Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
118 commits
Select commit Hold shift + click to select a range
e6d18a3
docs: vendor draft-11 WIP and map migration impact
dasiths Sep 11, 2026
0769a0b
docs: add draft-11 questions for the specification author
dasiths Sep 11, 2026
5f15f87
Add upgrade documentation for transitioning from AAuth Protocol -10 t…
dasiths Sep 28, 2026
eef4175
Merge remote-tracking branch 'origin/main' into wip/aauth-draft-11
dasiths Sep 28, 2026
f1e46de
docs: update implementation log and plan for AAuth draft-11 migration
dasiths Sep 28, 2026
05ea90c
feat(sdk): cut over draft-11 vocabulary, signature errors and agent i…
dasiths Sep 28, 2026
9a5ca3e
feat(events)!: bind subscription tickets to the agent key thumbprint
dasiths Sep 28, 2026
cc3d1b1
feat(sdk)!: cut over to draft-11 person tokens and presented-token pairs
dasiths Sep 28, 2026
f47f3d3
docs(plan): log draft-11 cutover decisions, bugs and open items
dasiths Sep 28, 2026
e1e85c0
docs(plan): pin v10 plan links to files removed by draft-11
dasiths Sep 28, 2026
e8c42ba
docs(samples): show the draft-11 person-token flow in page snippets
dasiths Sep 28, 2026
2951726
refactor(bookings): drop the mission_aware metadata flag
dasiths Sep 28, 2026
3977804
docs: describe the draft-11 identity model across the SDK docs
dasiths Sep 28, 2026
f5961d8
fix(verification): report a revoked Signature-Key token as revoked_jwt
dasiths Sep 28, 2026
979ce07
refactor(governance)!: rename mission Approver members to PersonServer
dasiths Sep 28, 2026
e14857d
docs(plan): log revoked_jwt, Approver rename, docs sweep and e2e base…
dasiths Sep 28, 2026
f4b9481
fix(agent): reuse a cached person token for account-scoped requests
dasiths Sep 28, 2026
24fac1e
feat(verification): trust person-token issuers separately from auth-t…
dasiths Sep 28, 2026
1449f8a
test(e2e): migrate SampleApp demos and specs to the draft-11 flow
dasiths Sep 28, 2026
e5114a8
feat(tour): walk every GuidedTour flow through the draft-11 person-to…
dasiths Sep 28, 2026
be7211c
refactor(agent)!: rename MissionHeaderHandler to MissionContextHandler
dasiths Sep 28, 2026
f8e0790
docs(plan): log e2e-found SDK fixes, tour migration and final gates
dasiths Sep 28, 2026
7a35bd0
fix(issuance): name the expired source token on fresh token requests
dasiths Sep 28, 2026
9fe8ffb
test(e2e): isolate demo server state from the developer's ~/.aauth
dasiths Sep 28, 2026
7a1ab63
test(issuance): cover SourceExpired parameter, Signature-Key and fall…
dasiths Sep 28, 2026
89cd34d
docs: move remaining spec links to v11 and correct Signature Keys cit…
dasiths Sep 28, 2026
2a73d74
test(ps): prove an upstream token from a revoked calling agent is ref…
dasiths Sep 28, 2026
4cd3bda
feat: add implementation log and research documentation for PS consen…
dasiths Sep 28, 2026
dcefc0e
feat(revocation)!: cut token revocation over to the draft-11 {jti, ex…
dasiths Sep 28, 2026
502e554
feat(governance): issue person_tokens in the mission approval response
dasiths Sep 28, 2026
79f86d3
docs(plan): log rulings for the six post-cutover open items
dasiths Sep 28, 2026
042c07a
docs(plan): fold the post-cutover items into their phases and tick ev…
dasiths Sep 28, 2026
4d077d5
docs(plan): correct the folded-item count to 12
dasiths Sep 28, 2026
0cdd7e9
docs(plan): name the 12 post-cutover items in closing-out step 1
dasiths Sep 28, 2026
368aa85
feat(r3)!: rename r3_conditional to r3_per_call
