docs(research): distinguish Artifacts token paths and evidence - #59
Conversation
Record the direct NuGet access-token branch alongside default exchange, including SelfDescribing and Compact/PAT semantics and cache differences. Separate personal-account source support from the accepted Git observation and the still-unobserved NuGet Basic and Artifacts feed path. Align the selected Slice's PAT exclusion and downstream validation basis without adding an authentication experiment or consumer implementation. Refs: #56
|
Independent GOV-011 triage by ARTIFACTS-1: True positive — material source-summary omission; confidence 10/10. Assessed accepted revision The triager independently retrieved all six cited files from official commit
The smallest evidence correction is to distinguish both branches, defaults, caching, and conditional PAT behavior in the existing baseline; preserve shared engine-resource scope and MSA/feed evidence limits; and clarify validation can concern direct presentation or an optional derived credential. Existing architecture/decision/Wave/Issue boundaries need consistency review rather than automatic scope expansion. No new owner decision or experiment is required or authorized by this finding. No edits or experiments were performed by the triager. The accompanying architecture clarification records the owner's explicit PAT exclusion within existing engine/Slice scope. |
|
Independent review by
The reviewer independently retrieved all seven relevant official files at The source supports the opt-in direct Basic-password branch, default-off option, separate session-cache disablement while retaining MSAL caching, conditional Compact/PAT versus SelfDescribing selection, requested duration/cap versus actual service validity, and MSA handling without arbitrary-client eligibility inference. The three canonical consumers distinguish source capability, bounded accepted Git observation, selected engine scope, and unobserved NuGet/feed behavior. PAT exclusion stays within the accepted engine/Slice boundary and owner direction; no adapter or exchange fallback is selected. The reviewer inspected the independent pre-edit ARTIFACTS-1 triage and confirmed the correction addresses that omission. All seven rechecks were evaluated: no new typed decision/workstream trigger, Wave transition, release, Profile selection, cache-policy change, or runtime/support claim; accepted dated dispositions remain applicable. No native TMT role/flow or record-family change occurs. Review performed only repository and public-source reads, without subject execution, account/cache/resource access, or experiments. Normal hk and GitHub CI are separate mechanical gates. |
Summary
The existing Artifacts source summary described the default session-token exchange without its direct-access-token alternative. Record both paths, distinguish SelfDescribing from Compact/PAT, and preserve what source inspection versus the accepted personal-account Git probe actually establishes. Align the architecture's explicit PAT exclusion and downstream validation requirements.
Authorization and Governing Records
Accepted main-v2
89c67730b08736d6fe430f9382d2cbefb50f6864, its current Delivery Wave, and #56 authorize bounded public research and design for this Slice. The owner requested durable intermediate findings and explicitly excludes PATs. Existing decisions 0003/0004 and request/result/identity requirements remain authoritative.Scope and Non-Goals
Three existing Markdown records. No new record family, contract freeze, product implementation, adapter, Profile activation, native TMT edit, authentication/cache/resource access, or experiment. Artifacts stays within the selected engine acquisition scope; this change does not claim end-to-end NuGet/feed success or select a session-token fallback.
Record-System Impact
Update the current public-research baseline, architecture overview, and validation strategy together. The existing Artifacts section remains the evidence authority; architecture owns the design boundary and validation owns the remaining claim obligations. No separate scratch report or parallel conclusion ledger is created. Issue #56 carries progress.
Evidence and Reasoning
Pinned official source
bca6c32fdb9611aea25819147ef4508f730aa5fbhas opt-in direct access-token return as a NuGet Basic credential, default session-token exchange, conditional Compact/PAT selection, SelfDescribing validity handling, distinct session-cache behavior, and MSA passthrough/tenant mapping. Direct-return source also matches released v2.0.4 commit14855bba1b20482623697fe9497cc5398d5077cd. The default is not a NuGet protocol requirement; account type does not control the direct-return branch.The accepted probe proves one personal-account access-token/Git-discovery/reuse scenario. It did not use NuGet Basic authentication or access a feed. Neither universal direct-feed success nor mandatory MSA exchange follows from those observations. A shared resource/scope still supports the settled engine capability boundary.
Identity and Security Effects
Retain exact account/tenant validation and conditional external-registration eligibility. Document that upstream defaults can generate PATs; no such behavior is authorized or imported. Tokens remain opaque. No private account, target, credential, raw diagnostic, or service content is retained. The existing native threat-model roles/flows do not change.
Validation
git diff --check: passed.Review and Disposition
Root-origin finding ARTIFACTS-1 was independently triaged by
/root/discovery_finding_triagebefore corrective edits: true positive, confidence 10/10, material omission of the direct-token branch. The triager independently retrieved six files at the original source pin and confirmed defaults, cache separation, and MSA claim limits. Required correction: qualify the exchange default, add the direct path, and retain downstream evidence limits. No new owner decision or experiment was needed. Full independent triage is recorded in this PR.Independent
/root/preparation_reviewpassed both accepted Skills and contextual architecture/requirements/security/minimality review with no material findings. Reviewed base89c67730b08736d6fe430f9382d2cbefb50f6864, exact treefb85e776f38fd98812323c7fe41de1cf8937c6a5; the full independent review binding is recorded in this PR. All seven rechecks are evaluated in the refinement paragraph: no new typed trigger, Wave change, release, Profile selection, or runtime claim; current accepted dispositions remain applicable.Upstream Provenance
Official Artifacts source commits and GCM scope source are linked in the evidence authority. No production code or cache behavior imported.