Skip to content

[Enhancement]: Identity required enforcement in Spectrum / CLI run path #73

Description

@rosspeili

Area (optional)

core framework

Problem or use case

#55 adds identity_required config and IdentityRequiredError. Enterprise full-bind posture should wire this into Spectrum (#27) and aura run so regulated projects fail fast when no verified operator is present.

Proposed behavior

  • Spectrum preset full-bind sets identity_required: true by default
  • aura run documents required env vars (AURA_OIDC_TOKEN, etc.)
  • Audit report finding when session ran without verified operator but policy expected one
  • CLI --require-identity flag override for one-off runs

Alternatives considered (optional)

Always require identity globally — rejected; breaks OSS zero-config path.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cliaura CLI commands and output.core frameworkSession, spine, constraints, conformance, identity, audit report.enhancementNew feature or improvement request.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions