docs(plans): plan the S09 permission verdicts, and the criterion 26 amendment Step 9 relies on

What

Implementation plan for the S09 Permission verdicts section (spec MR !2125): ten MR-sized steps.

  • A seam step owns the contended wiring (Deps.Verdicts, five construction sites, the seam-count literal) and the shared OpenAPI blocks, so the three verdict surfaces (detail, list, namespace) are order-free siblings.
  • The list envelope flip is preceded by a monolith tolerant-reader MR and carries a pact provider version floor (per-version contracts are frozen).
  • The namespace endpoint splits gate (the bindingOrgMemberOnly dispatch arm) from verdicts. The enforcement plan's step 17 stack (!2139 (merged)!2142 (merged)) is merged, so that arm exists and denies fail-closed until Step 7 replaces it; no step in this plan waits on another plan.
  • Cache headers land as one NewHandler wrap plus per-op OpenAPI region ownership.

This MR also carries a one-sentence spec amendment: criterion 26 gains the authentication layer's 401 as a carve-out. The sentence was written after !2125 (merged) merged and never reached main, and Step 9's Acceptance relies on it — riding it here means the plan and the criterion become true at the same instant, instead of the plan citing spec text that does not exist.

Related to #670 (closed)

Edited by João Pereira

Merge request reports

Loading
Loading