approval-engine/schemas/approval_claim.schema.json

116 lines
3.8 KiB
JSON
Raw Normal View History

{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://approval-engine.netkingdom/schemas/approval_claim.schema.json",
"title": "ApprovalClaim",
"description": "Input claim that access-engine consumes. This is a fact about an approval object, not a decision. Yields to the Taxonomy request-claim schema (statute §17) when that artifact exists and is assented; do not treat this local shape as permanent.",
"type": "object",
"additionalProperties": false,
"required": [
"schema_version",
"kind",
"issuer",
"approval_id",
"state",
"valid_now",
"consumed",
"binding",
"freshness",
"validity",
"reason_code"
],
"properties": {
"schema_version": { "const": "0.1" },
"kind": { "const": "approval-claim" },
"yields_to": {
"type": "string",
"description": "Taxonomy artifact this contract yields to. Informational; consumers must not branch on it."
},
"issuer": { "const": "approval-engine" },
"approval_id": { "type": "string", "format": "uuid" },
"state": {
"type": "string",
"enum": [
"requested",
"approved",
"valid",
"consumed",
"superseded",
"revoked",
"expired"
]
},
"valid_now": {
"type": "boolean",
"description": "True only when the object is approved, inside its validity window, and not consumed, superseded, revoked, or expired. Not a permission."
},
"consumed": { "type": "boolean" },
"binding": { "$ref": "#/$defs/binding" },
"freshness": { "$ref": "#/$defs/freshness" },
"validity": { "$ref": "#/$defs/validity" },
"reason_code": {
"type": "string",
"enum": [
"ok",
"requested",
"not_yet_valid",
"insufficient_approvers",
"expired",
"revoked",
"superseded",
"consumed"
]
}
},
"not": {
"anyOf": [
{ "required": ["effect"] },
{ "required": ["decision"] },
{ "required": ["allow"] },
{ "required": ["deny"] }
]
},
"$defs": {
"binding": {
"type": "object",
"additionalProperties": false,
"required": ["action", "target", "actor", "principal", "purpose", "digest"],
"properties": {
"action": { "type": "string", "minLength": 1 },
"target": { "type": "object" },
"actor": { "type": "string", "minLength": 1 },
"principal": { "type": "string", "minLength": 1 },
"purpose": { "type": "string", "minLength": 1 },
"digest": {
"type": "string",
"pattern": "^sha256:[0-9a-f]{64}$",
"description": "SHA-256 over the canonical JSON of action, actor, principal, purpose, target (sorted keys, RFC 8259). Distinguishes approved from approved-for-this-exact-request."
},
"pdp_digest": {
"type": "string",
"pattern": "^sha256:[0-9a-f]{64}$",
"description": "Optional. The flex-auth NewDecisionBinding request_digest recorded at issue time. When present, access-engine MUST compare this to the digest it already computes, not re-derive our native digest as a substitute."
}
}
},
"freshness": {
"type": "object",
"additionalProperties": false,
"required": ["observed_at", "ttl_seconds", "not_after"],
"properties": {
"observed_at": { "type": "string", "format": "date-time" },
"ttl_seconds": { "type": "integer", "minimum": 1 },
"not_after": { "type": "string", "format": "date-time" }
}
},
"validity": {
"type": "object",
"additionalProperties": false,
"required": ["not_before", "expires_at"],
"properties": {
"not_before": { "type": "string", "format": "date-time" },
"expires_at": { "type": "string", "format": "date-time" }
}
}
}
}