From 76f9b9f4cd9fcaa3fcc0854df22029a45553b55a Mon Sep 17 00:00:00 2001 From: Cea Stapleton Cordasco <261786559+cea-block@users.noreply.github.com> Date: Mon, 3 Aug 2026 16:28:40 -0500 Subject: [PATCH] fix(auth): enable sealed owner admission Signed-off-by: Cea Stapleton Cordasco <261786559+cea-block@users.noreply.github.com> --- crates/buzz-auth/src/context/evidence.rs | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/crates/buzz-auth/src/context/evidence.rs b/crates/buzz-auth/src/context/evidence.rs index 17960120e..c99018a4b 100644 --- a/crates/buzz-auth/src/context/evidence.rs +++ b/crates/buzz-auth/src/context/evidence.rs @@ -423,9 +423,9 @@ impl fmt::Debug for VerifiedFederatedAssertion { /// This evidence is independent of a federated assertion: a delegated request /// need not possess the owner's token. A provider adapter will construct it /// only after confirming that the bound owner is currently admitted in the -/// same authorization domain. Until that adapter exists, only crate tests can -/// construct this move-only value, so delegated enterprise finalization cannot -/// be activated by production handlers. +/// same authorization domain. Construction remains crate-private so only the +/// validated provider finalizer can turn a current capability decision into +/// this move-only evidence. #[derive(PartialEq, Eq)] pub struct VerifiedOwnerAdmission { authorization_domain: CommunityId, @@ -434,7 +434,8 @@ pub struct VerifiedOwnerAdmission { } impl VerifiedOwnerAdmission { - #[cfg(test)] + // Consumed by the provider finalizer in the stacked capability contract. + #[allow(dead_code)] pub(crate) const fn new( authorization_domain: CommunityId, principal: FederatedPrincipal,