Research-only scope + +RESOLVED. The user requested breaking-change and SDK/API/Samples/Docs analysis +following the draft-10 migration folder. This package records research, maps, +scenarios, a ledger and a proposed implementation plan. SDK baseline: +`94576a3ebcba8cd1d167923e50c8796132057600`; current target remains draft-10. +The reference is unpublished draft-11 WIP with pins in [research.md](research.md). +No SDK implementation or deployment is authorized by the analysis request. + +### [2026-09-11] [Phase 0] Publish the research branch + +RESOLVED. The follow-up request authorizes pushing `wip/aauth-draft-11` after +finishing the analysis. Commit and push the vendored WIP snapshot and this +research package; keep SDK implementation separate. This authorizes Git branch +publication, not package publication, runtime deployment or a conformance claim. + +### [2026-09-11] [Phase 0] Research validation and review + +RESOLVED for the research deliverable only. Five read-only area audits were +collated; a fresh reviewer checked the seven-document package, then rechecked +the identified repairs. The follow-up found no remaining P1/P2 document issues. +Repairs included owning-phase snippet updates, minimum client/Events dependencies +at the identity cutover, atomic clarification-pair replacement, and corrected +source citations. Q13 and Q14 retain newly identified upstream uncertainties. + +The local reference check validated 464 file/line links with no missing files +or empty cited lines; both heading-fragment links resolved. Markdown diagnostics +and tracked-document whitespace checks were clear. These are documentation +checks, not SDK tests. No build, unit, conformance, browser or external interop +pass is claimed, and all implementation definitions of done remain unchecked. + +### [2026-09-25] [Phase 0] Retarget to published draft-11 + +RESOLVED. Draft-11 was published at AAuth tag `draft-hardt-oauth-aauth-protocol-11` +(commit `178e9e6`) with HTTP Signature Keys -09. Both are vendored in +[`aauth-spec/v11/`](../../../aauth-spec/v11/), along with the per-role +[upgrade checklists](../../../aauth-spec/v11/upgrade-10-to-11/README.md) from +commit `180bc95`. The WIP snapshot remains readable at `e6d18a3`. The +[implementation plan](implementation-plan.md#target-pins) now targets the +published text. Its upstream rulings table gives the governing line for each Q. +This is a planning change. It does not authorize SDK implementation. + +### [2026-09-28] [Phase 0] Implementation authorized + +RESOLVED. The user asked to start implementing the plan. This authorizes SDK, +sample, test and docs changes on `wip/aauth-draft-11` in phase order. It does +not authorize package publication, deployment, PR creation or pushing. + +### [2026-09-28] [Phase 0] Q1-Q14 rulings + +RESOLVED (by spec) for Q1-Q5, Q7-Q11, Q13 and Q14, per the governing lines in +[the plan's upstream rulings](implementation-plan.md#upstream-rulings). The SDK +design choices those leave open are decided in their owning phases and logged +there: consent caches (Q4, Phase 6), retained-result storage (Q8, Phases 5 +and 8) and revocation delivery (Q9, Phase 7). + +PROCEEDED (default: core migration plus existing R3 and Events) for Q6. Full +Budgets, hosted child provisioning, supervision protocol and delayed artifacts +stay out of scope. Result-release execution stays disabled with explicit +unsupported handling. Optional checklist items are not selected yet; each +owning phase records its selection before implementing one. + +PROCEEDED (default: reuse current abstractions; isolated or versioned sample +storage) for Q12. No destructive reset of user data. Public API changes are a +single alpha cutover, tracked by the regenerated API map. + +### [2026-09-28] [Phase 0] Baseline + +RESOLVED. `origin/main` (`f44587f`, tag `v0.10.0-alpha.1`) was merged into the +branch as `eef4175` before implementation. .NET SDK 10.0.300, Node 20.20.2. +Release build clean. Baseline tests: Events 75, R3 290, Conformance 1079, core +1496, all passing. e2e TypeScript typecheck passes. Browser suites were not +run for this baseline and are not claimed. + +### [2026-09-28] [Phase 1] Tooling retarget + +RESOLVED. `tools/ApiSurface` defaults to the v11 API map and baseline +`v0.10.0-alpha.1`, with `--map` and `--baseline` overrides. The docs inventory +test writes the v11 docs map. The v10 maps are unchanged. The `jti` implies +`iss` heuristic is replaced by an explicit table of HTTP examples carrying a +`jti` body; the only entry is the revocation request, whose member set Phase 7 +cuts over. + +### [2026-09-28] [Phase 1] Signature error codes and the `created` window + +RESOLVED. Signature Keys -09 `revoked_jwt` and `clock_skew` are typed. +Missing or malformed `Signature` / `Signature-Input` is `invalid_signature` +(-09 section 5.4.4); a malformed `Signature-Key` is `invalid_key` (5.4.7). +The `created` window is symmetric (#verification, L2246): older is +`invalid_signature`, further ahead is `clock_skew`. `MaxFutureSkew` (5 s) +rejected in-window requests, so it is removed from `AAuthVerifier`, +`AAuthResourceOptions` and `AAuthVerificationOptions` (where it was never read). +Future `iat` handling moves in Phase 2 with temporal trust. + +### [2026-09-28] [Phase 1] Metadata vocabulary + +RESOLVED. `token_endpoint` is `auth_token_endpoint` on PS and AS metadata, +clients and the C# options (`AuthTokenEndpoint`). Agents parse +`person_token_endpoint`; the PS publishes it in Phase 2. `access_mode` values +are `agent-token`, `person-token`, `session-token` and `auth-token`; +`aauth-access-token` is rejected at configuration, and agents treat any +unrecognized value as no declaration (AG-02). `login_endpoint` is removed +(RS-02, AP-04). GuidedTour executable reads and snippets moved with it. + +### [2026-09-28] [Phase 1] Token, polling and revocation error vocabulary + +PROCEEDED (default: keep `invalid_agent_token` and `expired_agent_token` until +Phase 4). The published token table removes them, but the PS, AS and Bookings +emitters still send them for failures that become `revoked_presented_token` +and `expired_presented_token` only after the exchange cutover. Removing the +client codes first would misclassify our own servers. Phase 4 removes both +codes and their emitters together. All other published token codes, polling +`revoked`, and revocation errors and downstream outcomes are typed. The unused +`interaction_required` token code is removed. + +### [2026-09-28] [Phase 1] Agent identifiers and Ed25519 + +RESOLVED. `AgentId` accepts `A-Z` in the local part and compares ordinally, so +case variants are distinct identities (#agent-identifiers, L488). The domain +stays lowercase. Ed25519 needed no code change: `AAuthKey.Generate()` is +Ed25519, and the PS, AS, resource, R3 and Events endpoints all verify through +`AAuthVerificationMiddleware`. Existing suites sign with Ed25519 at each role: +MockPersonServer and MockAccessServer integration, `DeferredFederationTests`, +`AccessServerClientTests`, and `EnrolledBuilderTests` against MockAgentProvider's +refresh endpoint. + +### [2026-09-28] [Phase 1] Gates + +RESOLVED. Release build clean. Tests: Events 75, R3 290, Conformance 1112, core +1499, all passing. API map regenerated: 26 changed public-source files, +35/-9 +declarations, 0 unmapped, current on rerun. Docs inventory regenerated and +current on rerun. e2e typecheck passes. Browser suites not run. + +### [2026-09-28] [Phase 2-6] Single identity-model cutover + +PROCEEDED (default: one coordinated cutover; revisit at review). Owner +direction: no backwards compatibility, but consumer-facing API, DI and helpers +stay usable without hand-built tokens. Auth and resource tokens carry `ps`, +`sub`, optional `tenant` and `mission_s256`; `agent`, `act` and `mission` are +removed and reserved in `AdditionalClaims`. The PS issues person tokens at +`person_token_endpoint` (`/person`). Token requests carry `resource_token` and +`presented_token`, and servers verify the pair with +`TokenVerifier.VerifyPresentedTokenAsync`. Removed: `ActChainBuilder`, +`ActChainReader`, `MaxActDepth`, `MissionClaim`, `AAuthMissionHeader`, the +`aauth-mission` signature component, `AccessDecision.Subject`, and the R3 +`Subject` option. + +### [2026-09-28] [Phase 4] Consumer helpers kept for the new flow + +RESOLVED. The two-leg flow runs without callers building tokens: + +- `ChallengeHandler` answers `requirement=person-token` itself. +- `TokenExchangeClient.RequestPersonTokenAsync(ps, resource)` and + `ExchangeAsync(ps, resourceToken, presentedToken)` cover explicit use. +- `ctx.GetAAuthVerifiedAssertion()` exposes the presented token and signing key. +- `AAuthChallengeMiddleware.BuildResourceToken(..., interaction?, loginHint?)` + and `R3Challenge.Challenge(ctx, uri, s256)` build challenges; the R3 one gives + agent tokens the person-token requirement. +- `R3Challenge.BuildResourceToken(verifiedAuthToken, uri, s256)` names an + already-presented auth token for per-call proposals. + +### [2026-09-28] [Phase 4] Access Server accepts only PS callers + +PROCEEDED (default: remove direct agent mode). Draft-11 gives the AS a +`jwks_uri`-signed PS caller with `agent_token`, `resource_token` and +`presented_token`. The direct-agent path and its conformance tests were removed, +and `DirectAsDeferredSourceRevocationAndClarification` now goes through the PS. +`agent_token` keeps the draft-10 `invalid_agent_token`/`expired_agent_token` +codes pending AAuth issue #199 (see Open questions). + +### [2026-09-28] [Phase 3] Mission errors and actions + +RESOLVED. Unknown or foreign missions return 404 `mission_not_found`; terminated +or expired missions return 403 `mission_terminated` (previously 403 +`invalid_mission`). Approval returns the `{s256, mission}` envelope. Update and +completion are `POST {mission_endpoint}/{s256}` (`MissionClient.UpdateAsync` and +`CompleteAsync`); the interaction endpoint rejects `completion`. + +### [2026-09-28] [Phase 8] Events tickets bind to the key thumbprint (Q5) + +RESOLVED. Draft-11 auth tokens name no agent, so `SubscriptionTicket.Agent` +became `KeyThumbprint`, taken from the auth token's `cnf.jwk`. +`ResourceSubscription.KeyThumbprint` records the subscribe request's HTTP +signing key, and redemption requires the two to match. Tickets persisted with +the old shape no longer redeem; the sample SQLite store is disposable. + +### [2026-09-28] [Phase 7] Revoked source tokens on a first request + +RESOLVED. `TokenRegistration` now records the request parameter that carried +each source token. A revoked parameter token returns 400 +`revoked__token` (#token-revocation, L2765; `revoked_upstream_token` +L2593). A revoked `Signature-Key` agent token returns 401 +`Signature-Error: error=revoked_jwt` (L2764). Polling `403 revoked` stays for +revocation while a request is pending (L2624). The helper is +`AAuthProblemDetails.SourceRevoked`. + +### [2026-09-28] [Phase 7] Revocation wire cutover to `{jti, exp}` + +RESOLVED. Single cutover, no draft-10 shim (#token-revocation, L2666-L2768): + +- Request `{jti, exp}`, both required; the issuer is the verified server + signer (`jwks_uri`/`jwks`/`self-jwt`), never a body member (L2690). Body `iss` + is ignored. Malformed body, `jti` or `exp` is `400 invalid_request`. +- `IJtiStore.RevokeAsync(TokenKey, DateTimeOffset expiresAt)` records unseen + tokens (retained until `exp` plus retention, bounded capacity). There is no + 404 (L2703). A full inventory is `500 server_error`. +- `AAuthRevocationOptions.IsAcceptedIssuer` replaces + `AllowTokenIssuer`/`TrustedPersonServers`/`IsTrustedPersonServer`. Unset + means deny, answered `403 unsupported_iss` (L2745). `MapAAuthIssuerRevocation` + defaults to `AAuthTrust.Any`. `MaxTokenLifetime` (24 h + 5 min skew) rejects + a far-future `exp` (L2690 MAY). +- The endpoint records first, cascades, then answers `200` with a `downstream` + report (L2703, L2710). `revocation_incomplete`/502 is gone. The PS sets + `ReportDownstream = false`, so it answers the AP with an empty body. + `RevocationClient.RevokeAsync(Uri, jti, exp)` returns `RevocationResult` + (status, error, downstream, `Failure`). +- Cascade: a grant the recipient issued is revoked at its resource. For a grant + another server (an AS) issued against one of its own tokens, it revokes that + token at the AS instead (L2751), so AP revocation still ends federated access. +- `RevocationClient` covers `content-type`/`content-digest` (L2672). PS/AS/R3 + issuer endpoints require them. The generic resource endpoint behind + `UseAAuth` does not yet enforce coverage. +- Wallet sample: the PS revokes the person token it presented at the AS, and + the AS cascades to Wallet. Resource samples accept only the issuers of their + tokens. +- Not implemented: `202` deferred revocation, `rate_limited`, per-issuer + entry bounds, and records of every AS a person token was presented to. + +### [2026-09-28] [Phase 7] `downstream` lists every recipient + +PROCEEDED (default: spec text). The owner brief suggested listing only failed +downstream calls. L2710 says one entry per resource, with `error` absent on +success, so every recipient is listed and `error` appears only on failure. The +body is empty when nothing was downstream. + +### [2026-09-28] [Phase 5] Fresh token requests name the expired source + +RESOLVED. Direct PS, AS and R3 responses no longer return polling `408 +expired`. `AuthTokenResponse.CreateTrackedAsync` has an overload that takes the +source `TokenRegistration`s, and `AAuthProblemDetails.SourceExpired` maps the +earliest-expired source to one of: + +- a parameter token: 400 `expired__token` (#token-endpoint-error-codes); +- the `Signature-Key` token: 401 `Signature-Error: expired_jwt`; +- a ceiling set by a mission's `expires_at`: 403 `mission_terminated`. + +Pending polls keep `408 expired`. At the AS and R3 the agent token is +registered as the `agent_token` parameter, so it reports `expired_agent_token` +and `revoked_agent_token`. That follows the interim issue #199 ruling. + +### [2026-09-28] [Phase 6] Step 4 agent-token half already enforced + +RESOLVED (test