#96 FTX-96: new-tenant auth namespaces are strict by default (auth 3.0.0) — member provisioning 409s
Description
EditEARS SPEC:
- When Futex provisions the first member of a tenant whose auth namespace was created after auth 3.0.0, the Futex auth oracle shall complete the membership grant successfully.
- If a membership grant is refused with HTTP 409 and reason user_not_key_backed, then Futex shall record the strict-user cause distinctly rather than surfacing an opaque transport failure.
- Where a Futex tenant namespace is created, Futex shall record its intended strict_users setting explicitly rather than inheriting the auth server default.
EVIDENCE (live, 2026-07-31, auth 3.0.0 on 127.0.0.1:4000):
- Fresh throwaway UUID4 namespace key -> GET /api/settings -> {"strict_users": true}
- POST /api/role/<r> -> 200; POST /api/membership/<keyless-user>/<r> -> HTTP 409 {"reason": "user_not_key_backed", "result": false}
- Existing Futex platform namespace -> GET /api/settings -> {"strict_users": false} (grandfathered; existing tenants unaffected)
- app/integrations/auth_client.py:110 calls .raise_for_status() on that POST, so the 409 propagates as a provisioning failure.
Blast radius: existing tenants unaffected. New tenant onboarding (member->namespace provisioning, FTX-37) fails at the first membership grant.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...