Repository navigation
Adds the general capability for a signature produced outside the signing process to be verified and incorporated: describe_decision_signing_scope and incorporate_decision_signature, plus decision_record_by_id (exact-record selection) and public_fingerprint.
Every previous signing path assumed the process holds the private key. That is true of the CLI and false of any deployment that means it when it says private keys stay with their owners — a browser, a token, an HSM, a reviewer on a machine the service will never see.
The part implementers get wrong: a decision signature is ed25519 over the UTF-8 bytes of the 64-character lowercase hex string, not over the 32 raw bytes it encodes. integrity.sign_hash has documented that as intentional and non-standard since it was written, and signing the digest produces a signature that verifies against nothing while looking entirely correct. The instruction now ships inside the returned payload, and the refusal names it when somebody gets it wrong anyway.
Verification recomputes the scope from the document it was given. A caller's claim about which bytes were signed is not evidence.
Who was permitted to sign remains a question uofa does not answer. verify continues to report cryptographic validity, the claimed actor and the signer separately, and to say plainly that authorization was not assessed.
Also carries the signer-classification fix from #133: _FINGERPRINT could not match the sha256: form the product actually emits, so the signer was unclassifiable in every real package and derive_relation fell through to unrelated universally — including where actor and signer were byte-for-byte equal.
Artifact
uofa-0.18.0-py3-none-any.whl
sha256 93286134150933f755a4e0dfd320d316ad505cf746fd897ac139cb91af754d89
Rebuilds byte-identically from this tag. Not published to PyPI.
Suite: 3,499 passed, 15 skipped.