added). The PS records every person or auth token it issues as a +grant of the agent token, so an upstream token issued from a later-revoked agent +token has a revoked ancestor. The intermediary's request then gets 400 +`revoked_upstream_token` (L1835, L2593). `UpstreamFromRevokedCallingAgent_IsRevokedUpstreamToken` +pins it in three- and four-party. The "person binding" half has no SDK concept: +bindings live in the host's `IIdentityClaimsAsserter`, which can refuse to +assert. + +### [2026-09-28] [Phase 3] Mission approval issues `person_tokens` + +RESOLVED. When the governance and PS endpoints share an app, an approval, direct +or on the deferred poll, mints a mission-bound person token for each proposed +resource the identity asserter asserts (#mission-approval). The seam is +`IMissionPersonTokenIssuer`. + +- Tokens bind the agent key, carry `mission_s256`, and expire by the earliest + of the agent token, the mission `expires_at` and one hour. +- Each is a tracked grant of the agent token, so revocation cascades. +- The member is present, possibly empty, whenever the PS issued for named + resources. +- Governance hosted without a PS omits it. +- The deferred path mints at poll time from the poll's agent token rather than + storing key material at park time. + +Not done: MockPersonServer's own `/mission` handler still omits +`person_tokens`, no sample proposes `resources`, and agents do not yet reuse +`Mission.PersonTokens` before calling `/person`. + +### [2026-09-28] [Phase 10] E2E isolates demo server state + +RESOLVED. Playwright-started servers get a scratch `HOME` +(`$TMPDIR/aauth-e2e-home`, wiped per run; `AAUTH_E2E_HOME` keeps one) with the +real NuGet and dotnet caches, so `~/.aauth` no longer affects runs. +`FileKeyStore` names the offending key file. The R3 sample creates its data +folder instead of writing `r3-audit.sqlite` into the project. A plain +`npx playwright test` now passes against the stale `~/.aauth`. + +### [2026-09-28] [Phase 10] Docs spec links on v11 + +RESOLVED. + +- `document-release.md` now cites v11 L993/L994. +- The jkt-jwt and verification-middleware docs cite `signature-key-09`. +- Their `§6.3` citations were wrong in `-08` too. They now cite §7.3 (egress + admission) and §8.1 (pseudonymity). +- Draft-11 R3 removed the OpenAPI Gateway vocabulary (operation identifier + scope, L154). The Catalog page says so and keeps its v10 link until the + Phase 8 redesign. + +### [2026-09-28] [Phase 10] Sample resources echo person identity + +RESOLVED. Calendar and Wallet responses return `ps` and `sub` instead of +`agent` and `act`. `userKey` is `{ps}|{sub}`, because in four-party the `iss` is +the AS, not the person's PS. Profile's `/identified` keeps `agent`, because it +accepts agent tokens only. + +### [2026-09-28] [Phase 7] Resource middleware reports revoked tokens as `revoked_jwt` + +RESOLVED (bug fix). `AAuthVerificationMiddleware` answered a revoked +`Signature-Key` token with `Signature-Error: invalid_jwt`. It now returns +`revoked_jwt` (#token-revocation, L2764). An inventory conflict on a live token +stays `invalid_jwt`. The docs sweep found this; the conformance test +`RevokedAuthToken_Rejected` now pins the exact header. + +### [2026-09-28] [Phase 3] Mission `Approver` members renamed to `PersonServer` + +PROCEEDED (default: rename, no alias). Draft-11 missions have no approver +field. The renamed members are `StoredMission.PersonServer`, +`AAuthGovernancePipelineOptions.PersonServer` and the deferred-consent entry's +`PersonServer`, matching `Mission.PersonServer` and `MissionApprovalContext`. +`IMissionApprover` keeps its name, because it is the PS component that decides +a proposal, not a token field. + +### [2026-09-28] [Phase 10] `mission_aware` metadata removed + +RESOLVED. Draft-11 defines no `mission_aware` resource metadata and no +`AAuth-Mission` header; a mission reaches a resource as `mission_s256`. Bookings +no longer advertises or configures the flag, and the SDK doc comments no longer +cite it. + +### [2026-09-28] [Phase 10] Docs sweep + +RESOLVED for `docs/`. 27 files were rewritten to the draft-11 model by a worker, +and the highest-stakes claims were spot-checked against source (revocation +error rules, pair verification). `Documentation_ResourceRecipientsAndGenericRoutesUseCorrectContext` +now asserts draft-11 wording (`expectedPersonServer`, `VerifyPresentedTokenAsync`, +no `expectedApprover`). The docs inventory is regenerated after the GuidedTour +snippets compile. + +### [2026-09-28] [Phase 5] Holder dropped cached person tokens for account requests + +RESOLVED (bug fix, found by e2e). `AAuthTokenHolder.SelectForRequest` required +the carrier token's `account` to match the request's account. A person token +MUST NOT carry `account` (#person-tokens, L898), so every account-scoped request +fell back to the agent token and looped on `person_token_required` (Bookings, +protected Events). Person tokens now skip the account check; the resource token +and the auth token still bind the account. + +### [2026-09-28] [Phase 4] Person-token issuer trust separated from auth-token trust + +PROCEEDED (default: new `TrustedPersonServers` / `IsTrustedPersonServer`, +falling back to the auth-token issuer policy when unset). The verification +middleware checked person-token issuers against `TrustedAuthTokenIssuers`. In +four-party the AS issues auth tokens and the PS issues person tokens, so a +resource had to list the PS as an auth-token issuer too, which widens what it +accepts. The options are on `AAuthVerificationOptions`, +`AAuthResourcePipelineOptions` (`UseAAuth`) and `AAuthServerOptions` +(`RequireAAuth`). Wallet, Catalog and the Concierge `/wallet` branch use them. +Conformance `PersonTokenIssuerTrustIsIndependent` covers four-party, untrusted, +and the three-party fallback. + +### [2026-09-28] [Phase 10] Downstream `sub` is directed per resource + +RESOLVED. The downstream auth token in a call chain keeps the upstream `ps`, +but `sub` is directed at the downstream resource, and the issuer must not copy +the upstream `sub` (§Call Chaining, directed identifiers). The e2e specs assert +a directed downstream `sub`, not equality with the upstream one. + +### [2026-09-28] [Phase 10] GuidedTour and SampleApp migrated; step counts grew + +RESOLVED. Every PS-governed tour flow now shows the person-token leg, and plan +lengths grew to match: + +| Flow | Steps | +|---|---| +| Autonomous | 6 → 8 | +| Deferred | 9 → 11 | +| CallChain | 7/13 → 9/15 | +| Federated | 7/10 → 9/12 | +| RichRequests | 14 → 16 | +| Mission | 20 → 21 | +| MissionCallChain | 14 → 15 | +| SubAgent | 7 → 8 | + +The elevated `/trips/book` step presents the mission person token again rather +than stepping up from the `/trips` auth token; the spec allows either. Two e2e +checks became weaker because the echoed `agent` no longer exists: the +RichRequests account switch compares `ps`, and the sub-agent step 8 checks the +four-party result, while step 6 still binds the auth token `cnf` to the worker +key. The worker also fixed the MockPersonServer `/local/wallet/revoke` route: it +passed the agent id as the scope limit, a draft-10 argument order. + +### [2026-09-28] [Phase 9] `MissionHeaderHandler` renamed; ApiSurface gate restored + +RESOLVED. The handler only tags requests with `mission_s256`, so it is now +`MissionContextHandler`. The ApiSurface tool failed on the new +`AAuthTokenType.PersonToken` because `AAuthTokenType.cs` had no grouping rule. +It now maps to server contracts, and the API map is regenerated and current +(116 changed public-source files, +198/-117 declarations). + +### [2026-09-28] [Phase 10] Gates at `be7211c` + +RESOLVED. Release build: 0 errors, 0 warnings. Tests: core 1651, +Conformance 1124, R3 319, Events 75, all passing. The API map and docs inventory +are current on rerun, and the e2e typecheck is clean. Full Playwright run +(isolated `HOME`): 76 passed, 1 skipped. The skip is the Keycloak-gated +`federated-deferred` spec, which needs `KEYCLOAK_E2E=1`. + +## Deviations from plan + +None. Implementation has not started. The package follows the seven-document +draft-10 pattern without inheriting completed checkboxes, historical API counts, +defect verdicts or test results. Its upstream-question section is part of the +research, not a new specification or modification of vendored bytes. + +### [2026-09-25] [Phase 0] Research citations still point at WIP lines + +PROCEEDED (default: callouts now, full re-derivation in Phase 0). The v11 line +citations in `research.md`, the ledger and the maps refer to the WIP capture. +The plan's new citations were checked against the published files. Phase 0 now +includes re-deriving the rest before implementation. + +### [2026-09-28] [Phase 0] Merged `origin/main` instead of rebasing + +PROCEEDED (default: keep the merge). The plan said rebase. The branch owner +merged `origin/main` (`eef4175`) instead. The published branch history is +preserved, and the API baseline uses the release tag directly. + +### [2026-09-28] [Phase 1] Started before Phase 0 documentation re-derivation + +PROCEEDED (default: finish before Phase 2). Phase 1 depends only on published +vocabulary, which was read from the published text directly. Re-deriving the +research, ledger and map citations, and assigning each upgrade-checklist ID to a +phase in the ledger, are still open Phase 0 items. Phase 2 does not start until +they are done. + +### [2026-09-28] [Phase 2-6] Cutover landed as one commit + +PROCEEDED (default: accept). Person tokens, the presented-token pair, `ps`/`sub` +and the `mission_s256` reference change the same wire contracts at every role, +so Phases 2-6 could not be split and still build. The Events ticket binding and +later fixes are separate commits. The Phase 0 documentation re-derivation was +not finished first; it moves to Phase 10. + +### [2026-09-28] [Phase 10] GuidedTour and snippets still show draft-10 flows + +PROCEEDED (default: sweep in Phase 10). `TourSession.cs` was only changed to +compile; its steps and `CodeSnippets` still describe agent-to-auth flows. The +snippet-compilation, frozen-surface and reference-table tests fail until the +sweep, along with the SampleApp `Mission.razor` snippets, the Documents step 2 +snippet, and the v10 plan links to deleted files. + +### [2026-09-28] [Phase 2-6] Bugs found and fixed during the cutover + +RESOLVED. + +- **The PS fetched its own metadata over HTTP** to verify the tokens it had + issued. It now verifies them with its configured keys, via + `TokenVerifier.WithLocalIssuer`. +- **`AuthTokenResponse` left `StatusCode` null**, which broke callers checking + for 200 (federation, mission log). It now returns an explicit 200. +- **A Bookings call silently rebound an argument.** After the + `VerifyAuthTokenWithJwksAsync` signature change, the agent id bound to + `expectedMaxScope` with no compile error. The argument was removed. +- **The Calendar consent-deny fixture** did not trust the test PS. This only + surfaced once the resource verified a PS-issued person token before consent. +- **First requests with a revoked upstream token returned 403 `revoked`** + (Conformance `RevocationLifecycleTests`). Fixed in "Revoked source tokens on a + first request" above. + +### [2026-09-28] [Phase 3, 5-10] Post-cutover items folded into the plan + +PROCEEDED (default: assign each to its owning phase). A gap review after the +revocation cutover found 12 remaining items. Eleven are now responsibilities +and Definition of Done boxes in their owning phases: + +- Phase 3: deferred-approval expiry (item 8); MockPersonServer `person_tokens` and a resource-naming proposal (10). +- Phase 5: agent reuse of `Mission.PersonTokens` (11); MockAgentProvider `401` Signature-Error (4). +- Phase 6: agent-person binding revocation at step 4 (3). +- Phase 7: revocation digest coverage at every endpoint (2); per-issuer bounds and `rate_limited` (5); deferred `202` revocation (6); AS presentation records (9). +- Phase 8: R3 draft-11 wire names (1); event dedup on `(iss, jti)` (7). +- Phase 10: Wallet `DirectAs` label (12). + +AAuth issue #199 is excluded and stays an open upstream question. Boxes were +ticked only where a named, passing test backs them; 29 are ticked and 57 are +open. The plan gained a closing-out section for when every box is ticked. + +### [2026-09-28] [Phase 3, 5-10] Correction: all 12 items are in the plan + +CORRECTED. The previous entry says "Eleven". The gap review listed 12 items, +with AAuth issue #199 listed separately, and all 12 were folded in as the list +above shows. No plan change was needed. + +### [2026-09-28] [Phase 8] R3 draft-11 wire format (post-cutover item 1) + +RESOLVED in four commits: + +- `368aa85`: `r3_conditional` is now `r3_per_call`. The public names follow: + `PerCallClaim`, `AuthTokenClaims.PerCall`, `R3EnforcementDecision.PerCall`, + `R3EnforcementDecisionKind.PerCall` and `IsPerCallOperation`. The R3 sample + config key is now `PerCallOperations`. +- `f849825`: R3 documents and proposals no longer carry `version`. The reader is + tolerant, so a `version` member sent by a peer is ignored. +- `88c0882`: the OpenAPI Gateway vocabulary is removed. Catalog now publishes one + merged OpenAPI definition that renames the colliding `list` operations to + `listDestinations` and `listExperiences` (R3 #operation-identifier-scope). The + `/catalog-gateway` route name is kept so links stay stable. +- `ad40801`: the core SDK accepts `per-call` as an `access_mode`. The new + `R3AccessAnnotations` writes and reads the OpenAPI/AsyncAPI and MCP encodings + and applies the spec rules: `session-token` is rejected, a budget flag means + at least `auth-token`, and annotations are sparse. OData is left to + `$metadata` XML; gRPC, GraphQL and WSDL have no encoding. Bookings marks + `confirmReservation` as `per-call`. + +DECISION: a reader ignores an unrecognized or `session-token` annotation +value, the same way it treats an unknown `access_mode`. Only the writer +rejects them. + +ISSUE: my first draft of the Catalog snippet opened with a `//` comment. That +broke `SnippetCompilationTests`, which classifies a snippet as a member by +checking `StartsWith("public static")`. I dropped the comment rather than +change the harness. + +Evidence: `Draft11WireNames_PerCallClaimAndNoDocumentVersion`, +`R3Draft11FixtureTests` (the spec's R3 document example pins +`DB_rCyQ4eWAg8LYhNyyKl-Ze3_hmuGK3zf-AnoK4WOU`; the spec's annotation examples +read as `per-call` plus budget), `MergedDefinition_RenamedCollidingOperationsAreDistinct`, +`MalformedOrRemovedDiscoveryFails`, `OpenApi_AnnotatesOnlyConfirmationAsPerCall` +and `EmitsEachAccessMode(per-call)`. Gates: R3 tests 323, Conformance 1161, +AAuth.Tests 1658, Events 75; the API map and docs inventory are current; e2e +76 passed, 1 skipped (Keycloak), including 6/6 Catalog. + +Not done in this item: atomic single-use per-call grants, per-document PS +readership, and release gating (the `result` member). These stay open under +their own Phase 8 boxes. + +### [2026-09-28] [Phase 7] Revocation body coverage at every endpoint (post-cutover item 2) + +RESOLVED. Before this change, only hosts using `MapAAuthIssuerRevocation` (the +PS, the AS and R3) demanded `content-type` and `content-digest`. A resource that +mapped `MapAAuthRevocationEndpoint` behind its own `UseAAuth` verifier accepted +a revocation whose signature covered neither (L2672: "at a resource's +revocation endpoint as much as a PS's or an AS's"). + +Fix: + +- `AAuthVerificationResult.CoveredComponents` exposes the components the + verified signature covers. +- The shared revocation handler now answers `401 Signature-Error: + invalid_input` with `required_input` when either component is missing. This + holds whatever the host verifier was configured to require. +- The middleware already rejects a covered digest that does not match the body. + +Every SDK revocation route goes through that handler: PS, AS and R3 via +`MapAAuthIssuerRevocation`, resources directly. + +Evidence: `Revocation_RequiresBodyCoverageAtEveryRecipient` (the host verifier +has no required components; the uncovered request gets 401 and the token is not +revoked) and `Revocation_RejectsTamperedBody`. The test helper now signs as +`RevocationClient` does. Conformance 1163 passed. + +### [2026-09-28] [Phase 8] Event tokens carry `jti`; dedup on `(iss, jti)` (post-cutover item 7) + +RESOLVED. The gap was wider than the sample key. The SDK issued event tokens +with no `jti`, although Events -11 lists `jti` among the required payload claims +(L363). Two tests encoded the old behaviour: + +- `EventWithoutJtiOrCnfVerifies` asserted that no `jti` was present; +- `AgentContextAndLiteralIssuerEidDedupPersist` asserted that a second event on + the same `eid` was dropped. + +The docs also said "No required per-event `jti` was added." Deduplicating on +`eid` drops every event after the first on an unlimited subscription. + +Fix: + +- `EventTokenBuilder.Jti` defaults to a fresh value, and the builder emits it. +- `EventsTokens.Verify` requires `jti` on event tokens. +- `EventEnvelope` carries `Jti`, and the AP endpoint and `EventReceiver` fill it + in. +- The sample AP receipt is now a hash of `(iss, jti)` rather than of the token. + A re-signed copy is the same delivery, costs no quota, and a different body is + still 400. +- The agent table `received_events` is keyed `(issuer, jti)`. It is a new table + name so that existing sample databases pick up the new key. + +Evidence: + +- `EventWithJtiAndWithoutCnfVerifies`, `EventWithoutJtiFails` and + `InvalidEventClaimsFail(jti, ...)`; +- `BuilderIssuesDistinctJtiPerEvent`; +- `AgentContextPersistsAndEventsDedupeOnIssuerAndJti` (a re-signed copy is + ignored; a second event on the same `eid` is recorded); +- `ProviderAcceptsEachJtiOnceWithoutSpendingQuotaOnDuplicates`; +- `HttpStatusQuotaUnlimitedUnknownAndWrongAudience`, where a true retry resends + the same token and a new event on a single-use subscription is 429. + +The ticket-key half of the box was already covered by +`TicketRedemptionIsAtomicAndPreservesAccount`. Events tests 80 passed; Events +e2e 4/4. + +### [2026-09-28] [Phase 6] Agent-person binding half of step 4 (post-cutover item 3) + +RESOLVED. L1835 step 4 requires the PS to answer `revoked_upstream_token` +when it has revoked the calling agent's agent token or its binding to the +person. + +DECISION: the binding is an entry in the PS token inventory, +`AgentPersonBinding.Key(ps, agentIss, agentSub)`. It is keyed by the agent +identity, not by an agent-token `jti`, so it survives agent-token refresh. +Every token the PS issues directly to an agent is recorded as a grant of that +binding: direct token requests and mission `person_tokens`. Chained requests +are not, because L2918 says a chained request neither uses nor establishes a +binding. + +Revoking the binding with `AgentPersonBinding.RevokeAsync` has three effects +through the existing ancestor check: + +- any upstream token issued under it becomes a revoked ancestor, so a chained + request gets `400 revoked_upstream_token`; +- the agent's own requests fail source registration (`401 revoked_jwt`), even + with a refreshed agent token; +- other agents are unaffected. + +DECISION: the binding entry uses a fixed far expiry. A binding has no natural +expiry, and `RegisterAsync` rejects an existing key registered with a different +expiry. + +Not done: revoking a binding does not cascade downstream revocation calls. +Only the rejection is a MUST. + +ISSUE: the first test registered `IJtiStore` in the PS's DI container. That +switched on PS request replay detection, and the harness resends identical +signatures, so 7 unrelated tests failed. Hosts now pass the inventory through +the new `AAuthPersonServerOptions.TokenInventory`, and +`MapAAuthIssuerRevocation` takes an optional `inventory`. + +Evidence: `UpstreamFromRevokedBinding_IsRevokedUpstreamToken` (three- and +four-party). The agent token is not revoked; the chained request is `400 +revoked_upstream_token`; the refreshed agent token is refused; another agent is +unaffected. Conformance 1165 passed. The call-chaining docs have a +compile-checked snippet. + +### [2026-09-28] [Phase 5] MockAgentProvider refresh signature failures (post-cutover item 4) + +RESOLVED. The sample AP's `/refresh` answered most signature failures with +`400 invalid_request`, or with a 401 that had no `Signature-Error`. Every +signature failure is now `401` with `Signature-Error`: + +- a missing or unparseable `Signature-Key`, `Signature-Input` or `Signature` + is `invalid_input`, with `required_input`; +- a scheme other than hwk or jkt-jwt is `unsupported_scheme`, with + `Accept-Signature-Scheme: hwk, jkt-jwt`; +- an hwk header without its key is `invalid_key`; +- a naming-JWT or HTTP signature failure carries the verifier's code. + +An unknown enrolled key stays `400 invalid_grant`, because it is not a +signature failure. + +Evidence: `MockAgentProviderRefreshTests` (unsigned, unsupported scheme, +tampered signature). The tests isolate the AP's key directory and databases: +with the defaults, a stale `~/.aauth/ap-keys` key from an earlier release made +the host fail to start. + +### [2026-09-28] [Phase 3] Deferred mission approval keeps `expires_at` (post-cutover item 8) + +RESOLVED. When `IMissionApprover` returned `Defer()` with an `ExpiresAt`, the +parked `DeferredConsent` dropped it, so the mission approved after the user +decided had no expiry. `DeferredConsent.MissionExpiresAt` now carries the +approver's value, and the completion passes it to `CompleteMissionAsync`. + +Evidence: `Mission_Prompt_ApprovalKeepsApproverExpiry`. The mission parsed from +the completed poll has the approver's `expires_at`. Governance mapper tests: 37 +passed. + +### [2026-09-28] [Phase 10] Wallet `DirectAs` renamed (post-cutover item 12) + +RESOLVED. Draft-11 has no direct agent-to-AS path, so the Wallet flow is now +`WalletFlow.AsGrantChaining` (UI label "Chaining an AS-issued grant"), with +`WalletScenarioCode.AsGrantChaining`. The e2e flow names, the docs and the +three READMEs follow. The wallet guide no longer says "The sample still labels +this flow `DirectAs`". + +Evidence: Wallet e2e 9/9 passed, the snippet tests pass, and a grep finds no +`DirectAs` or "direct-AS" in the samples, docs or tests. + +### [2026-09-28] [Phase 7] PS revokes only where a person token was presented (post-cutover item 9) + +RESOLVED. The SDK cascade already works this way: an auth token an AS issued +against a PS person token is recorded as that token's grant. Revocation +revokes the person token at each such AS once, and never at an AS with no +record. + +The MockPersonServer demo route `/local/wallet/revoke` revoked at every +configured Access Server instead. The sample now passes `TokenInventory` and +revokes only at the trusted Access Servers recorded as issuers of the person +token's grants. + +Evidence: + +- the SDK path: `ProviderRevoke_BlocksSourceAndCascadesExactIssuedOrProvidedGrants` + and `UpstreamRevocationCascadesToDownstreamGrant` (federated), which assert + exactly the AS revocations; +- the sample route: Wallet e2e Revocation (9/9). The PS revocation's result + names the AS and its downstream Wallet. That result can only come from the + recorded presentation. + +### [2026-09-29] [Phase 7] Per-issuer revocation bounds (post-cutover item 5) + +RESOLVED. L2745: a recipient that accepts any verified issuer SHOULD bound what +one issuer can hold, in entries and in rate, and answer `rate_limited` beyond +either (429, `Retry-After` REQUIRED, L2740). `AAuthRevocationOptions.Limits` +(`RevocationLimits`) is on by default: 10,000 unexpired entries and 600 +requests a minute per issuer; `null` turns it off. + +The check runs after body validation and before anything is recorded: + +- an entry counts from acceptance until its `exp` plus clock skew; +- a repeat of a held `jti` is not a new entry; +- `Retry-After` is the time until the oldest request leaves the window, or + until the earliest entry expires. + +DECISION: bounds apply on every mapped endpoint, not only under +`AAuthTrust.Any`, because an accepted-issuer list does not bound volume either. + +Not done: the limiter is in memory per endpoint instance. A scaled-out host +needs a shared limiter; this is recorded as a deployment limit, not a gap. + +Evidence: `Revocation_EntryBound_IsRateLimited` and +`Revocation_RateBound_IsRateLimited` (429 `rate_limited` with `Retry-After`, +and the token is not recorded). Conformance 1168 passed. + +### [2026-09-29] [Phase 7] Deferred `202` revocation (post-cutover item 6) + +RESOLVED. Revocation follows L2728-L2730. When the cascade outlasts +`AAuthRevocationOptions.DeferAfter` (default 20 s, which a caller's +`Prefer: wait` can shorten), the recipient answers `202` with: + +- `Location: {path}/pending/{id}`; +- `Retry-After: 0` and `Cache-Control: no-store`; +- a `{"status":"pending"}` body and no `AAuth-Requirement`. + +The poll is a bodyless signed `GET`. Only the verified identity that made the +revocation gets an answer; any other gets `404`. The terminal answer is what +the synchronous path would have returned. A recipient with nothing downstream +never answers `202`. The cascade runs on the host's stopping token, not on the +aborted request. + +`RevocationClient` now follows a `202`. It polls the same-origin pending URL +under its own signing identity, with `Prefer: wait`, until a terminal answer or +`MaxPollDuration` (2 min). After that the downstream is +`revocation_unavailable`. + +BUG found and fixed: the PS and AS agent-verification branches excluded only +the exact revocation path, so a poll of `/revoke/pending/{id}` was verified as +an agent request and got `unsupported_scheme`. Both now exclude by path +prefix, and `MapAAuthIssuerRevocation` adds a verification branch for the +pending route that requires no body components. + +Evidence: + +- `Revocation_SlowCascade_DefersAndOnlyTheRevokerPolls`: 202 headers; the + agent identity gets 404; `Prefer: wait=0` still gets 202; the terminal 200 + carries `downstream`; +- `Revocation_NothingDownstream_NeverDefers`; +- `RevocationClient_FollowsDeferredRecipient`; +- `SlowDownstream_PersonServerDefersAndCompletesOnPoll`, end to end through the + PS. + +Conformance 1172 passed. + +### [2026-09-29] [Phase 5] Agents reuse mission person tokens (post-cutover item 11) + +RESOLVED. `MissionContextHandler` now also sets +`AAuthRequestOptions.MissionPersonTokens` from `Mission.PersonTokens`. On a +`person-token` challenge, `ChallengeHandler` presents the approval's token for +the resource instead of calling `/person` when all of these hold: + +- the request is not chained; +- the token is a person token whose `iss` is the PS in use and whose `aud` is + the resource; +- its `mission_s256` equals the request's mission; +- its `cnf.jwk` is the signing key; +- it has more than a minute left. + +Any mismatch falls back to `/person`. A reused token the resource then refuses +is not offered again, and the next challenge calls `/person`. The token's +signature is left to the resource; the agent received it over its signed PS +channel. + +Evidence: `MissionPersonToken_ReusedOnlyWhenItMatches`. A match makes no PS +call; resource, mission, key and expiry mismatches each fall back. + +### [2026-09-29] [Phase 3, 10] Sample mission approvals carry `person_tokens` (post-cutover item 10) + +RESOLVED. MockPersonServer's own `/mission` and its parked approval now return +`person_tokens`. The SDK gains `HttpContext.IssueMissionPersonTokensAsync`, so +a host that maps its own mission endpoint gets the tokens with one call instead +of building `MissionPersonTokenRequest` by hand. `MapAAuthGovernance` uses the +same helper, which removed a private duplicate. + +Both apps now propose missions naming the Trips resource in `resources`: + +- GuidedTour's raw proposal body and its narrative; +- SampleApp's proposal. SampleApp also presents the returned person token + instead of calling `/person`, falling back when it is absent; its code sample + shows the same. + +Evidence: `MissionNamingResources_ApprovalCarriesPersonTokens` against the real +MockPersonServer (one token keyed by the resource, with the mission's +`mission_s256`, `iss` and `aud`). + +The first