fix(auth): enable sealed owner admission

Signed-off-by: Cea Stapleton Cordasco <261786559+cea-block@users.noreply.github.com>
This commit is contained in:
Cea Stapleton Cordasco
2026-08-03 16:28:40 -05:00
parent 5a014bda25
commit 76f9b9f4cd
+5 -4
View File
@@ -423,9 +423,9 @@ impl fmt::Debug for VerifiedFederatedAssertion {
/// This evidence is independent of a federated assertion: a delegated request
/// need not possess the owner's token. A provider adapter will construct it
/// only after confirming that the bound owner is currently admitted in the
/// same authorization domain. Until that adapter exists, only crate tests can
/// construct this move-only value, so delegated enterprise finalization cannot
/// be activated by production handlers.
/// same authorization domain. Construction remains crate-private so only the
/// validated provider finalizer can turn a current capability decision into
/// this move-only evidence.
#[derive(PartialEq, Eq)]
pub struct VerifiedOwnerAdmission {
authorization_domain: CommunityId,
@@ -434,7 +434,8 @@ pub struct VerifiedOwnerAdmission {
}
impl VerifiedOwnerAdmission {
#[cfg(test)]
// Consumed by the provider finalizer in the stacked capability contract.
#[allow(dead_code)]
pub(crate) const fn new(
authorization_domain: CommunityId,
principal: FederatedPrincipal,