>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #96
Update issue details
Title *
Description
EARS SPEC: - When Futex provisions the first member of a tenant whose auth namespace was created after auth 3.0.0, the Futex auth oracle shall complete the membership grant successfully. - If a membership grant is refused with HTTP 409 and reason user_not_key_backed, then Futex shall record the strict-user cause distinctly rather than surfacing an opaque transport failure. - Where a Futex tenant namespace is created, Futex shall record its intended strict_users setting explicitly rather than inheriting the auth server default. EVIDENCE (live, 2026-07-31, auth 3.0.0 on 127.0.0.1:4000): - Fresh throwaway UUID4 namespace key -> GET /api/settings -> {"strict_users": true} - POST /api/role/<r> -> 200; POST /api/membership/<keyless-user>/<r> -> HTTP 409 {"reason": "user_not_key_backed", "result": false} - Existing Futex platform namespace -> GET /api/settings -> {"strict_users": false} (grandfathered; existing tenants unaffected) - app/integrations/auth_client.py:110 calls .raise_for_status() on that POST, so the 409 propagates as a provisioning failure. Blast radius: existing tenants unaffected. New tenant onboarding (member->namespace provisioning, FTX-37) fails at the first membership grant.
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel