Skip to content

docs(enrollment): bind pending password state to host ceremony - #39

Merged
Sequela02 merged 1 commit into
mainfrom
release/8.0.1
Sep 13, 2026
Merged

Sequela02 merged 1 commit into
mainfrom
release/8.0.1

Conversation

@Sequela02

Copy link
Copy Markdown
Contributor

Summary

Clarifies the host-owned password boundary during contact enrollment and prepares Vigil 8.0.1.

  • permits hosts to collect a password before or after contact verification;
  • requires a server-issued, fixation-resistant ceremony and explicit intent before a pending password verifier can reach EnrollmentService.verify;
  • requires independent restart without inherited proof, receipt, verifier, or authority when ceremony continuity is unavailable;
  • preserves Vigil's route-free, provider-neutral, credential-free runtime and public API.

ADR 0004 owns the decision. The enrollment guide, security model, API contract, system boundaries, ADR 0002, Javadoc, documentation index, compatibility reference, README, and changelog project the relevant parts without adding a parallel implementation.

Security boundary

A receipt is evidence that Vigil accepted the bound contact proof. APPLIED means the host applied that receipt, and COMPLETED is Vigil's acknowledgement; none independently authorizes a credential or account link.

Hosts with pending password state must validate ceremony continuity and CSRF protection before calling verify, then revalidate and consume any receipt-bound finalization permission first-write-wins after COMPLETED. Invalid requests cannot retire another ceremony. Email equality never authorizes classic/federated account linking.

OPAQUE_TOKEN may use a GET interstitial followed by POST. DECIMAL_CODE uses a host form and POST. Neither transport proves ceremony continuity.

Release

  • version: 8.0.1
  • compatibility: Java 25 / Spring Boot 4.1.1 unchanged
  • binary/runtime/configuration changes: none
  • migration: none

Verification

  • gradlew.bat clean check --no-daemon
  • gradlew.bat qualityCheck build publishToMavenLocal --no-daemon --no-configuration-cache
  • Maven-local JAR, sources, Javadoc, POM, and module metadata verified as 8.0.1
  • local Markdown links and the referenced USENIX source verified
  • git diff --check
  • independent Astra and Sol reviews: no actionable findings

Host ceremony, CSRF, credential activation, and account-linking tests remain the responsibility of each consuming application because Vigil owns none of that runtime state.

Closes #38

@Sequela02
Sequela02 merged commit 4ef31a3 into main Sep 13, 2026
3 checks passed
@Sequela02
Sequela02 deleted the release/8.0.1 branch September 13, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Clarify host-owned pending password state during contact enrollment

1 participant