dasiths Sep 28, 2026
f849825
feat(r3)!: drop the version field from R3 documents and proposals
dasiths Sep 28, 2026
88c0882
feat(r3)!: remove the OpenAPI Gateway vocabulary; Catalog uses one me…
dasiths Sep 28, 2026
ad40801
feat(r3): per-call access mode and operation access annotations
dasiths Sep 28, 2026
af521e3
docs(plan): log the R3 draft-11 wire cutover and tick its Phase 8 boxes
dasiths Sep 28, 2026
caa57e9
fix(revocation): require content-digest/content-type coverage at ever…
dasiths Sep 28, 2026
a907e9f
fix(events)!: event tokens carry jti; AP and agent dedupe on (iss, jti)
dasiths Sep 28, 2026
dff0f96
feat(person): agent-person binding revocation for upstream step 4
dasiths Sep 29, 2026
fbd01e6
fix(samples): MockAgentProvider refresh answers signature failures wi…
dasiths Sep 29, 2026
62ac79e
fix(governance): a deferred mission approval keeps the approver's exp…
dasiths Sep 29, 2026
c4ed702
refactor(samples)!: rename the Wallet DirectAs flow to AsGrantChaining
dasiths Sep 29, 2026
dc91899
fix(samples): PS demo route revokes only at the ASes a person token w…
dasiths Sep 29, 2026
0927928
feat(revocation): per-issuer entry and rate bounds with 429 rate_limited
dasiths Sep 29, 2026
b13d994
feat(revocation): deferred 202 revocation with caller-bound polling
dasiths Sep 29, 2026
3463a22
[Phase 5] Agents reuse mission person tokens
dasiths Sep 29, 2026
e6bd173
[Phase 3] Mission approvals carry person_tokens; partial resource app…
dasiths Sep 29, 2026
1a345b0
[Phase 2] Test person-token lifetime bounds and request fields
dasiths Sep 29, 2026
4504d64
[Phase 3] Mission store keeps terminal state and expiry; test update …
dasiths Sep 29, 2026
79a1d4f
[Phase 4] Test the prerequisite and step-up legs and identity overwrite
dasiths Sep 29, 2026
f152101
[Phase 4] Require body coverage at PS and AS; map AS timeouts apart f…
dasiths Sep 29, 2026
16028de
[Phase 4] Attribute agent-asserted consent content
dasiths Sep 29, 2026
9e1dea2
[Phase 5] Support 202 auth-token delivery; retain held results; refre…
dasiths Sep 29, 2026
13426ce
[Phase 6] Accepted mission updates end the consent fast path; delegat…
dasiths Sep 29, 2026
f72f786
[Phase 7] Test resource-token independence and cascade retention
dasiths Sep 29, 2026
a864f7d
[Phase 8] R3 per-call single use, per-document readership, release ga…
dasiths Sep 29, 2026
ffcabde
[Phase 3, 7] termination_reason; refuse withdrawn resource tokens
dasiths Sep 29, 2026
537d935
[Phase 0] Re-derive citations; own F01-F24 and every checklist ID
dasiths Sep 29, 2026
b302726
[Phase 9, 10] Reproduce P1 findings by mutation; sweep stale mission …
dasiths Sep 29, 2026
815b1dd
[Phase 11] Independent review, Keycloak run, draft-11 target language
dasiths Sep 29, 2026
ecc71e7
[Closure] Draft-11 migration complete
dasiths Sep 29, 2026
6f23f61
Rename demo state folder to aauth-samples/demo-home
dasiths Sep 29, 2026
e2154a1
Refactor code structure for improved readability and maintainability
dasiths Sep 29, 2026
623dd06
[Plan] SDK API surface consistency (server + client)
dasiths Sep 29, 2026
1045186
[Plan] SDK API surface: adversarial review of Q1-Q18
dasiths Sep 29, 2026
a23cb99
[Plan] Owner rulings Q16/Q19; PS consent dashboard goes next
dasiths Sep 29, 2026
11751f3
[Phase 0] PS consent dashboard: owner accepts defaults Q4-Q15
dasiths Sep 29, 2026
4692e8b
[Phase 1] PS consent dashboard: decision service and consent registry
dasiths Sep 29, 2026
351178a
[Phase 2] PS consent dashboard: endpoints, UI, tests
dasiths Sep 29, 2026
068c780
samples: Person Server approval prompt for SampleApp and walkthroughs
dasiths Sep 29, 2026
7422adf
samples: GuidedTour polls on arrival at Person Server consent
dasiths Sep 29, 2026
6b88e05
samples: CLIs and demo banners point at the PS dashboard
dasiths Sep 29, 2026
79bca06
docs: consent dashboard and poll-first guidance
dasiths Sep 29, 2026
d182458
samples: dashboard only renders http(s) Access Server links
dasiths Sep 29, 2026
0ba8f78
samples: consent dashboard and prompt UX tidy-up
dasiths Sep 29, 2026
9d5a182
[Plan] SDK API surface: Phase 0 baseline after the dashboard
dasiths Sep 29, 2026
9e0c331
[Phase 1] SDK API surface: typed termination reasons, labels, dead code
dasiths Sep 29, 2026
b59f110
[Phase 2a] SDK API surface: TimeProvider replaces clock delegates
dasiths Sep 29, 2026
a955279
[Phase 2b-e] SDK API surface: trust seam, seam resolver, settable opt…
dasiths Sep 29, 2026
8fa6a99
[Phase 3] SDK API surface: async signing abstraction and key sets
dasiths Sep 29, 2026
2893ea6
[Phase 4] SDK API surface: server role registration
dasiths Sep 30, 2026
58dc8b8
[Phase 5] SDK API surface: server feature seams
dasiths Sep 30, 2026
fe6aef7
[Phase 6] SDK API surface: revocation service
dasiths Sep 30, 2026
6213175
[Phase 7] SDK API surface: agent registration, factory, configuration
dasiths Sep 30, 2026
b5d20d1
[Phase 8] SDK API surface: client callbacks
dasiths Sep 30, 2026
b2d7de7
feat(agent): token cache, keyed typed clients and client lifetime (Ph…
dasiths Sep 30, 2026
5dbb55a
feat(samples): SampleApp pages use the registered Aria agent (Phase 10a)
dasiths Sep 30, 2026
4b5c762
feat(samples): Concierge, MissionAgent, AgentConsole and events on DI…
dasiths Sep 30, 2026
63a1314
feat(person): consent-dashboard seams and the bare pending 202 (Phase…
dasiths Sep 30, 2026
8452e68
docs(plan): close Phase 10 with DoD evidence
dasiths Sep 30, 2026
60ecab8
docs: configuration reference, extensibility patterns and Phase 11 sweep
dasiths Sep 30, 2026
30b8015
docs(plan): Phase 12 independent review and final gates
dasiths Sep 30, 2026
a45e0a2
fix(verification): bind auth/person token aud to the resource identit…
dasiths Sep 30, 2026
0fabb3c
feat: signing created, metadata validation and Events fixes (Phase 2)
dasiths Sep 30, 2026
36c2eca
feat(verification): JWT hygiene, four-party trust and person-token au…
dasiths Sep 30, 2026
096bd94
feat(deferred): shared poll core and registered error tables (Phase 4)
dasiths Sep 30, 2026
697ca9b
docs(plan): record upstream replay-tuple message to the spec author
dasiths Sep 30, 2026
171540d
feat(revocation): source guard before outbound presentation and scope…
dasiths Sep 30, 2026
f513ea1
feat(chaining): upstream provenance and intermediary-owned interactio…
dasiths Sep 30, 2026
4576fbf
fix(samples): intermediary interaction URL is public; step-up expecta…
dasiths Sep 30, 2026
015e6be
feat(revocation): cancel an in-flight federation send when a source i…
dasiths Sep 30, 2026
f9194bb
feat(r3): execute-once per-call grants, complete audit, per-token ent…
dasiths Sep 30, 2026
8b33eb2
feat(person): agent-person binding, pairwise subjects and governance …
dasiths Oct 1, 2026
ab31e03
feat(missions): single status evaluator, (PS, s256) identity, termina…
dasiths Oct 1, 2026
c11ed3c
feat(person): updated_request bounds, shared input validation, clarif…
dasiths Oct 1, 2026
d89799d
feat(governance): one governance declaration, 424/202 relay results, …
dasiths Oct 1, 2026
59db2ad
feat(federation): explicit PS-AS collapse, 402 payment loop, claims s…
dasiths Oct 1, 2026
0dd8f13
feat(agent): login_hint, verified auth tokens, refresh margin, PS-fir…
dasiths Oct 1, 2026
0bd74e0
feat(samples): Mock Person Server on SDK governance mapping and missi…
dasiths Oct 1, 2026
fc1e677
feat(samples): samples sweep — SDK polling, same-origin pending, gene…
dasiths Oct 1, 2026
07c02d5
docs: draft-11 walkthrough, signing modes, five access modes and rest…
dasiths Oct 1, 2026
3478894
fix: Phase 13 review and re-audit — fail-closed source guard, registe…
dasiths Oct 1, 2026
f4ddb34
fix(samples): poll on arrival for every consent; Run all never parks
dasiths Oct 1, 2026
fb1b6c7
docs: draft-11 alignment pass for docs and rendered sample snippets
dasiths Oct 1, 2026
dd9be33
docs: add AAuth community collaboration deck
dasiths Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2,930 changes: 2,930 additions & 0 deletions .agent/decks/aauth-community-collaboration.html

Large diffs are not rendered by default.

2,002 changes: 2,002 additions & 0 deletions .agent/decks/secret-agent-coop-architecture.html

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -1879,7 +1879,7 @@ Public owners: `AAuth.AAuthFederationOptions`, `AAuth`.

### src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs

Concept/decision: [di](#di). Source: [AAuthFederationServiceCollectionExtensions.cs](../../../src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs).
Concept/decision: [di](#di). Source: `src/AAuth/DependencyInjection/AAuthFederationServiceCollectionExtensions.cs` (since removed; federation is now `AAuthPersonServerBuilder.WithFederation()`).

```diff
- Microsoft.Extensions.DependencyInjection.AAuthFederationServiceCollectionExtensions: public static IServiceCollection AddAAuthFederation ( this IServiceCollection services , AAuthKey personServerKey , string personServerIssuer , string personServerKeyId )
Expand Down Expand Up @@ -2970,7 +2970,7 @@ Public owners: `AAuth.Tokens.AccountBinding`, `AAuth.Tokens.AccountExpectation`,

### src/AAuth/Tokens/ActChainBuilder.cs

Concept/decision: [tokens](#tokens). Source: [ActChainBuilder.cs](../../../src/AAuth/Tokens/ActChainBuilder.cs).
Concept/decision: [tokens](#tokens). Source: [ActChainBuilder.cs](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs).

```diff
- AAuth.Tokens.ActChainBuilder: public static JsonObject BuildNestedAct ( string upstreamAgentId , JsonObject ? upstreamChain = null )
Expand All @@ -2983,7 +2983,7 @@ Public owners: `AAuth.Tokens.ActChainBuilder`, `AAuth.Tokens`.

### src/AAuth/Tokens/ActChainReader.cs

Concept/decision: [tokens](#tokens). Source: [ActChainReader.cs](../../../src/AAuth/Tokens/ActChainReader.cs).
Concept/decision: [tokens](#tokens). Source: [ActChainReader.cs](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainReader.cs).

```diff
- AAuth.Tokens.ActChainReader: public static IReadOnlyList < string > GetDelegationChain ( JsonObject payload , int maxDepth = 10 )
Expand Down Expand Up @@ -3083,7 +3083,7 @@ Public owners: `AAuth.Tokens.AuthTokenDeliveryResult`, `AAuth.Tokens.AuthTokenRe

### src/AAuth/Tokens/MissionClaim.cs

Concept/decision: [tokens](#tokens). Source: [MissionClaim.cs](../../../src/AAuth/Tokens/MissionClaim.cs).
