DUNIN7 · LOOMWORKS · RECORD
record.dunin7.com
Status Current
Path change-requests/cr-2026-188-loomworks-b47-credential-issuance-v0_1.md

DUNIN7-M4 — INFRASTRUCTURE CHANGE REQUEST

CR-2026-188 — B-47: contributor credential issuance screen (v0.1)

Version. 0.1 · Date. 2026-08-07 · Author. Claude.ai (drafting) / Marvin Percival (approving). Target. /Users/dunin7/loomworks, branch main (+ engine only if Step 1 finds a gap — see §2). Baseline. Post CR-2026-187. CC confirms at Step 0. Companion to. inspection-briefs/loomworks-small-work-sweep-step-0-findings-v0_1.md §6; standing-notes/loomworks-development-schedule-v0_1 (decision pre-settled). Charter. Autonomous regime. Status. Ready for CC execution.


1. Summary

The engine pathway for issuing a contributor credential is complete. No screen exists. The form itself is two fields — which is why this looked small and isn't.

What makes it not small: the credential is a bearer-style claim link granting unmoderated write access, shown once. Getting the reveal wrong means either a credential the Operator never captured, or one sitting in a place it shouldn't be.

Design decision, settled in advance: a standard one-time-reveal — shown once, copy-to-clipboard, cannot be reopened — plus a revoke control on the existing credentials list. No new pattern invented for a one-screen feature.


2. Step 1 — read first

CC establishes and reports before building:

  1. What the issuance endpoint requires and returns.
  2. Whether a revoke pathway exists in the engine. The reveal and the revoke are a pair — a one-time reveal without revoke means a mis-handled credential cannot be withdrawn. If revoke does not exist, halt and report: that is engine work and changes this CR's shape.
  3. What the existing credentials list shows today, and whether it can carry a revoke control.

3. Scope

The reveal.

The revoke.

Operator authority. Issuance and revocation are Operator acts. Nothing here transitions state automatically on the Operator's behalf.


4. Out of scope


5. Build steps

| Step | What | Mode | |---|---|---| | 0 | Pre-flight. | Auto | | 1 | Read per §2. Halt if no revoke pathway exists. | Auto, conditional halt | | 2 | One-time-reveal screen + tests. | Auto | | 3 | Revoke control + confirmation + tests. | Auto | | 4 | Test asserting no path back to a revealed credential — reload, navigation, list, history. | Auto | | 5 | Surface sweep. | Auto | | A | Checkpoint. | Checkpoint | | 6 | Tag cr-2026-188-b47-credential-issuance. Push. | Auto |


6. Acceptance gate

  1. A credential is shown exactly once and is unreachable afterward by any route — tested, not asserted.
  2. The screen states in plain terms that this is the only showing and what the credential permits.
  3. Revoke exists, requires confirmation, and works.
  4. The credential appears in no log, URL, query string, or client-side store — verified explicitly, since this is the failure that would not surface in a test of normal behavior.
  5. Surface sweep clean.

7. Kickoff prompt


Execute CR-2026-188 v0.1 at ~/Downloads/cr-2026-188-loomworks-b47-
credential-issuance-v0_1.md. Confirm the CR number first.

B-47: the engine pathway is complete, no screen exists. The form is two
fields; what makes it not small is that the credential is a bearer-style
claim link granting unmoderated write access, shown once.

Remedy is pre-decided: standard one-time-reveal plus a revoke on the
existing credentials list. Don't invent a new pattern.

Step 1 HALTS if no revoke pathway exists in the engine. Reveal and
revoke are a pair — a one-time reveal with no way to withdraw a
mishandled credential is worse than no screen.

Gate item 4 is the one that won't surface in ordinary testing: verify
explicitly that the credential appears in no log, no URL, no query
string, and no client-side store. Check it rather than assume it.

Out of scope and deliberately so: rotation, expiry, usage auditing, and
anything that could re-display a credential.

DUNIN7 — Done In Seven LLC — Miami, Florida CR-2026-188 — B-47 credential issuance — v0.1 — 2026-08-07