mission e2e run failed: the GuidedTour proposal got 400, because +`GovernanceEndpoints.ParseMissionProposal` validated `resources` against the +production (HTTPS-only) policy and the tour names `http://localhost:5002`. The +parser now takes an optional egress policy. `MapAAuthGovernance` passes its +`EgressPolicy`; MockPersonServer passes its sample policy. The default stays +HTTPS-only. Evidence: `ParseMissionProposal_LoopbackResourcesNeedDevelopmentPolicy`; +Playwright `--grep "[Mm]ission"`: 8 passed. + +### [2026-09-29] [Phase 3] Person-token lifetime bounds and request fields + +RESOLVED. Two DoD boxes lacked a `/person` test. The existing cited tests +covered `/token` and auth tokens, not person tokens. + +- `PersonTokenEndpoint_LifetimeIsCappedByEveryBound`: the issued `exp` is capped + by the one-hour default, the agent token, the upstream token and the mission, + one case each. +- `PersonTokenRequest_CapabilitiesAndLoginHintReachAsserter`: `capabilities` and + `login_hint` from the `/person` body reach the person asserter. + +### [2026-09-29] [Phase 3] Partial resource approval + +RESOLVED (SDK change). A PS could not approve only some proposed resources. +`MissionApprovalDecision.ApprovedResources` (and +`DeferredConsent.MissionApprovedResources` for the parked path) now set +`approved_resources`. The governance pipeline keeps only the intersection with +`proposal.resources` and issues person tokens only for those. Leaving it unset +approves every proposed resource, as before. + +Evidence: `PartialResourceApproval_LimitsApprovedResourcesAndPersonTokens`, sync +and deferred. An unproposed resource in the decision is dropped. That +capabilities stay outside the mission hash is covered by +`MissionModelTests.FromApprovalResponse_ParsesSessionMembers`. + +Gates: build 0 warnings; AAuth.Tests 1667, Conformance 1180, R3 323, Events 80; +API and docs maps refreshed; snippet and link tests 108. + +### [2026-09-29] [Phase 3] Mission store keeps terminal state and expiry + +RESOLVED (SDK fix). `InMemoryMissionStore` broke two §Mission Management rules +("A terminated mission MUST NOT return to `active`", L1516): + +- `SaveAsync` overwrote a stored mission, so re-saving a terminated mission + revived it and could drop or extend `ExpiresAt`; +- `SetStateAsync` read then wrote, so a concurrent `Active` could overwrite + `Terminated`, and `SetStateAsync(Active)` reopened a terminated mission. + +`SaveAsync` now merges atomically: terminated stays terminated and the +earliest expiry wins. `SetStateAsync` uses compare-and-swap and ignores any +transition out of `Terminated`. `IMissionStore` documents both rules for +custom stores. + +Evidence: `MissionStore_TerminatedIsFinal`, +`MissionStore_ReplacementKeepsEarliestExpiry` and +`MissionStore_ConcurrentMutationKeepsTerminal` (50 rounds of 16 racing +transitions and saves). + +### [2026-09-29] [Phase 3] Accepted updates keep exact bytes + +RESOLVED (test only). §Mission Update (L1471, L1479) returns `s256` over the +update's persisted bytes and leaves the mission unchanged. The existing test +only checked that `s256` was non-empty. `MissionUpdate_OwnedMissionOnly` now +checks: + +- the returned `s256` equals `Mission.ComputeS256` of the logged entry's bytes; +- the entry retains the description; +- the stored mission keeps its blob and `Active` state under the same + `mission_s256`. + +Conformance 1183 passed. + +### [2026-09-29] [Phase 4] Wire tests for the prerequisite and step-up legs + +RESOLVED (test only). The exchange legs already had wire tests: + +- agent to PS: `UpstreamTokenIncludedInPostBody` checks `resource_token`, + `presented_token` and `upstream_token`; +- PS to AS: `FederateAsync_ReturnsVerifiedAuthToken_OnSuccess` checks + `resource_token` and `agent_token`; `FederateAsync_IncludesUpstreamToken_WhenProvided` + and `FederateAsync_ForwardsChildToken` check `upstream_token`, + `subagent_token` and `presented_token`. + +The agent side of the prerequisite and of step-up (L641) had no wire test. +`PrerequisiteAndStepUp_WireBodies` covers both: + +- **prerequisite:** an agent-token request is answered `requirement=person-token`. + The agent sends exactly one `/person` POST, naming the resource and carrying + no resource or presented token; +- **step-up:** an auth-token request is answered `requirement=auth-token` with a + resource token naming that auth token's `jti`. The agent sends exactly one + `/token` POST, with that resource token and the auth token itself as + `presented_token`. + +The resource side of step-up is covered by +`Enforcement_PerCallChallengeResultEmitsAAuthRequirementWithProposalResourceToken` +(`presented_jti` equals the verified auth token's `jti`). + +### [2026-09-29] [Phase 4] Identity overwrite fails at PS and at AS + +RESOLVED (test only). Stripping and substitution had tests at both servers. +Overwritten identity fields did not: + +- PS: only `sub`, `presented_jti` and `ps` were tested, through MockPersonServer; +- AS: only `ps`, `subject` and the presented key were tested. + +Each server now has its own theory. A resource token with one binding +overwritten (`ps`, `sub`, `presented_jti`, `mission_s256`, `tenant`, +`agent_jkt`) is rejected `invalid_resource_token`: + +- PS: `TokenRequest_OverwrittenIdentity_Rejected` also checks the asserter was + never called; +- AS: `AsRejectsResourceTokenNotNamingTheSigningPsOrPresentedToken` also checks + the access policy was never called. + +Stripping is covered by `TokenRequest_MissingPresentedToken_Rejected` (PS) and +`AsRequiresAgentResourceAndPresentedTokens` (AS). Substitution is covered by +`TokenRequest_MismatchedPresentedToken_Rejected` (PS) and the AS +`presented-key` case. + +### [2026-09-29] [Phase 4] PS and AS require body coverage + +RESOLVED (SDK fix). §Covered Components (L2211) requires every body-bearing +request to a PS or AS to cover `content-type` and `content-digest`. The SDK +enforced this only at revocation endpoints, and its own agent and PS clients did +not cover a body. Neither side followed the rule. + +Changes: + +- **Signer:** `AAuthSigningHandler.SignAsync` now covers `content-type` and + `content-digest` on every request with a body, and computes the digest itself. + It can't tell a PS or AS from a resource, and covering more is always + accepted. Callers of the synchronous `Sign` are unchanged. +- **Verifier:** new `AAuthVerificationOptions.RequireBodyCoverage`. When the + request has a body and doesn't cover both, verification answers `401 + invalid_input` naming them in `required_input`, before replay recording or + any handler. +- **Servers:** the option is on for the `MapAAuthPersonServer` branch + (initial, pending and governance paths), the `MapAAuthAccessServer` branch, + and R3 `VerifyFetcherAsync` (the R3 AS token endpoint). +- **Governance:** `MapAAuthGovernance` handlers also check coverage themselves, + so a host that mounts governance without the PS branch still enforces it. +- **Sample:** MockAgentProvider `/refresh` now passes header fields to + `AAuthVerifier.Verify`. Without them it couldn't resolve the newly covered + components, and the first full e2e run failed two flows (`inbox`, `jkt-jwt`). + Covered by `BodyCoveredRefresh_VerifiesSignature`. + +Evidence. Each test also checks that no policy, consent or pending state was +touched: + +- PS: `PsBody_UncoveredOrTampered_FailsBeforeAsserter` (`/token`, `/person`; + uncovered gives `invalid_input`, a body swapped after signing gives + `invalid_signature`) and `PsPendingBodyWithoutCoverageFailsBeforePendingState`; +- AS: `AsBodyUncoveredOrTampered_FailsBeforePolicyOrPendingState`; +- governance: `UncoveredBody_RejectedBeforeSeams` (`/mission`, mission action, + `/permission`, `/audit`, `/mission-interaction`); +- R3 AS: `UncoveredOrTamperedBodyFailsBeforeDocumentPolicyOrAudit`. + +Shared test helpers `UncoveredBodySigner` and `BodySwapHandler` live in +`tests/TestEgress.cs`. The revocation coverage tests now use the former, since +the signer would otherwise cover the body. Docs: `signing-modes/overview.md` +describes the automatic coverage. The stale "Deferred `202` and `rate_limited` +are not implemented" sentence in `replay-detection.md` is gone (items 5 and 6 +implemented both). + +Full Playwright run after the fix: 74 passed, 1 skipped; the two failures +above pass on rerun. + +### [2026-09-29] [Phase 4] AS timeouts are not local cancellation + +RESOLVED (SDK fix). The PS mapped every `OperationCanceledException` from +federation to `408 expired`. An AS call that timed out in `HttpClient` (also an +`OperationCanceledException`) was therefore reported as a local expiry. Only the +PS's own cancellation (agent `DELETE` or pending expiry) is `expired` now; an AS +timeout is `502 as_unreachable`, like any other AS failure. + +Evidence: `AsOutcomesMapSeparatelyFromLocalCancellation`: + +- AS `deny` gives `403 denied`; +- an unstructured AS `502`, an unverifiable AS token, and a client timeout each + give `502 as_unreachable`. + +Local cancellation stays covered by `ProductionPsRelaysClarificationAndResumes` +(`cancel`) and `ClarificationDeadlineTerminatesBothPendingRequests` (`408`). + +Expiry: agent, parent and upstream bounds on immediate and deferred issuance +are covered by `DirectAndDeferred_UseOriginalAgentAndParentBounds`, +`Deferred_RejectsOriginalExpiryDespiteFreshPollCarrier`, +`Direct_RejectsExpiredParentOrChild` and +`UpstreamExpiry_IsPreservedThroughDeferredIssuance`. The mission bound had no +auth-token test; `AuthToken_IsCappedByMissionExpiry` covers immediate and +deferred (clarification) issuance. + +Gates: AAuth.Tests 1670, Conformance 1211, R3 325, Events 80; API and docs maps +refreshed. + +### [2026-09-29] [Phase 4] Consent attributes agent-asserted content + +RESOLVED (SDK and sample). §Consent Presentation (L1031, L1039) requires a +PS to visually separate resource-asserted from agent-asserted content and to +attribute the latter to the agent, and to convey the same distinction to a +supervision server. The PS ignored `justification`, `platform` and `device`, +so no hook or consent page could show them. `MissionTokenConsentContext.Prompt` +was also mis-documented as the justification (it is OIDC `prompt`). + +Changes: + +- **New type:** public record `AgentAssertedContent` (`Justification`, + `Platform`, `Device`). +- **Parsing:** the PS reads these from `/person` and `/token` bodies. A + non-string value gets `400 invalid_request` before the asserter runs. +- **Hooks:** `IdentityAssertionRequest.AgentAsserted` and + `MissionTokenConsentContext.AgentAsserted` carry the content; + `PersonPendingEntry.AgentAsserted` keeps it for re-review. +- **Docs comments:** `ResourceContext` is now documented as resource-asserted. +- **Sample:** the MockPersonServer consent page renders a "From the resource" + panel and a separately styled "The agent says (not verified)" panel, with + HTML-encoded values. Its approve handler forwards `AgentAsserted`. +- **Docs:** `server/token-issuance.md` gains a resource-asserted versus + agent-asserted table. + +Evidence: + +- `AgentAssertedContent_ReachesAsserterApartFromResourceContext` (`/token`, + `/person`); +- `AgentAssertedContent_NonString_Rejected` (each member); +- `AgentAssertedContent_ReachesMissionSupervisor` (gate and post-clarification + review); +- `Interaction_ConsentPage_AttributesAgentAssertedContentApartFromResource`: + separate sections, encoded `"; + + private const string Styles = + "*{box-sizing:border-box}body{font-family:system-ui,sans-serif;margin:0;background:#f8fafc;color:#1e293b;line-height:1.5}" + + "main{max-width:60rem;margin:0 auto;padding:1.5rem 1rem 3rem}main.narrow{max-width:34rem}" + + "header{display:flex;align-items:center;justify-content:space-between;gap:1rem;flex-wrap:wrap}" + + ".badge{display:inline-flex;align-items:center;gap:.5rem;background:#1d4ed8;color:#fff;padding:.4rem .8rem;" + + "border-radius:.4rem;font-weight:600;letter-spacing:.02em}.badge .dot{width:.6rem;height:.6rem;border-radius:50%;background:#bfdbfe}" + + "h1{font-size:1.4rem;margin:1.25rem 0 .25rem}h2{font-size:1.05rem;margin:1.75rem 0 .6rem;display:flex;align-items:center;gap:.5rem}" + + ".muted{color:#64748b;font-size:.9rem}.empty{color:#94a3b8;font-style:italic}" + + ".count{background:#1d4ed8;color:#fff;border-radius:999px;padding:0 .55rem;font-size:.8rem}" + + ".toolbar{display:flex;align-items:center;gap:.4rem;margin-top:1rem;flex-wrap:wrap}.toolbar>span:first-child{color:#475569;font-size:.9rem}" + + ".toolbar button{border:1px solid #cbd5e1;background:#fff;border-radius:999px;padding:.2rem .8rem;cursor:pointer;font:inherit;font-size:.85rem}" + + ".toolbar button[aria-pressed=true]{background:#1d4ed8;border-color:#1d4ed8;color:#fff}#status{margin-left:auto}" + + ".group{margin:.75rem 0}.group-h{font-weight:600;color:#334155;margin:.25rem 0 .4rem;display:flex;gap:.5rem;align-items:baseline;flex-wrap:wrap}" + + ".group-h a{font-weight:400;font-size:.85rem}" + + ".card{background:#fff;border:1px solid #e2e8f0;border-radius:.6rem;padding:.85rem 1rem;margin:.5rem 0;" + + "display:grid;grid-template-columns:1fr auto;gap:.5rem 1rem;align-items:start}" + + ".card.highlight{border-color:#f59e0b;box-shadow:0 0 0 3px #fde68a}" + + ".kind{font-weight:600}.meta{display:grid;grid-template-columns:max-content 1fr;gap:.1rem .75rem;margin-top:.35rem;font-size:.9rem}" + + ".meta dt{color:#64748b}.meta dd{margin:0;overflow-wrap:anywhere}code{font-size:.85em;background:#f1f5f9;padding:0 .25rem;border-radius:.25rem}" + + ".asserted{grid-column:1/-1;background:#fffbeb;border:1px dashed #f59e0b;border-radius:.4rem;padding:.4rem .7rem;font-size:.85rem}" + + ".asserted blockquote{margin:.2rem 0;font-style:italic;white-space:pre-wrap}" + + ".actions{display:flex;gap:.5rem;flex-wrap:wrap;justify-content:flex-end}" + + "button.approve,button.deny,button.primary{padding:.45rem 1rem;font:inherit;cursor:pointer;border-radius:.35rem;border:1px solid}" + + "button.approve,button.primary{background:#16a34a;border-color:#15803d;color:#fff}button.deny{background:#fff;border-color:#dc2626;color:#b91c1c}" + + "button:disabled{opacity:.6;cursor:progress}button:focus-visible,a:focus-visible{outline:3px