Concept/decision: [tokens](#tokens). Source: [MissionClaim.cs](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/MissionClaim.cs).

```diff
- AAuth.Tokens.MissionClaim: public static MissionClaim ? FromPayload ( JsonObject ? payload )
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,7 @@ not be mistaken for a current runtime contract.
| [Reauthorization L1338](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1338), agent expiry limits and renewed consent | PS/AS minting, [AuthTokenBuilder](../../../src/AAuth/Tokens/AuthTokenBuilder.cs) | Implemented: [IssuanceBoundsTests](../../../tests/AAuth.Conformance/AuthTokens/IssuanceBoundsTests.cs); Wallet fresh-grant recovery browser cases |
| [Mission creation/approval L1350](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1350), exact bytes/hash L1428 | [Mission](../../../src/AAuth/Agent/Mission.cs), governance builder/store | Implemented: [MissionS256Tests](../../../tests/AAuth.Conformance/Missions/MissionS256Tests.cs), [MissionModelTests](../../../tests/AAuth.Conformance/Missions/MissionModelTests.cs), HTTP mission approvals |
| [Mission log/completion/status L1432](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1432), permanently terminated L1449/L1455 | Governance mapper and PS state gates | Implemented terminal rejection: [MissionTerminatedTests](../../../tests/AAuth.Conformance/Missions/MissionTerminatedTests.cs), new signed three-endpoint tests and deferred completion tests. Production store permanence/retention is Policy |
| [Mission presentation L1488](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1488), no dereference L1490 and exact reference echo | [Mission header](../../../src/AAuth/Agent/Mission.cs), challenge/chain handlers | Implemented reference-only data flow: [MissionReferenceValidationTests](../../../tests/AAuth.Conformance/Missions/MissionReferenceValidationTests.cs), [MissionHeaderSeamTests](../../../tests/AAuth.Conformance/Missions/MissionHeaderSeamTests.cs), [MissionSignedComponentTests](../../../tests/AAuth.Conformance/HttpSignatures/MissionSignedComponentTests.cs). Resource/AS have no mission-fetch implementation; no arbitrary application callback guarantee |
| [Mission presentation L1488](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1488), no dereference L1490 and exact reference echo | [Mission header](../../../src/AAuth/Agent/Mission.cs), challenge/chain handlers | Implemented reference-only data flow: [MissionReferenceValidationTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/Missions/MissionReferenceValidationTests.cs), [MissionHeaderSeamTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/Missions/MissionHeaderSeamTests.cs), [MissionSignedComponentTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/HttpSignatures/MissionSignedComponentTests.cs). Resource/AS have no mission-fetch implementation; no arbitrary application callback guarantee |
| [PS-to-AS request L1503](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1503), child/upstream propagation and signing | [AccessServerClient](../../../src/AAuth/Access/AccessServerClient.cs), [AgentIssuanceContext](../../../src/AAuth/Tokens/AgentIssuanceContext.cs) | Implemented: [AccessServerClientTests](../../../tests/AAuth.Tests/AccessServerClientTests.cs), [DeferredFederationTests](../../../tests/AAuth.Conformance/Person/DeferredFederationTests.cs). Q2 uses normative Signature Keys jwks_uri discovery, not stale protocol example syntax |
| [AS response/delivery L1531](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1531), claims composition L1581 | AS endpoints, [AuthTokenResponseValidator](../../../src/AAuth/Tokens/AuthTokenResponseValidator.cs) | Implemented: [AuthTokenDeliveryTests](../../../tests/AAuth.Conformance/AuthTokens/AuthTokenDeliveryTests.cs), [MockAccessServerTests](../../../tests/AAuth.Tests/Integration/MockAccessServerTests.cs); reserved claim requests/pushes rejected |
| [Signed requested claims L1599](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1599) (#requirement-claims), [clarification action L1054](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1054) (#agent-response-to-clarification) | [TokenRequestBody](../../../src/AAuth/Server/TokenRequestBody.cs), [AS pending dispatch](../../../src/AAuth/Access/AAuthAccessServerEndpoints.cs) | Implemented, 2026-09-09 final repair: ClaimsPushPreservesRequestedCredentialNamedIdentity in [DeferredFederationTests](../../../tests/AAuth.Conformance/Person/DeferredFederationTests.cs) preserves policy-requested credential-like names and action values through signed HTTP issuance; trusted pending state controls dispatch. Raw duplicate/nested-duplicate and reserved/typed-identity failures leave policy and pending state unchanged; initial and updated-request malformed credential matrices retained |
Expand All @@ -84,7 +84,7 @@ not be mistaken for a current runtime contract.
