Problem/Motivation

file_gate_assurance verifies OIDC at redemption (verify_at: redeem) or trusts the mint caller (verify_at: mint / A1). Design note docs/design/piv-cac-webauthn.md deferred A2: File Gate verifies the user OIDC token at mint before issuing the grant.

Deferred because a front-end access token typically has aud = the SPA client, not File Gate. Correct audience pinning rejects it unless the token is exchanged or remapped for File Gate.

GitHub: Wilkes-Liberty/file_gate#36 (implementation work happens there; this issue is the public dual-venue record).

Proposed resolution

  1. Document and support RFC 8693 token exchange (or IdP audience mapper) so mint receives aud = File Gate API client.
  2. Reuse AssuranceVerifier at mint when field is assurance + a mint-time verify setting.
  3. Fail closed on missing/invalid token / wrong acr / audience.
  4. Keep A1 as default for callers that cannot do exchange (honest docs).
  5. Kernel tests; redeem path unchanged (bridge / DPoP still apply at download as configured).

Remaining tasks

  • Spec in design note + API.md
  • Config surface on assurance field settings
  • Verifier wired on mint path with fail-closed behaviour
  • Tests for success / wrong aud / low acr / missing token
  • Dual-venue status updated on ship

API changes

Optional mint-time user token / exchange requirement when enabled on the field.

Data model changes

None beyond third-party field settings / config schema for the new option.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

jmcerda’s picture

Status: Fixed » Closed (fixed)
jmcerda’s picture

jmcerda’s picture

Confirm Closed (fixed). Work shipped; removing from Open queue.