generated from coulomb/repo-seed
Align IAM Profile consumption with v0.2
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# examples/claims/
|
||||
|
||||
Contract fixtures for the NetKingdom IAM Profile v0.1 claim shapes
|
||||
Contract fixtures for the NetKingdom IAM Profile v0.2 claim shapes
|
||||
flex-auth must accept. Each file is the *raw verified claim map* as
|
||||
flex-auth receives it from the upstream identity layer (key-cape or
|
||||
Keycloak); flex-auth's normalization produces the same
|
||||
@@ -11,10 +11,10 @@ surface.
|
||||
|
||||
| Fixture | Provider | Demonstrates |
|
||||
| --- | --- | --- |
|
||||
| `key-cape-lightweight.yaml` | key-cape lightweight mode | Profile-conformant minimum: single audience, top-level `roles` array, single-factor `amr=pwd`. |
|
||||
| `keycloak-heavy.yaml` | Keycloak production | Full variation set: `realm_access.roles` + `resource_access.<client>.roles`, scope as space-separated string, MFA via `amr=otp`, multiple audiences. |
|
||||
| `service-account.yaml` | Either provider | Hub-to-hub service account; `service` + `operator` roles, no `preferred_username`, narrow scope. |
|
||||
| `emergency.yaml` | Either provider | Break-glass human identity; `emergency` role, short expiry, hardware MFA, audit-trail metadata in an `emergency` claim. |
|
||||
| `key-cape-lightweight.yaml` | key-cape lightweight mode | Profile-conformant minimum: single audience, top-level `roles` array, explicit tenant/principal/assurance. |
|
||||
| `keycloak-heavy.yaml` | Keycloak production | Full variation set: canonical `roles`, provider-native role sources, scope as space-separated string, MFA assurance, multiple audiences. |
|
||||
| `service-account.yaml` | Either provider | Service account; `principal_type: service`, `service` + `operator` roles, no `preferred_username`, narrow scope. |
|
||||
| `emergency.yaml` | Either provider | Break-glass human identity; `emergency` role, `assurance.level: break_glass`, short expiry, audit-trail metadata in an `emergency` claim. |
|
||||
| `keycloak-group-overage.yaml` | Entra/Keycloak | Group-claim overage signal (`hasgroups: true`); flex-auth's directory resolver fetches the full set. |
|
||||
|
||||
These fixtures are loaded by the standalone evaluator's contract tests
|
||||
|
||||
Reference in New Issue
Block a user