sh-mcp/docs
Adam Moussa 70987522b2 Remediate Fable round-2: BLOCK-1 credential mechanism + residual fixes
- BLOCK-1: invert the token-layer trifecta layering — per-app-client AllowedOAuthScopes
  is the PRIMARY vendor-supported boundary (Cognito won't issue out-of-tier scopes
  regardless of group union); pre-token suppression is a fail-closed backstop; the
  aud/authorizer mechanism is flagged unverified-load-bearing and added to the §6 verify
  gate (#8); fix the design.md §2.3 misattribution + add the amendment to §4.
- FIX-1: §1f notion-sync dual-feeds via S3 (was 'repointed instead of').
- FIX-2: split Phase 0a exit gate into fatal vs decision-input (Testing-Center identity).
- FIX-3: remove stale 'boundary stays in infrastructure' phrasing (server is the boundary).
- FIX-4: bound parallel-run double-spend (G9 + Phases 1-3 time-box).
- FIX-5: specify minimal throwaway 0a kit + Slack-plan dependency.
- FIX-6: remove dangling (O3); D3 recorded as accepted.
- NITs: severity arithmetic, Ops welcome no longer oversells tasks, wrong-audience alarm
  named, flip-point clarified. Q1 fallback scope + Q2 freshness-bound documented.
2026-06-11 13:09:13 -04:00
..
agentforce-plan.md Remediate Fable round-2: BLOCK-1 credential mechanism + residual fixes 2026-06-11 13:09:13 -04:00
design.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00