| [Upstream verification L1766](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1766), AS/PS route L1784, directed sub L1800 | [UpstreamTokenValidator](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs), [CallChainingRouter](../../../src/AAuth/Server/CallChaining/CallChainingRouter.cs) | Implemented: [UpstreamTokenValidationTests](../../../tests/AAuth.Conformance/AuthTokens/UpstreamTokenValidationTests.cs), DirectAsChainingUsesAccessMetadataAndAgentCarrier / RejectsUnboundAuthorization in DeferredFederationTests; distinct intermediary key and audience are preserved |
| [Interaction chaining L1819](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1819) | Concierge and shared interaction helpers | Implemented representative flows: [InteractionChainingTests](../../../tests/AAuth.Tests/Agent/InteractionChainingTests.cs), call-chain deferred browsers. Intermediary-owned pending storage requires its own ownership/retention controls; see review limits below |
| [Sub-agents L1825](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1825), single depth and parent authorization L1859 | AgentIssuanceContext, agent identifiers and token builders | Implemented: [PersonServerMapperTests](../../../tests/AAuth.Conformance/Person/PersonServerMapperTests.cs), four-party [FederatedWorkerScenario](../../../samples/FederatedWorkerScenario.cs) and both sub-agent browser specs |
| [Delegation chain L1874](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1874), actor nesting/no person identifiers | [ActChainBuilder](../../../src/AAuth/Tokens/ActChainBuilder.cs), [ActChainReader](../../../src/AAuth/Tokens/ActChainReader.cs) | Implemented: [ActChainBuilderTests](../../../tests/AAuth.Conformance/AuthTokens/ActChainBuilderTests.cs), [ActChainReaderTests](../../../tests/AAuth.Conformance/AuthTokens/ActChainReaderTests.cs) |
| [Delegation chain L1874](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1874), actor nesting/no person identifiers | [ActChainBuilder](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs), [ActChainReader](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainReader.cs) | Implemented: [ActChainBuilderTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/AuthTokens/ActChainBuilderTests.cs), [ActChainReaderTests](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/tests/AAuth.Conformance/AuthTokens/ActChainReaderTests.cs) |
| [Third-party login L1928](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L1928), conditional ps/start_path validation L2000 | Metadata field only | Optional unsupported by sample hosts. No login_endpoint flow is advertised/implemented by the migration; hosts enabling their own endpoint must validate PS discovery and same-origin relative start_path. Metadata serialization tests do not establish login conformance |
| [Capabilities L2010](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L2010), ignore unknown/no assumed capabilities | [AAuthCapabilitiesHeader](../../../src/AAuth/Agent/AAuthCapabilitiesHeader.cs), exchange options | Implemented: [CapabilitiesHeaderTests](../../../tests/AAuth.Conformance/HttpSignatures/CapabilitiesHeaderTests.cs), client callback/capability tests |
| [Scopes L2034](../../../aauth-spec/v10/draft-hardt-oauth-aauth-protocol.md#L2034), identity scopes and account L2051 | Scope validation and [AccountBinding](../../../src/AAuth/Tokens/AccountBinding.cs) | Implemented: [ScopeVocabularyTests](../../../tests/AAuth.Conformance/ResourceTokens/ScopeVocabularyTests.cs), [AccountBindingTests](../../../tests/AAuth.Tests/Tokens/AccountBindingTests.cs), two-account Bookings/Events browsers |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -207,7 +207,7 @@ file even when it has zero snippets; a file hash detects prose/navigation change