solid #93c5fd;outline-offset:2px}" + + ".pill{display:inline-block;border-radius:999px;padding:0 .6rem;font-size:.8rem;font-weight:600}" + + ".s-Approved,.s-Delivered{background:#dcfce7;color:#166534}.s-Denied{background:#fee2e2;color:#991b1b}" + + ".s-Expired,.s-Withdrawn{background:#e2e8f0;color:#475569}.s-Pending{background:#dbeafe;color:#1e40af}" + + ".note{font-size:.85rem;color:#64748b}.error{color:#b91c1c;font-size:.9rem;margin:.5rem 0 0}.error:empty{display:none}" + + ".info{background:#eff6ff;border:1px solid #bfdbfe;color:#1e3a8a;border-radius:.4rem;padding:.5rem .8rem;font-size:.9rem;margin:.75rem 0 0}" + + "@media (max-width:40rem){.card{grid-template-columns:1fr}.actions{justify-content:flex-start}}"; + + private const string Script = """ + const csrf = document.querySelector('meta[name=csrf]').content; + const code = new URLSearchParams(location.search).get('code'); + let group = 'none', highlighted = false, busy = false; + const decidedHere = new Set(); + const labels = { + Token: 'Access to a resource', PersonToken: 'Share your identity with a resource', + MissionToken: 'Extra access under a mission', MissionCreation: 'Start a new mission', + Permission: 'Run a tool under a mission', FederatedConsent: 'Access through an Access Server', + AccessServerInteraction: 'Sign-in at an Access Server' }; + const statusLabels = { Delivered: 'Approved · agent has it', Withdrawn: 'Withdrawn by agent' }; + const el = (tag, cls, text) => { const e = document.createElement(tag); if (cls) e.className = cls; if (text != null) e.textContent = text; return e; }; + const when = iso => iso ? new Date(iso).toLocaleString() : ''; + function row(dl, label, value, asCode) { + if (value == null || value === '') return; + dl.append(el('dt', null, label)); + const dd = el('dd'); dd.append(asCode ? el('code', null, value) : document.createTextNode(value)); dl.append(dd); + } + function card(r, highlight) { + const c = el('article', 'card' + (highlight ? ' highlight' : '')); + c.dataset.id = r.id; c.dataset.agent = r.agent; + if (r.resource) c.dataset.resource = r.resource; + if (r.scope) c.dataset.scope = r.scope; + if (r.mission_s256) c.dataset.mission = r.mission_s256; + const body = el('div'); + const title = el('div'); title.append(el('span', 'kind', labels[r.kind] || r.kind)); + if (r.status !== 'Pending') title.append(' ', el('span', 'pill s-' + r.status, statusLabels[r.status] || r.status)); + body.append(title); + const dl = el('dl', 'meta'); + row(dl, 'Agent', r.agent, true); row(dl, 'Resource', r.resource, true); row(dl, 'Scope', r.scope, true); + row(dl, 'Account', r.account, true); row(dl, 'Tool', r.action, true); if (group !== 'mission') row(dl, 'Mission', r.mission); row(dl, 'Tools', r.tools, true); + if (r.mission_s256 && group !== 'mission') row(dl, 'Mission s256', r.mission_s256, true); + row(dl, 'Requested', when(r.created_at)); + if (r.status === 'Pending') row(dl, 'Expires', when(r.expires_at)); + if (r.status !== 'Pending') row(dl, 'Decided', [when(r.decided_at), r.decided_by && 'via ' + r.decided_by.toLowerCase()].filter(Boolean).join(' ')); + body.append(dl); c.append(body); + const actions = el('div', 'actions'); + if (r.decidable) { + const approve = el('button', 'approve', 'Approve'); approve.type = 'button'; + const deny = el('button', 'deny', 'Deny'); deny.type = 'button'; + approve.addEventListener('click', () => decide(r.id, 'approve', c)); + deny.addEventListener('click', () => decide(r.id, 'deny', c)); + actions.append(approve, deny); + } else if (r.external_url && r.status === 'Pending') { + const a = el('a', null, 'Complete at the Access Server'); a.href = r.external_url; a.target = '_blank'; a.rel = 'noopener noreferrer'; + actions.append(a); + } else if (r.status === 'Pending') { + actions.append(el('span', 'note', 'Waiting for the agent')); + } + c.append(actions); + if (r.agent_asserted) { + const a = el('div', 'asserted'); a.append(el('strong', null, 'The agent says (not verified)')); + if (r.agent_asserted.justification) a.append(el('blockquote', null, r.agent_asserted.justification)); + const dl2 = el('dl', 'meta'); row(dl2, 'Platform', r.agent_asserted.platform); row(dl2, 'Device', r.agent_asserted.device); + if (dl2.childElementCount) a.append(dl2); + c.append(a); + } + return c; + } + function render(target, groups, empty, highlight) { + const root = document.getElementById(target); root.replaceChildren(); + if (!groups.some(g => g.records.length)) { root.append(el('p', 'empty', empty)); return; } + for (const g of groups) { + const wrap = el('div', 'group'); + if (g.label) { + const h = el('div', 'group-h'); h.append(el('span', null, g.label)); + if (g.mission_s256) { const a = el('a', null, 'Mission log'); a.href = '/admin/mission-log/' + encodeURIComponent(g.mission_s256); a.target = '_blank'; a.rel = 'noopener'; h.append(a); } + wrap.append(h); + } + for (const r of g.records) wrap.append(card(r, r.id === highlight && r.status === 'Pending')); + root.append(wrap); + } + } + async function refresh() { + if (busy) return; + const query = new URLSearchParams({ group }); if (code) query.set('code', code); + try { + const response = await fetch('/dashboard/requests?' + query, { credentials: 'same-origin', cache: 'no-store' }); + if (response.status === 401) { location.reload(); return; } + const data = await response.json(); + const pending = data.pending.reduce((n, g) => n + g.records.length, 0); + document.getElementById('pending-count').textContent = pending; + document.title = (pending ? '(' + pending + ') ' : '') + 'Consent dashboard — Person Server'; + render('pending', data.pending, 'No pending requests.', data.highlight); + render('history', data.history, 'Nothing decided yet.', data.highlight); + document.getElementById('settled').hidden = !data.settled || decidedHere.has(data.highlight); + document.getElementById('status').textContent = 'Updated ' + new Date().toLocaleTimeString(); + if (data.highlight && !highlighted) { + highlighted = true; + document.querySelector('.card.highlight')?.scrollIntoView({ block: 'center' }); + } + } catch { document.getElementById('status').textContent = 'Reconnecting…'; } + } + async function decide(id, action, cardEl) { + busy = true; + const notice = document.getElementById('notice'); + notice.textContent = ''; + cardEl.querySelectorAll('button').forEach(b => b.disabled = true); + try { + const response = await fetch('/dashboard/requests/' + encodeURIComponent(id) + '/' + action, + { method: 'POST', headers: { 'X-CSRF-Token': csrf }, credentials: 'same-origin' }); + if (!response.ok) { + const problem = await response.json().catch(() => ({})); + notice.textContent = problem.error === 'already_decided' + ? 'That request was already decided elsewhere.' + : 'Could not ' + action + ' the request: ' + (problem.detail || problem.error || response.status); + } else decidedHere.add(id); + } finally { busy = false; await refresh(); } + } + document.querySelectorAll('[data-group]').forEach(b => b.addEventListener('click', () => { + group = b.dataset.group; + document.querySelectorAll('[data-group]').forEach(x => x.setAttribute('aria-pressed', String(x === b))); + refresh(); + })); + refresh(); + setInterval(refresh, 1000); + """; +} diff --git a/samples/MockPersonServer/ConsentRegistry.cs b/samples/MockPersonServer/ConsentRegistry.cs new file mode 100644 index 00000000..82311130 --- /dev/null +++ b/samples/MockPersonServer/ConsentRegistry.cs @@ -0,0 +1,238 @@ +using AAuth.Person; +using AAuth.Server; + +namespace MockPersonServer; + +/// What a PS consent request asks the person to decide. +public enum ConsentKind +{ + Token, + PersonToken, + MissionToken, + MissionCreation, + Permission, + FederatedConsent, + AccessServerInteraction, +} + +public enum ConsentStatus +{ + Pending, + Approved, + Denied, + Expired, + Withdrawn, + Delivered, +} + +public enum ConsentDecider +{ + Dashboard, + Link, + Admin, + Script, + Policy, +} + +/// +/// One PS-parked consent request. It holds the live pending entry, so status and +/// the current interaction code are derived rather than copied. +/// +public sealed class ConsentRecord +{ + private readonly MissionPolicyStore _policy; + + internal ConsentRecord(PersonPendingEntry entry, MissionPolicyStore policy) + { + PersonEntry = entry; + _policy = policy; + CreatedAt = entry.CreatedAt; + } + + internal ConsentRecord(MissionPendingEntry entry, MissionPolicyStore policy) + { + MissionEntry = entry; + _policy = policy; + CreatedAt = entry.CreatedAt; + } + + public PersonPendingEntry? PersonEntry { get; } + public MissionPendingEntry? MissionEntry { get; } + public string Id => PersonEntry?.Id ?? MissionEntry!.Id; + public DateTimeOffset CreatedAt { get; } + public DateTimeOffset ExpiresAt => PersonEntry?.PendingExpiresAt ?? MissionEntry!.ExpiresAt; + public DeferredState Lifecycle => PersonEntry?.Lifecycle ?? MissionEntry!.Lifecycle; + public BrowserInteraction Browser => PersonEntry?.Browser ?? MissionEntry!.Browser; + public string AgentId => PersonEntry?.ConsentAgentId ?? MissionEntry!.AgentId; + public string? Resource => PersonEntry?.ResourceUrl ?? MissionEntry!.Resource; + public string? Scope => PersonEntry is { } entry ? (entry.PersonToken ? null : entry.Scope) : MissionEntry!.Scope; + public string? Account => PersonEntry?.Account; + public string? Action => MissionEntry?.Action; + + /// The Access Server's interaction URL when the PS relays one; not PS-hosted. + public string? ExternalInteractionUrl => PersonEntry is { InteractionCode: not null } entry ? entry.InteractionUrl : null; + + public string? MissionS256 => PersonEntry is { } entry ? entry.MissionS256 + : string.IsNullOrEmpty(MissionEntry!.S256) ? null : MissionEntry.S256; + + public string? MissionDescription => MissionEntry?.Proposal?.Description + ?? (MissionS256 is { } s256 ? _policy.Describe(s256) : null); + + /// Tool names a mission proposal asks for (mission creation only). + public IReadOnlyList ProposedTools => + MissionEntry?.Proposal?.Tools.Select(tool => tool.Name).ToArray() ?? []; + + public ConsentDecider? DecidedBy { get; private set; } + public DateTimeOffset? DecidedAt { get; private set; } + + public ConsentKind Kind => MissionEntry is { } mission + ? mission.Kind switch + { + MissionPendingKind.Mission => ConsentKind.MissionCreation, + MissionPendingKind.Token => ConsentKind.MissionToken, + _ => ConsentKind.Permission, + } + : PersonEntry switch + { + { FederationConsent: not null } => ConsentKind.FederatedConsent, + { InteractionCode: not null } => ConsentKind.AccessServerInteraction, + { PersonToken: true } => ConsentKind.PersonToken, + { MissionGate: true } => ConsentKind.MissionToken, + _ => ConsentKind.Token, + }; + + /// + /// Whether the person sees this request. Resource-interaction hops and a + /// four-party federation that has not asked the PS for consent are not + /// PS consent requests (yet). + /// + public bool IsListed => PersonEntry is not { } entry + || (!entry.AwaitingResourceInteraction + && (entry.AgentConfirmationKey is not null || entry.PersonToken + || entry.FederationConsent is not null || entry.InteractionCode is not null)); + + public ConsentStatus Status + { + get + { + var now = DateTimeOffset.UtcNow; + if (MissionEntry is { } mission) + { + if (mission.Lifecycle.Cancelled) return ConsentStatus.Withdrawn; + if (mission.Decision is false) return ConsentStatus.Denied; + if (mission.Decision is true) + return mission.Lifecycle.Delivered ? ConsentStatus.Delivered : ConsentStatus.Approved; + return mission.ExpiresAt <= now || mission.Lifecycle.InvalidCode || mission.Lifecycle.Delivered + ? ConsentStatus.Expired : ConsentStatus.Pending; + } + var entry = PersonEntry!; + if (entry.Status == PersonPendingStatus.Withdrawn || entry.Lifecycle.Cancelled) return ConsentStatus.Withdrawn; + if (entry.Status == PersonPendingStatus.Denied) return ConsentStatus.Denied; + if (entry.FederationConsent is { Task.IsCompletedSuccessfully: true } consent + && consent.Task.Result.Kind != IdentityAssertionKind.Assert) return ConsentStatus.Denied; + if (entry.Lifecycle.Delivered) return ConsentStatus.Delivered; + if (entry.Status == PersonPendingStatus.Allowed || entry.FederationConsent is { Task.IsCompleted: true }) + return ConsentStatus.Approved; + return entry.PendingExpiresAt <= now || entry.Lifecycle.InvalidCode + ? ConsentStatus.Expired : ConsentStatus.Pending; + } + } + + /// Whether the PS dashboard may decide this request now (Q9: PS-hosted only). + public bool IsDecidable => IsListed && Status == ConsentStatus.Pending && Kind != ConsentKind.AccessServerInteraction + && (PersonEntry is not { } entry || entry.Status == PersonPendingStatus.Pending) + && (Kind != ConsentKind.FederatedConsent || PersonEntry!.AwaitingFederationConsent); + + /// Who decided, falling back to the automated decider when nobody recorded one. + public ConsentDecider? Decider => DecidedBy ?? (Status is ConsentStatus.Approved or ConsentStatus.Denied or ConsentStatus.Delivered + ? Kind is ConsentKind.MissionToken or ConsentKind.MissionCreation or ConsentKind.Permission + ? ConsentDecider.Script : ConsentDecider.Policy + : null); + + internal void MarkDecided(ConsentDecider by) + { + if (DecidedBy is not null) return; + DecidedBy = by; + DecidedAt = DateTimeOffset.UtcNow; + } +} + +/// +/// In-memory, capped history of every PS-parked consent request (Q8). +/// /admin/reset drops only the requests still pending. +/// +public sealed class ConsentRegistry(MissionPolicyStore policy) : IPersonPendingObserver +{ + public const int Capacity = 500; + private readonly LinkedList _records = new(); + private readonly Dictionary> _byId = new(StringComparer.Ordinal); + private readonly Lock _lock = new(); + + public void Register(PersonPendingEntry entry) => Add(new ConsentRecord(entry, policy)); + + /// The Person Server parked a request: list it on the dashboard. + public void OnParked(PersonPendingEntry entry) => Register(entry); + + public void Register(MissionPendingEntry entry) => Add(new ConsentRecord(entry, policy)); + + public ConsentRecord? Find(string id) + { + lock (_lock) return _byId.TryGetValue(id, out var node) ? node.Value : null; + } + + /// Read-only lookup of a pending request by its current code; never consumes it. + public ConsentRecord? FindPendingByCode(string code) + => FindByCode(code) is { IsDecidable: true } record ? record : null; + + /// + /// Read-only lookup of any listed request by its current code. A four-party + /// request keeps advertising a fresh PS code while the Access Server works, so + /// the dashboard can say there is nothing to decide. + /// + public ConsentRecord? FindByCode(string code) + { + var normalized = AAuth.Headers.InteractionCode.Normalize(code); + if (string.IsNullOrEmpty(normalized)) return null; + return Snapshot().FirstOrDefault(record => record.Browser.Code == normalized); + } + + /// Listed records, newest first. + public IReadOnlyList Snapshot() + { + lock (_lock) return _records.Where(record => record.IsListed).Reverse().ToArray(); + } + + public void MarkDecided(string id, ConsentDecider by) => Find(id)?.MarkDecided(by); + + /// Drop requests still pending (a reset abandons them); decided history stays. + public void DropPending() + { + lock (_lock) + { + for (var node = _records.First; node is not null;) + { + var next = node.Next; + if (node.Value.Status == ConsentStatus.Pending) + { + _byId.Remove(node.Value.Id); + _records.Remove(node); + } + node = next; + } + } + } + + private void Add(ConsentRecord record) + { + lock (_lock) + { + if (_byId.ContainsKey(record.Id)) return; + _byId[record.Id] = _records.AddLast(record); + while (_records.Count > Capacity) + { + _byId.Remove(_records.First!.Value.Id); + _records.RemoveFirst(); + } + } + } +} diff --git a/samples/MockPersonServer/MissionGovernance.cs b/samples/MockPersonServer/MissionGovernance.cs index e12ee77f..6b23378a 100644 --- a/samples/MockPersonServer/MissionGovernance.cs +++ b/samples/MockPersonServer/MissionGovernance.cs @@ -195,7 +195,7 @@ public sealed class SampleAuditSink : IAuditSink public Task RecordAsync(AuditRecord record, CancellationToken ct = default) => _log.AppendAsync( - new MissionLogEntry(record.Mission.S256, MissionLogEntryKind.Audit, DateTimeOffset.UtcNow) + new MissionLogEntry(record.MissionS256, MissionLogEntryKind.Audit, DateTimeOffset.UtcNow) { Action = record.Action.Name, Detail = record.Description, @@ -219,7 +219,7 @@ public Task RelayAsync(InteractionRequest request, Cance { InteractionType.Question => new InteractionRelayResult { Answer = _script.QuestionAnswer }, InteractionType.Completion => new InteractionRelayResult { Accepted = _script.AcceptCompletion }, - _ => new InteractionRelayResult { Pending = false }, + _ => new InteractionRelayResult { Unavailable = true }, }); } @@ -260,7 +260,8 @@ public sealed class MissionPendingEntry public string Id { get; } = Guid.NewGuid().ToString("N"); public AAuth.Server.BrowserInteraction Browser { get; } = new(); public AAuth.Server.DeferredState Lifecycle { get; } = new(); - public DateTimeOffset ExpiresAt { get; } = DateTimeOffset.UtcNow.AddMinutes(10); + public DateTimeOffset CreatedAt { get; } = DateTimeOffset.UtcNow; + public DateTimeOffset ExpiresAt => CreatedAt.AddMinutes(10); public string? OwnerIssuer { get; init; } public string? OwnerKeyThumbprint { get; init; } @@ -291,11 +292,11 @@ public bool Decide(bool allow) /// The agent that made the request (token `sub`). public required string AgentId { get; init; } - /// The mission this request belongs to. - public required string S256 { get; init; } + /// The mission this request belongs to; empty on a creation request until it is approved. + public required string S256 { get; set; } - /// The mission approver (for re-emitting the mission claim). - public required string Approver { get; init; } + /// The PS that approves the mission. + public required string PersonServer { get; init; } /// The requested resource (token requests). public string? Resource { get; init; } @@ -312,9 +313,6 @@ public bool Decide(bool allow) /// The agent's confirmation key, captured to mint the auth token. public IAAuthKey? ConfirmationKey { get; init; } - /// Any upstream act claim to carry into the issued auth token. - public JsonObject? UpstreamAct { get; init; } - /// The clarification question (when started in clarification). public string? Question { get; init; } @@ -327,13 +325,10 @@ public bool Decide(bool allow) /// on deny. Ignored in scripted mode. /// public bool? Decision { get; set; } - - /// The mission claim to embed in the issued auth token. - public MissionClaim MissionClaim => new(Approver, S256); } /// In-memory store of parked mission-governance requests. -public sealed class MissionPendingStore +public sealed class MissionPendingStore(ConsentRegistry registry) { private readonly ConcurrentDictionary _entries = new(StringComparer.Ordinal); @@ -343,6 +338,7 @@ public MissionPendingEntry Add(MissionPendingEntry entry) foreach (var pair in _entries) if (pair.Value.ExpiresAt.AddHours(1) <= DateTimeOffset.UtcNow) _entries.TryRemove(pair.Key, out _); _entries[entry.Id] = entry; + registry.Register(entry); return entry; } diff --git a/samples/MockPersonServer/PersonConsentDecisions.cs b/samples/MockPersonServer/PersonConsentDecisions.cs new file mode 100644 index 00000000..5e667d1c --- /dev/null +++ b/samples/MockPersonServer/PersonConsentDecisions.cs @@ -0,0 +1,109 @@ +using AAuth.Person; +using Microsoft.Extensions.DependencyInjection; + +namespace MockPersonServer; + +public enum ConsentOutcome +{ + Applied, + AlreadyDecided, + Expired, + Unknown, + NotDecidable, + Refused, +} + +/// +/// The one place a PS consent decision mutates state (Q15). The per-request link +/// (/interaction/approve|deny) and the dashboard both decide through it. +/// +public sealed class PersonConsentDecisions(ConsentStore consent, + [FromKeyedServices(AAuthPersonServerBuilder.DefaultName)] IIdentityClaimsAsserter asserter, ConsentRegistry registry) +{ + /// Decide a mission-governance request. The caller holds the entry's lifecycle gate. + public ConsentOutcome ApplyHeld(MissionPendingEntry entry, bool approve, ConsentDecider by) + { + if (entry.Decision is not null) return ConsentOutcome.AlreadyDecided; + entry.Decision = approve; + registry.MarkDecided(entry.Id, by); + return ConsentOutcome.Applied; + } + + /// Decide a PS token request. The caller holds the entry's lifecycle gate. + public async Task ApplyHeldAsync(PersonPendingEntry entry, bool approve, ConsentDecider by, + CancellationToken cancellationToken) + { + var now = DateTimeOffset.UtcNow; + if (!approve) + { + if (entry.AwaitingResourceInteraction + || entry.Status is PersonPendingStatus.Allowed or PersonPendingStatus.Denied or PersonPendingStatus.Withdrawn + || entry.PendingExpiresAt <= now) + return ConsentOutcome.AlreadyDecided; + entry.Status = PersonPendingStatus.Denied; + entry.DenyReason = "the user denied this request"; + entry.FederationConsent?.TrySetResult(IdentityAssertion.Deny(entry.DenyReason)); + registry.MarkDecided(entry.Id, by); + return ConsentOutcome.Applied; + } + + if (entry.AwaitingResourceInteraction || entry.Status != PersonPendingStatus.Pending || entry.PendingExpiresAt <= now) + return ConsentOutcome.AlreadyDecided; + // An out-of-scope mission token request resolves by marking the SDK-owned + // pending decision allowed; a plain three-party request records standing consent. + if (!entry.MissionGate) + consent.Grant(entry.ConsentAgentId, entry.ResourceUrl, entry.Scope, entry.Account, entry.ResourceKeyThumbprint); + var asserted = await asserter.AssertAsync(new IdentityAssertionRequest + { + ResourceUrl = entry.ResourceUrl, Scope = entry.Scope, AgentId = entry.ConsentAgentId, + AgentIssuer = entry.OwnerIssuer ?? "https://ap.example", + Account = entry.Account, AgentKeyThumbprint = entry.ResourceKeyThumbprint, + PersonKey = entry.PersonKey, + MissionS256 = entry.MissionS256, RequiredClaims = entry.RequiredIdentityClaims, + ResourceContext = entry.ResourceContext, AgentAsserted = entry.AgentAsserted, InteractionId = entry.Id, + }, cancellationToken); + if (asserted.Kind != IdentityAssertionKind.Assert) return ConsentOutcome.Refused; + cancellationToken.ThrowIfCancellationRequested(); + entry.PersonKey = asserted.PersonKey; + entry.Subject = asserted.Subject!; + entry.Tenant = asserted.Tenant; + entry.Roles = asserted.Roles; + entry.Groups = asserted.Groups; + entry.AdditionalClaims = asserted.AdditionalClaims; + if (entry.FederationConsent is { } consentCompletion) consentCompletion.TrySetResult(asserted); + else entry.Status = PersonPendingStatus.Allowed; + registry.MarkDecided(entry.Id, by); + return ConsentOutcome.Applied; + } + + /// + /// Decide a request out-of-band (the dashboard). Takes the entry's lifecycle + /// gate, so a concurrent link decision resolves exactly once, and consumes the + /// interaction code on success (#interaction-code-format). + /// + public async Task DecideAsync(string id, bool approve, ConsentDecider by, CancellationToken cancellationToken) + { + if (registry.Find(id) is not { } record) return ConsentOutcome.Unknown; + ConsentOutcome Undecidable() => record.Status switch + { + ConsentStatus.Expired => ConsentOutcome.Expired, + ConsentStatus.Pending => ConsentOutcome.NotDecidable, + _ => ConsentOutcome.AlreadyDecided, + }; + var outcome = Undecidable(); + // The SDK takes the lifecycle gate and consumes the code once the decision applies. + await record.Browser.CompleteOutOfBandAsync(record.Lifecycle, async ct => + { + if (!record.IsDecidable) + { + outcome = Undecidable(); + return false; + } + outcome = record.PersonEntry is { } person + ? await ApplyHeldAsync(person, approve, by, ct) + : ApplyHeld(record.MissionEntry!, approve, by); + return outcome == ConsentOutcome.Applied; + }, cancellationToken); + return outcome; + } +} diff --git a/samples/MockPersonServer/Program.cs b/samples/MockPersonServer/Program.cs index 3858527c..0273dcf8 100644 --- a/samples/MockPersonServer/Program.cs +++ b/samples/MockPersonServer/Program.cs @@ -40,19 +40,18 @@ // drives the GuidedTour's deferred / user-consent showcase and the §3.4 // ThreePartyUserConsentFlow integration test. // ----------------------------------------------------------------------- -var psKey = AAuthKey.Generate(); const string PsKid = "ps-1"; const string PsScope = "calendar.read"; -const string PsAdminScope = "calendar.write"; // Demo identity claims the mock PS asserts about the user. A production PS // would resolve these from the signed-in user's directory entry. These let // the Calendar `/events/admin` (RBAC) endpoint succeed end-to-end. // -// Roles/groups are asserted ONLY for recognized "admin" demo agents (those -// whose id is `aauth:demo@...`). Any other agent receives an auth token -// without the role, so role-based DENIAL is exercised end-to-end (a guest -// agent calling `/events/admin` gets a 403). A production PS would resolve the -// principal's directory membership instead of a hard-coded prefix. +// Roles/groups are asserted ONLY for recognized "admin" demo agents: the AP +// issuer and agent id must exactly match the configured demo binding. Any other +// agent receives an auth token without the role, so role-based DENIAL is +// exercised end-to-end (a guest agent calling `/events/admin` gets a 403). +// A production PS would resolve the principal's directory membership instead +// of a hard-coded demo binding. string[] demoRoles = ["calendar.owner"]; string[] demoGroups = ["demo-users"]; // Identity claims the PS can release for the bound principal when an Access @@ -76,35 +75,64 @@ .GetSection("MockPersonServer:TrustedAccessServers").Get() ?? ["http://localhost:5500"]; -builder.Services.AddSingleton(psKey); builder.Services.AddSingleton(new AAuthVerifier { MaxAge = TimeSpan.FromSeconds(signatureWindowSeconds), }); -builder.Services.AddSingleton(new TokenVerifier { EgressPolicy = SampleEgress.Policy }); // Shared discovery clients (MetadataClient + JwksClient) with a pooled handler; // no manual HttpClient wiring. builder.Services.AddAAuthDiscovery(options => options.EgressPolicy = SampleEgress.Policy); builder.Services.AddSingleton(); -// Person Server decision seams. The SDK's MapAAuthPersonServer owns the protocol -// (verification, mint, federation, the mission three-gate + the clarification -// round-trip); these supply only the demo's decisions: +// `/admin` and `/dashboard` are the PS's own unsigned consent surfaces (§PS Approval +// Endpoint Authentication — out of scope), so the mapper skips signature verification for them. +var browserConsent = new AAuth.Server.BrowserConsentSessions("AAuth.Person.Consent", + builder.Configuration.GetValue("AAuth:EnableIsolatedDemoConsent") ? "isolated-person-demo" : null); + +// Person Server registration. The SDK's MapAAuthPersonServer (below) owns the +// protocol (verification, mint, federation, the mission three-gate + the +// clarification round-trip); the builder supplies only the demo's decisions: // * identity + the non-mission consent gate (over ConsentStore); -// * the id-keyed pending store, bridged to the (agent,resource,scope) ConsentStore. -builder.Services.AddSingleton(sp => - new SampleIdentityClaimsAsserter( - sp.GetRequiredService(), requireConsent, demoRoles, demoGroups, demoUserClaims)); -builder.Services.AddSingleton(sp => - new ConsentBridgePersonPendingStore(sp.GetRequiredService(), demoRoles, demoGroups)); +// * the id-keyed pending store, bridged to the (agent,resource,scope) ConsentStore; +// * four-party federation (PS→AS): the PS signs token requests as itself via the +// `jwks_uri` scheme through the named federation client, so tests can route it +// to an in-process AS; +// * the mission governance seams (§PS Governance Endpoints). +builder.Services.AddAAuthPersonServer(configure: options => + { + options.EgressPolicy = SampleEgress.Policy; + options.Issuer = psIssuer; + options.SigningKeys = new AAuthSigningKeySet(PsKid, AAuthKey.Generate()); + options.DefaultScope = PsScope; + // Governance endpoints (mapped below) advertised in aauth-person.json so the + // agent's MissionClient / PermissionClient / AuditClient can resolve them. + options.MissionPath = "/mission"; + options.PermissionPath = "/permission"; + options.AuditPath = "/audit"; + options.UnsignedPathPrefixes = new[] { "/admin", "/dashboard" }; + options.ResourceInteractionSessions = browserConsent; + }) + .WithTrust(trust => trust.AccessServers.Allowed = new HashSet(trustedAccessServers)) + .UseClaimsAsserter(sp => new SampleIdentityClaimsAsserter( + sp.GetRequiredService(), requireConsent, demoRoles, demoGroups, demoUserClaims)) + .UsePendingStore(sp => new ConsentBridgePersonPendingStore( + sp.GetRequiredService(), sp.GetRequiredService(), demoRoles, demoGroups)) + .WithFederation() + .WithGovernance(); +// Every PS-parked consent request and its outcome, and the one decision path the +// per-request link and the dashboard share. The registry observes every request +// the PS parks (IPersonPendingObserver), so the dashboard lists it. +builder.Services.AddSingleton(); +builder.Services.AddSingleton(sp => sp.GetRequiredService()); +builder.Services.AddSingleton(); +builder.Services.AddSingleton(); -// Mission governance (§PS Governance Endpoints). AddAAuthGovernance registers -// the in-memory mission store + log; the PS supplies the policy/user-channel +// Mission governance (§PS Governance Endpoints). WithGovernance registers the +// in-memory mission store + log; the PS supplies the policy/user-channel // seams (decider / audit sink / interaction relay), the deterministic consent // script that stands in for a real user-consent screen, and the out-of-scope // mission-token decision (ScriptMissionTokenConsent — the SDK's clarification // protocol calls into it). -builder.Services.AddAAuthGovernance(); builder.Services.AddSingleton(); builder.Services.AddSingleton(); builder.Services.AddSingleton(); @@ -119,85 +147,64 @@ sp.GetRequiredService(), sp.GetRequiredService())); -// Four-party federation client (PS→AS), wired by the SDK: the PS signs the -// token request with its own key via the `jwks_uri` scheme, and the transport -// uses the named federation client so tests can route it to an in-process AS. -builder.Services.AddAAuthFederation(psKey, psIssuer, PsKid); - var app = builder.Build(); +var ps = app.Services.GetRequiredKeyedService(AAuthPersonServerBuilder.DefaultName); // ----------------------------------------------------------------------- -// Well-known endpoints — served BEFORE the verification middleware so the -// metadata document and JWKS are reachable without an AAuth signature. +// Well-known endpoints: MapAAuthPersonServer (below) publishes the PS +// metadata and JWKS before its verification middleware, so they are +// reachable without an AAuth signature. The PS is not a resource, so it +// publishes no aauth-resource.json. // ----------------------------------------------------------------------- -// JWKS (reused from the shared resource helper — same shape). -app.MapAAuthResourceWellKnown(new AAuthResourceMetadataOptions -{ - EgressPolicy = SampleEgress.Policy, - Issuer = psIssuer, - Name = "Mock Person Server", - SigningKeys = new Dictionary { [PsKid] = psKey }, - ScopeDescriptions = new Dictionary - { - [PsScope] = "Issue AAuth auth tokens for the Calendar", - [PsAdminScope] = "Issue elevated (write) AAuth auth tokens for the Calendar", - }, - SignatureWindow = signatureWindowSeconds, -}); - // Person Server token endpoint + pending polls + PS metadata, in one call. The // SDK owns verification, the three-/four-party mint, PS→AS federation, and the -// mission three-gate + clarification protocol; the decision seams registered -// above supply the demo's policy. `/admin` is the PS's own unsigned consent -// surface (§PS Approval Endpoint Authentication — out of scope), so the mapper -// skips signature verification for it. -var browserConsent = new AAuth.Server.BrowserConsentSessions("AAuth.Person.Consent", - builder.Configuration.GetValue("AAuth:EnableIsolatedDemoConsent") ? "isolated-person-demo" : null); -app.MapAAuthPersonServer(new AAuthPersonServerOptions -{ - EgressPolicy = SampleEgress.Policy, - Issuer = psIssuer, - SigningKeys = new Dictionary { [PsKid] = psKey }, - DefaultScope = PsScope, - TrustedAccessServers = trustedAccessServers, - // Governance endpoints (mapped below) advertised in aauth-person.json so the - // agent's MissionClient / PermissionClient / AuditClient can resolve them. - MissionEndpoint = $"{psIssuer.TrimEnd('/')}/mission", - PermissionEndpoint = $"{psIssuer.TrimEnd('/')}/permission", - AuditEndpoint = $"{psIssuer.TrimEnd('/')}/audit", - InteractionEndpoint = $"{psIssuer.TrimEnd('/')}/mission-interaction", - UnsignedPathPrefixes = new[] { "/admin" }, - ResourceInteractionSessions = browserConsent, -}); +// mission three-gate + clarification protocol; the builder registered above +// supplies the demo's policy. +app.MapAAuthPersonServer(); -app.MapPost("/local/wallet/revoke", async (HttpContext context, MetadataClient metadata, JwksClient jwks, TokenVerifier verifier) => +// Demo route: the agent asks this PS to revoke a person token it issued. Per +// #revocation-cascade the PS revokes it at its resource and at every AS it was +// presented to; each AS then revokes the auth tokens it issued against it. +app.MapPost("/local/wallet/revoke", async (HttpContext context, + [FromKeyedServices(AAuthPersonServerBuilder.DefaultName)] TokenVerifier verifier, + [FromKeyedServices(AAuthPersonServerBuilder.DefaultName)] IAAuthRevocationService revocation) => { var owner = context.GetAAuthVerification(); if (owner is not { TokenType: AAuthTokenType.AgentToken, IssuerVerified: true, Agent: not null }) return AAuthProblemDetails.Create("invalid_carrier_token", statusCode: 403); var body = await context.Request.ReadFromJsonAsync(); - if (body?["auth_token"] is not JsonValue value || !value.TryGetValue(out var token)) + if (body?["person_token"] is not JsonValue value || !value.TryGetValue(out var personToken)) return AAuthProblemDetails.Create("invalid_request", statusCode: 400); var wallet = builder.Configuration["AAuth:Wallet"] ?? "http://localhost:5003"; TokenVerifier.VerifiedToken verified; try { + // Only this PS's own person token, bound to the requesting agent's key. var key = SignatureKeyParser.Parse(context.Request.Headers["Signature-Key"].ToString()).ConfirmationKey; - verified = await verifier.VerifyAuthTokenWithJwksAsync(token, metadata, jwks, wallet, - key, owner.Agent, cancellationToken: context.RequestAborted); - if (!trustedAccessServers.Contains(verified.Issuer, StringComparer.Ordinal)) + verified = verifier.VerifyPersonToken(personToken, ps.SigningKeys.Active.Signer, wallet, key); + if (verified.Issuer != ps.Issuer) return AAuthProblemDetails.Create("denied", statusCode: 403); } catch (TokenVerificationException) { return AAuthProblemDetails.Create("denied", statusCode: 403); } - using var signed = new AAuthClientBuilder(psKey).UseJwksUri(psIssuer, AuthTokenBuilder.PersonDwk, PsKid) - .WithEgressPolicy(SampleEgress.Policy).Build(); - var tokenKey = new TokenKey(verified.Issuer, (string)verified.Payload["jti"]!); - var status = await new RevocationClient(signed).RevokeAsync(new Uri(wallet + "/revoke"), tokenKey, context.RequestAborted); - return Results.Json(new { iss = tokenKey.Issuer, jti = tokenKey.TokenId, resource = wallet, status = (int)status }, statusCode: (int)status); + var jti = (string)verified.Payload["jti"]!; + var result = await revocation.RevokeTokenAsync(jti, context.RequestAborted); + return Results.Json(new JsonObject + { + ["jti"] = jti, + ["exp"] = verified.ExpiresAt.ToUnixTimeSeconds(), + ["downstream"] = new JsonArray(result.Downstream.Select(Report).ToArray()), + }); + + static JsonNode Report(RevocationDownstreamResult entry) => new JsonObject + { + ["recipient"] = entry.Recipient, + ["error"] = entry.Error is { } error ? RevocationError.ToWireCode(error) : null, + ["downstream"] = new JsonArray(entry.Downstream.Select(Report).ToArray()), + }; }); // ----------------------------------------------------------------------- @@ -211,8 +218,8 @@ // ----------------------------------------------------------------------- // mission_endpoint (§Mission Creation): the agent proposes a mission; the PS -// records the approved mission and returns the verbatim approval blob plus the -// `AAuth-Mission` header whose `s256` the agent verifies. +// records the approved mission and returns the approval response: the verbatim +// blob (base64url) and its `s256`, which the agent verifies (#mission-approval). app.MapPost("/mission", async ( HttpContext ctx, IMissionStore missions, @@ -248,7 +255,7 @@ MissionProposal proposal; try { - proposal = GovernanceEndpoints.ParseMissionProposal(body); + proposal = GovernanceEndpoints.ParseMissionProposal(body, SampleEgress.Policy); } catch (FormatException) { @@ -264,7 +271,7 @@ // important consent in the model, so park the proposal and let the user // approve it on the PS browser screen — the same deferred (202) path the // token and permission gates use. The agent's MissionClient polls the - // pending URL and receives the signed approval blob once the user decides. + // pending URL and receives the mission blob plus s256 digest once the user decides. if (script.InteractiveBrowser) { var pendingMission = pending.Add(new MissionPendingEntry @@ -274,7 +281,7 @@ OwnerIssuer = ctx.GetAAuthVerification()!.Issuer, OwnerKeyThumbprint = ctx.GetAAuthVerification()!.Jkt, S256 = string.Empty, // computed from the blob once approved - Approver = psIssuer, + PersonServer = ps.Issuer, Proposal = proposal, }); ctx.Response.Headers.Location = $"/mission-create-pending/{pendingMission.Id}"; @@ -282,26 +289,26 @@ ctx.Response.Headers["Retry-After"] = "1"; ctx.Response.Headers["Cache-Control"] = "no-store"; ctx.Response.Headers[AAuthRequirementHeader.Name] = - Interaction.Format($"{psIssuer.TrimEnd('/')}/interaction", pendingMission.Browser.Code, SampleEgress.Policy); + Interaction.Format(ps.Url("/interaction"), pendingMission.Browser.Code, SampleEgress.Policy); return Results.Json(new { status = "pending" }, statusCode: StatusCodes.Status202Accepted); } // The demo approves every proposed tool; a real PS would let the user prune them. var approvedTools = proposal.Tools; - var (blob, s256) = MissionApprovalBuilder.Build(psIssuer, agentId, proposal, approvedTools, DateTimeOffset.UtcNow); + var (blob, s256) = MissionApprovalBuilder.Build(agentId, proposal, approvedTools, DateTimeOffset.UtcNow, + approvedResources: proposal.Resources); - await missions.SaveAsync(new StoredMission(s256, psIssuer, agentId, blob)); + await missions.SaveAsync(new StoredMission(s256, ps.Issuer, agentId, blob)); policy.Record(s256, proposal.Description, approvedTools, script.InScopeSnapshot()); - ctx.Response.Headers[AAuthMissionHeader.Name] = - AAuthMissionHeader.FormatStructured(psIssuer, s256); - return Results.Bytes(blob, "application/json"); + var personTokens = await ctx.IssueMissionPersonTokensAsync(ps.Issuer, s256, proposal.Resources); + return Results.Json(MissionApprovalBuilder.Response(blob, s256, personTokens: personTokens)); }); // Interactive mission-creation resolution (§Mission Creation). The agent polls // here while the user approves or declines the proposed mission in the browser. -// On approval the PS builds and stores the verbatim approval blob and returns it -// with the AAuth-Mission header — exactly what the synchronous path returns. +// On approval the PS builds and stores the verbatim approval blob and returns the +// same approval response the synchronous path returns. app.MapMethods("/mission-create-pending/{id}", ["GET", "DELETE"], async ( HttpContext ctx, string id, MissionPendingStore pending, IMissionStore missions, MissionPolicyStore policy, MissionConsentScript script) => @@ -310,7 +317,7 @@ if (entry is null) return AAuth.Server.DeferredState.Missing(id); if (entry is null || entry.Kind != MissionPendingKind.Mission || !entry.MatchesOwner(ctx)) { - return AAuth.Server.AAuthProblemDetails.Create("unknown_pending", statusCode: StatusCodes.Status404NotFound, + return AAuth.Server.AAuthProblemDetails.Polling(PollingErrorCode.InvalidCode, extensions: new Dictionary { ["id"] = id }); } @@ -327,7 +334,7 @@ ctx.Response.Headers["Retry-After"] = "1"; ctx.Response.Headers["Cache-Control"] = "no-store"; ctx.Response.Headers[AAuthRequirementHeader.Name] = - Interaction.Format($"{psIssuer.TrimEnd('/')}/interaction", entry.Browser.Code, SampleEgress.Policy); + Interaction.Format(ps.Url("/interaction"), entry.Browser.Code, SampleEgress.Policy); return Results.Json(new { status = "pending" }, statusCode: StatusCodes.Status202Accepted); } @@ -340,12 +347,13 @@ var proposal = entry.Proposal!; // The demo approves every proposed tool; a real PS would let the user prune them. var approvedTools = proposal.Tools; - var (blob, s256) = MissionApprovalBuilder.Build(psIssuer, entry.AgentId, proposal, approvedTools, DateTimeOffset.UtcNow); - await missions.SaveAsync(new StoredMission(s256, psIssuer, entry.AgentId, blob)); + var (blob, s256) = MissionApprovalBuilder.Build(entry.AgentId, proposal, approvedTools, DateTimeOffset.UtcNow, + approvedResources: proposal.Resources); + await missions.SaveAsync(new StoredMission(s256, ps.Issuer, entry.AgentId, blob)); policy.Record(s256, proposal.Description, approvedTools, script.InScopeSnapshot()); - ctx.Response.Headers[AAuthMissionHeader.Name] = - AAuthMissionHeader.FormatStructured(psIssuer, s256); - return Results.Bytes(blob, "application/json"); + entry.S256 = s256; + var personTokens = await ctx.IssueMissionPersonTokensAsync(ps.Issuer, s256, proposal.Resources); + return Results.Json(MissionApprovalBuilder.Response(blob, s256, personTokens: personTokens)); }); }); @@ -372,7 +380,7 @@ PermissionRequest request; try { - request = GovernanceEndpoints.ParsePermission(body, SampleEgress.Policy); + request = GovernanceEndpoints.ParsePermission(body); } catch (FormatException) { @@ -381,20 +389,20 @@ StoredMission? stored = null; IReadOnlyList history = []; - if (request.Mission is not null) + if (request.MissionS256 is not null) { - stored = await missions.GetAsync(request.Mission.S256); + stored = await missions.GetAsync(ps.Issuer, request.MissionS256); } - if (GovernanceEndpoints.Authorize(ctx, request.Mission, stored) is { } denied) return denied; - if (request.Mission is not null) + if (GovernanceEndpoints.Authorize(ctx, request.MissionS256, stored) is { } denied) return denied; + if (request.MissionS256 is not null) { - history = await log.ReadAsync(request.Mission.S256); + history = await log.ReadAsync(request.MissionS256); } var decision = await decider.DecideAsync(new PermissionDecisionContext(request, stored, history)); // Prompt -> park the request and let the agent poll while the user decides. - if (decision.Outcome == PermissionOutcome.Prompt && request.Mission is not null) + if (decision.Outcome == PermissionOutcome.Prompt && request.MissionS256 is not null) { var entry = pending.Add(new MissionPendingEntry { @@ -402,8 +410,8 @@ AgentId = agentId, OwnerIssuer = ctx.GetAAuthVerification()!.Issuer, OwnerKeyThumbprint = ctx.GetAAuthVerification()!.Jkt, - S256 = request.Mission.S256, - Approver = request.Mission.Approver, + S256 = request.MissionS256, + PersonServer = ps.Issuer, Action = request.Action.Name, }); ctx.Response.Headers.Location = $"/permission-pending/{entry.Id}"; @@ -414,16 +422,16 @@ if (script.InteractiveBrowser) { ctx.Response.Headers[AAuthRequirementHeader.Name] = - Interaction.Format($"{psIssuer.TrimEnd('/')}/interaction", entry.Browser.Code, SampleEgress.Policy); + Interaction.Format(ps.Url("/interaction"), entry.Browser.Code, SampleEgress.Policy); } return Results.Json(new { status = "pending" }, statusCode: StatusCodes.Status202Accepted); } var granted = decision.Outcome == PermissionOutcome.Granted; - if (request.Mission is not null) + if (request.MissionS256 is not null) { await log.AppendAsync(new MissionLogEntry( - request.Mission.S256, MissionLogEntryKind.Permission, DateTimeOffset.UtcNow) + request.MissionS256, MissionLogEntryKind.Permission, DateTimeOffset.UtcNow) { Action = request.Action.Name, Granted = granted, @@ -453,89 +461,73 @@ await log.AppendAsync(new MissionLogEntry( AuditRecord record; try { - record = GovernanceEndpoints.ParseAudit(body, SampleEgress.Policy); + record = GovernanceEndpoints.ParseAudit(body); } catch (FormatException) { return AAuth.Server.AAuthProblemDetails.Create("invalid_request", statusCode: StatusCodes.Status400BadRequest); } - var stored = await missions.GetAsync(record.Mission.S256); - if (GovernanceEndpoints.Authorize(ctx, record.Mission, stored) is { } denied) return denied; + var stored = await missions.GetAsync(ps.Issuer, record.MissionS256); + if (GovernanceEndpoints.Authorize(ctx, record.MissionS256, stored) is { } denied) return denied; await sink.RecordAsync(record); return Results.StatusCode(StatusCodes.Status201Created); }); -// interaction_endpoint (§Interaction Endpoint): questions and completion -// proposals relayed to the user. A completion the user accepts terminates the -// mission; otherwise the mission stays active. -app.MapPost("/mission-interaction", async ( +// mission_endpoint actions (§Mission Update, §Mission Completion). A completion +// the user accepts terminates the mission; otherwise the mission stays active. +app.MapPost("/mission/{missionS256}", async ( HttpContext ctx, + string missionS256, IMissionStore missions, IMissionLog log, IInteractionRelay relay) => { var body = await ctx.Request.ReadFromJsonAsync(); - if (body is null) - { + var action = (string?)(body?["action"] as JsonValue); + if (body is null || !AAuth.Tokens.MissionReference.IsValid(missionS256) || action is not ("update" or "completion")) return AAuth.Server.AAuthProblemDetails.Create("invalid_request", statusCode: StatusCodes.Status400BadRequest); - } + var stored = await missions.GetAsync(ps.Issuer, missionS256); + if (GovernanceEndpoints.Authorize(ctx, missionS256, stored) is { } denied) return denied; - InteractionRequest request; - try + if (action == "update") { - request = GovernanceEndpoints.ParseInteraction(body, SampleEgress.Policy); + var description = (string?)(body["description"] as JsonValue); + if (string.IsNullOrWhiteSpace(description)) + return AAuth.Server.AAuthProblemDetails.Create("invalid_request", statusCode: StatusCodes.Status400BadRequest); + var persisted = new JsonObject { ["description"] = description, ["accepted_at"] = DateTimeOffset.UtcNow.ToString("o") }.ToJsonString(); + await log.AppendAsync(new MissionLogEntry(missionS256, MissionLogEntryKind.Update, DateTimeOffset.UtcNow) { Detail = persisted }); + return Results.Json(new { s256 = Mission.ComputeS256(System.Text.Encoding.UTF8.GetBytes(persisted)) }); } - catch (FormatException) - { - return AAuth.Server.AAuthProblemDetails.Create("invalid_request", statusCode: StatusCodes.Status400BadRequest); - } - - var stored = request.Mission is null ? null : await missions.GetAsync(request.Mission.S256); - if (GovernanceEndpoints.Authorize(ctx, request.Mission, stored) is { } denied) return denied; - - var result = await relay.RelayAsync(request); - if (request.Mission is not null) + var summary = (string?)(body["summary"] as JsonValue); + if (string.IsNullOrWhiteSpace(summary)) + return AAuth.Server.AAuthProblemDetails.Create("invalid_request", statusCode: StatusCodes.Status400BadRequest); + var result = await relay.RelayAsync(new InteractionRequest(InteractionType.Completion) { Summary = summary, MissionS256 = missionS256 }); + await log.AppendAsync(new MissionLogEntry(missionS256, MissionLogEntryKind.Interaction, DateTimeOffset.UtcNow) { - await log.AppendAsync(new MissionLogEntry( - request.Mission.S256, MissionLogEntryKind.Interaction, DateTimeOffset.UtcNow) - { - Detail = request.Type.ToString(), - }); - } - - switch (request.Type) + Detail = InteractionType.Completion.ToString(), + }); + if (result.Accepted == true) { - case InteractionType.Question: - return Results.Json(new { answer = result.Answer ?? string.Empty }); - - case InteractionType.Completion: - // The user accepted completion -> terminate the mission (§Mission Management). - if (result.Accepted == true && request.Mission is not null) - { - await missions.SetStateAsync(request.Mission.S256, MissionState.Terminated); - return Results.Json(new { mission_status = "terminated" }); - } - return Results.Json(new { mission_status = "active" }); - - default: - return Results.Json(new { status = "ok" }); + await missions.TerminateAsync(ps.Issuer, missionS256, AAuthConstants.MissionTerminationReasons.Completed); + return Results.Json(new { mission_status = "terminated" }); } + return Results.Json(new { mission_status = "active" }); }); // Non-pre-approved permission resolution (§Permission Endpoint). The poll // returns the (scripted) user decision. app.MapMethods("/permission-pending/{id}", ["GET", "DELETE"], async ( HttpContext ctx, string id, MissionPendingStore pending, - IMissionLog log, MissionConsentScript script, IMissionStore missions) => + IMissionLog log, MissionConsentScript script, IMissionStore missions, ConsentRegistry registry) => { var entry = pending.Get(id); if (entry is null) return AAuth.Server.DeferredState.Missing(id); if (entry is null || entry.Kind != MissionPendingKind.Permission || !entry.MatchesOwner(ctx)) { - return AAuth.Server.AAuthProblemDetails.Create("unknown_pending", statusCode: StatusCodes.Status404NotFound, + return AAuth.Server.AAuthProblemDetails.Polling(PollingErrorCode.InvalidCode, extensions: new Dictionary { ["id"] = id }); } return await entry.Lifecycle.ExecuteAsync(ctx, entry.ExpiresAt, TimeProvider.System, async () => @@ -546,8 +538,8 @@ await log.AppendAsync(new MissionLogEntry( return Results.NoContent(); } // Interactive mode: hold at 202 until the user decides in the browser. - var mission = await missions.GetAsync(entry.S256, ctx.RequestAborted); - if (GovernanceEndpoints.Authorize(ctx, entry.MissionClaim, mission) is { } denied) return denied; + var mission = await missions.GetAsync(entry.PersonServer, entry.S256, ctx.RequestAborted); + if (GovernanceEndpoints.Authorize(ctx, entry.S256, mission) is { } denied) return denied; bool granted; if (script.InteractiveBrowser) { @@ -556,7 +548,7 @@ await log.AppendAsync(new MissionLogEntry( ctx.Response.Headers["Retry-After"] = "1"; ctx.Response.Headers["Cache-Control"] = "no-store"; ctx.Response.Headers[AAuthRequirementHeader.Name] = - Interaction.Format($"{psIssuer.TrimEnd('/')}/interaction", entry.Browser.Code, SampleEgress.Policy); + Interaction.Format(ps.Url("/interaction"), entry.Browser.Code, SampleEgress.Policy); return Results.Json(new { status = "pending" }, statusCode: StatusCodes.Status202Accepted); } granted = entry.Decision.Value; @@ -564,6 +556,8 @@ await log.AppendAsync(new MissionLogEntry( else { granted = script.ApprovePermission; + entry.Decision = granted; + registry.MarkDecided(entry.Id, ConsentDecider.Script); } await log.AppendAsync(new MissionLogEntry( entry.S256, MissionLogEntryKind.Permission, DateTimeOffset.UtcNow) @@ -604,16 +598,19 @@ await log.AppendAsync(new MissionLogEntry( return Results.Ok(new { ok = true, agent, resource, scope }); }); -// Demo-only: wipe all consent + pending state back to baseline so an automated +// Demo-only: wipe consent + pending state back to baseline so an automated // test harness can start each spec from a known-empty store (see the E2E suite's // resetConsent helper). A production PS would never expose this. The SDK-owned // token pending entries are id-keyed + TTL-evicted, so clearing the demo -// ConsentStore + mission stores is enough to re-baseline. -app.MapPost("/admin/reset", (ConsentStore consent, MissionPendingStore missionPending, MissionConsentScript script) => +// ConsentStore + mission stores is enough to re-baseline. Decided requests stay +// in the dashboard history; only abandoned pending ones are dropped. +app.MapPost("/admin/reset", (ConsentStore consent, MissionPendingStore missionPending, MissionConsentScript script, + ConsentRegistry registry) => { consent.Clear(); missionPending.Clear(); script.Reset(); + registry.DropPending(); return Results.Ok(new { ok = true }); }); @@ -675,7 +672,7 @@ await log.AppendAsync(new MissionLogEntry( { return AAuth.Server.AAuthProblemDetails.Create("invalid_request", "missing s256", statusCode: StatusCodes.Status400BadRequest); } - await missions.SetStateAsync(s256, MissionState.Terminated); + await missions.TerminateAsync(ps.Issuer, s256, AAuthConstants.MissionTerminationReasons.Administrative); policy.Remove(s256); return Results.Ok(new { ok = true, s256, mission_status = "terminated" }); }); @@ -709,7 +706,8 @@ await log.AppendAsync(new MissionLogEntry( // (cookie/passkey/SSO); here we trust the demo environment and just look // up the pending entry by its single-use code. The form submits to // /interaction/approve or /interaction/deny. -app.MapMethods("/interaction", ["GET", "POST"], async (HttpContext ctx, IPersonPendingStore pending, MissionPendingStore missionPending, MissionPolicyStore missionPolicy) => +app.MapMethods("/interaction", ["GET", "POST"], async (HttpContext ctx, + [FromKeyedServices(AAuthPersonServerBuilder.DefaultName)] IPersonPendingStore pending, MissionPendingStore missionPending, MissionPolicyStore missionPolicy) => { var entered = await browserConsent.EnterAsync(ctx, supplied => { @@ -882,15 +880,29 @@ await log.AppendAsync(new MissionLogEntry( + "form{margin-top:1.5rem;display:inline-flex;gap:.75rem}" + "button{padding:.5rem 1rem;font-size:1rem;cursor:pointer;border-radius:.25rem;border:1px solid #999}" + "button.approve{background:#6ee7b7;border-color:#34d399}" - + "button.deny{background:#fecaca;border-color:#f87171}" + + "button.deny{background:#fecaca;border-color:#f87171}" + + "section{border-radius:.4rem;padding:.5rem .9rem;margin:.9rem 0}section h2{font-size:.95rem;margin:.2rem 0 .4rem}" + + ".resource-asserted{background:#eff6ff;border:1px solid #bfdbfe}" + + ".agent-asserted{background:#fffbeb;border:1px dashed #f59e0b}" + + ".agent-asserted blockquote{white-space:pre-wrap;margin:.3rem 0;font-style:italic}" + "
Person Server
" + "
localhost:5100 — the server that holds your resources and standing consent
" + "

An agent is requesting access on your behalf

" + "

Signed in as the isolated demo user at the Person Server.

" + $"
Agent: {System.Net.WebUtility.HtmlEncode(entry.AgentId)}
" + // §Consent Presentation: resource-asserted and agent-asserted content are + // shown apart, and the agent's words are attributed to the agent. + + "

From the resource

" + $"
Resource: {System.Net.WebUtility.HtmlEncode(entry.ResourceUrl)}
" + $"
Scope: {System.Net.WebUtility.HtmlEncode(entry.Scope)}
" + (entry.Account is null ? "" : $"
Account: {System.Net.WebUtility.HtmlEncode(entry.Account)}
") + + "
" + + (entry.AgentAsserted is not { } agentSays ? "" : + "

The agent says (not verified)

" + + (agentSays.Justification is null ? "" : $"
{System.Net.WebUtility.HtmlEncode(agentSays.Justification)}
") + + (agentSays.Platform is null ? "" : $"
Platform: {System.Net.WebUtility.HtmlEncode(agentSays.Platform)}
") + + (agentSays.Device is null ? "" : $"
Device: {System.Net.WebUtility.HtmlEncode(agentSays.Device)}
") + + "
") + "
" + decisionFields + "" @@ -906,7 +918,8 @@ await log.AppendAsync(new MissionLogEntry( // consent for the entry's (agent, resource, scope) triple, and shows a // confirmation page. Idempotent: re-submitting a code whose entry is // already approved still 200s. -app.MapPost("/interaction/approve", async (HttpContext ctx, ConsentStore consent, IPersonPendingStore pending, MissionPendingStore missionPending, IIdentityClaimsAsserter asserter) => +app.MapPost("/interaction/approve", async (HttpContext ctx, + [FromKeyedServices(AAuthPersonServerBuilder.DefaultName)] IPersonPendingStore pending, MissionPendingStore missionPending, PersonConsentDecisions decisions) => { var decision = await browserConsent.DecideAsync(ctx); if (decision.Error is not null) return decision.Error; @@ -922,8 +935,8 @@ await log.AppendAsync(new MissionLogEntry( { return await decision.Decision.ApplyAsync(ctx, () => { - if (mission.Decision is not null) return AAuth.Server.AAuthProblemDetails.Create("invalid_code", statusCode: 400); - mission.Decision = true; + if (decisions.ApplyHeld(mission, approve: true, ConsentDecider.Link) != ConsentOutcome.Applied) + return AAuth.Server.AAuthProblemDetails.Create("invalid_code", statusCode: 400); return Results.Content( "Approved — Person Server" + "