Follow-up to #360's explicitly deferred authorization boundary.
Assigning or unassigning a Worker from a flock is a durable authorization mutation. In particular, removing the last assignment restores farm-wide Worker scope. #360 closes durable authenticator creation/reset and role changes, but intentionally leaves flock-scope changes unchanged so that remediation remains bounded.
Acceptance criteria:
- Every interactive flock assignment and unassignment requires a fresh, single-use step-up grant before target lookup or mutation.
- Missing or invalid proof remains non-enumerating and makes no assignment change.
- The SPA collects the signed-in Owner's current password for both operations, clears it before awaiting grant issuance, and uses the returned grant once.
- Trusted non-HTTP callers use an explicit internal path; no request-selectable bypass is introduced.
- Existing tenant, audit, concurrency, simulation-seeder, k6, and Playwright contracts are inventoried and preserved.
- User-facing Help/glossary copy and all supported locales describe the expanded boundary.
- Guards include adversarial mutations for both assignment and last-unassignment paths.
This issue does not assert that production exploitation occurred or was ruled out; repository-local audit evidence is unavailable.
Follow-up to #360's explicitly deferred authorization boundary.
Assigning or unassigning a Worker from a flock is a durable authorization mutation. In particular, removing the last assignment restores farm-wide Worker scope. #360 closes durable authenticator creation/reset and role changes, but intentionally leaves flock-scope changes unchanged so that remediation remains bounded.
Acceptance criteria:
This issue does not assert that production exploitation occurred or was ruled out; repository-local audit evidence is unavailable.