| [samples/GuidedTour/CodeSnippets.cs](../../../samples/GuidedTour/CodeSnippets.cs) | `ff4d96d0e9b8f5cf58beba47bb15c3ed4dfcf72651ac8c6ba740489aeed10ea3` | 42 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| [samples/GuidedTour/Components/_Imports.razor](../../../samples/GuidedTour/Components/_Imports.razor) | `ff71bc5b618f275846e5fc70ad99cd64d493b8bf198d6b604d7105764bbd08a0` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| [samples/GuidedTour/Components/App.razor](../../../samples/GuidedTour/Components/App.razor) | `848293d6fb5463468a75591d228c60beb0b52c8c187d2fa9882d393d77f4b143` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| [samples/GuidedTour/Components/CapabilityTourChrome.razor](../../../samples/GuidedTour/Components/CapabilityTourChrome.razor) | `53bb329bec371f05041a298da8d6f30bb41af8597553f04de66bcc6e6f1ec724` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| `samples/GuidedTour/Components/CapabilityTourChrome.razor` (removed; flows 12–15 now run in `/tour`) | `53bb329bec371f05041a298da8d6f30bb41af8597553f04de66bcc6e6f1ec724` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| [samples/GuidedTour/Components/EntityHighlighter.cs](../../../samples/GuidedTour/Components/EntityHighlighter.cs) | `44dbe8b987a09db2021e280d3156ac5fb1b59a30854adc611f3f153d509ab829` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| [samples/GuidedTour/Components/Pages/Catalog.razor](../../../samples/GuidedTour/Components/Pages/Catalog.razor) | `3d9fdad1a7512894272e75a106ba55030e8f5c8644e7d0b726b8954dd0c7c8ce` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
| [samples/GuidedTour/Components/Pages/Documents.razor](../../../samples/GuidedTour/Components/Pages/Documents.razor) | `744149b225526a8f806399051240443a71157683b6ad2551d5b756f940fdc556` | 0 | Frozen source; links/patterns; blocks below; capability matrix for runtime/browser evidence |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -418,7 +418,7 @@ Phase rule: preserve authenticated context end to end; no placeholder consent gr
- Complete [UpstreamTokenValidator](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs)
structural validation without incorrectly equating the original upstream PoP
key to the intermediary's current request key.
- Tighten [ActChainBuilder](../../../src/AAuth/Tokens/ActChainBuilder.cs), readers,
- Tighten [ActChainBuilder](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs), readers,
and [AuthTokenResponseValidator](../../../src/AAuth/Tokens/AuthTokenResponseValidator.cs):
immediate actor, nested context, no person identifiers, independently asserted
downstream sub. Extend agent delivery checks as well as PS-side checks.
Expand Down
4 changes: 2 additions & 2 deletions .agent/plans/2026-09-08-aauth-v10-spec-migration/research.md
Original file line number Diff line number Diff line change
Expand Up @@ -341,8 +341,8 @@ P2, R; pre-existing structural gap, with a v10 actor prohibition.
[UpstreamTokenValidator L219](../../../src/AAuth/Tokens/UpstreamTokenValidator.cs#L219)
uses generic JWT verification without all those checks. Trust and audience
checks exist. [P1809] (`#directed-sub-chaining`) prohibits person
identifiers inside `act`; [ActChainBuilder L32](../../../src/AAuth/Tokens/ActChainBuilder.cs#L32)
clones upstream objects and [L55](../../../src/AAuth/Tokens/ActChainBuilder.cs#L55)
identifiers inside `act`; [ActChainBuilder L32](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs#L32)
clones upstream objects and [L55](https://github.com/aauth-dev/dotnet-samples/blob/v0.10.0-alpha.1/src/AAuth/Tokens/ActChainBuilder.cs#L55)
only checks agent presence/depth. Direct top-level upstream `sub` copying was
not found. [AuthTokenBuilder L211](../../../src/AAuth/Tokens/AuthTokenBuilder.cs#L211)
blocks only already-populated extra claims, allowing unset reserved fields such
Expand Down
Loading
Loading