docs(secrets): mxaccessgw G-4/G-5/G-6 adopted + merged (mxaccessgw @ e088dfa)

This commit is contained in:
Joseph Doherty
2026-07-16 13:49:43 -04:00
parent 6be5f746d5
commit d95328efb3
2 changed files with 17 additions and 1 deletions
+16
View File
@@ -5,6 +5,22 @@ The delta between each project's [`current-state`](current-state/) and the
reference-consumer-proven**; everything here is per-app adoption of an existing lib (not lib
construction).
## Execution status (2026-07-16)
- **mxaccessgw — G-4 + G-5 + G-6 DONE.** Executed via the plan below (8 tasks, subagent-driven,
classification-driven reviews), **merged + pushed to `origin/main` (mxaccessgw @ `e088dfa`)**.
Offline: 0-warning build, full suite 781 pass / 44 pre-existing worker-COM (0 non-worker),
behavioral claim-type authz test, no Data-Protection disturbance. Box-verified on windev
(real .NET 10.0.8): fail-closed on unseeded `${secret:}` (`SecretNotFoundException`, refuses
to start) + CLI seed/`get` decrypt round-trip + **zero plaintext in the SQLite store at rest**.
(`/admin/secrets` interactive reveal not re-proven on this box — same shared `.Ui` component
already live-proven via HistorianGateway; box gateway runs LDAP-disabled/anonymous so a real
LDAP-via-secret login wasn't exercised there.) Two review-caught fixes folded in: the LDAP
password change's test/doc blast radius (validator-helper + host-test-bootstrap + doc truth),
and the live-LDAP integration suite now honors the `MxGateway__Ldap__ServiceAccountPassword`
env override. **G-4/G-5/G-6 below are the remaining OtOpcUa + ScadaBridge scope.**
- **OtOpcUa, ScadaBridge — planned, NOT executed** (recommended order: OtOpcUa next, then ScadaBridge).
## Design + implementation plans (2026-07-16)
G-2 … G-6 are now planned. Shared design + three per-repo executable plans (task-metadata'd,