docs: plan per-installation DWH REST auth
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
|
||||
**Date:** 2026-08-20
|
||||
|
||||
**Status:** Approved in discussion; awaiting review of this written specification
|
||||
**Status:** Approved by the owner
|
||||
|
||||
## Purpose
|
||||
|
||||
@@ -105,10 +105,10 @@ beyond the approved PSD `systemd` deployment is not required by this implementat
|
||||
One credential identifies one ThothII installation, not one human user. An installation may have
|
||||
more than one temporarily active generation during rotation.
|
||||
|
||||
The external key has two components:
|
||||
The external key contains a version marker, a public key ID, and a random secret:
|
||||
|
||||
```text
|
||||
<public-key-id>.<random-secret>
|
||||
thtdwh_v1.<public-key-id>.<random-secret>
|
||||
```
|
||||
|
||||
Requirements:
|
||||
@@ -271,7 +271,10 @@ is local-only and does not weaken the authentication decision.
|
||||
|
||||
The exposed shared credential is represented temporarily as `legacy-shared`. It is imported only
|
||||
from an approved protected source and is never placed in a command argument, terminal output,
|
||||
document, or evidence file.
|
||||
document, or evidence file. Because the existing value does not use the new versioned key
|
||||
format, it is stored as the only permitted `legacy_raw` record. The service compares the digest of
|
||||
the complete opaque legacy header only for that reserved record. After `legacy-shared` is revoked,
|
||||
no unversioned credential is accepted.
|
||||
|
||||
The production route does not switch to the new authenticator until all of the following hold:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user