State pdp_digest explicitly; decline to publish a vocabulary mapping
flex-auth asked whether this engine should publish an action/target
mapping between the claim binding's vocabulary (secrets.kv.destroy,
{"id": "lane-openbao-root"}) and a policy package's (destroy, lane:...),
since their package makes no cross-check that a claim was approved for
the action being decided.
Answered no. A PIP asserting that one vocabulary's action means
another's would author policy semantics it does not own, over
vocabularies it does not own, and the failure mode is asymmetric: a wrong
mapping silently accepts a claim approved for a different action, which
is worse than no mapping. binding.pdp_digest is the correspondence and
sidesteps vocabulary entirely -- it compares the PDP's own digest to the
PDP's own digest, with no translation by anyone.
Implemented the part that was ours. pdp_digest was emitted only when
recorded, so a consumer could not distinguish "not issued against a
decision" from "we forgot to look". It is now always present and null in
that case, required-but-nullable in the schema, and documented as
something a PEP on a privileged lane must refuse. This engine states the
fact; enforcing the lane's policy stays with the consumer.
Both published examples were already contradicting the updated schema by
omitting the field -- the same fixture-versus-contract defect flex-auth
hit twice this week and that secrets-engine implemented. Fixed both, made
them cover the PDP-bound and unbound shapes so neither is inferred from
the other, and added tests/test_examples.py to validate every example
against the schema so the class cannot recur here. jsonschema added as a
dev dependency.
94 tests pass (6 new).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 411227@bnt-lap001
Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
This commit is contained in:
parent
87e55e2bca
commit
6d0dfc8010
8 changed files with 224 additions and 38 deletions
|
|
@ -89,6 +89,45 @@ compares digests.
|
|||
| `principal` | `subject.attributes.principal` if present, else `subject.id` |
|
||||
| `purpose` | `context.purpose` |
|
||||
|
||||
### Action and target vocabulary — there is no published mapping, by design
|
||||
|
||||
The table above maps *fields*, not *values*. The claim's `action` and `target`
|
||||
carry whatever vocabulary the approval's creator used
|
||||
(`secrets.kv.destroy`, `{"id": "lane-openbao-root", "stage": "prod"}`); a policy
|
||||
package may use its own (`destroy`, `lane:...`). **This engine does not publish
|
||||
a translation between them and will not.**
|
||||
|
||||
This is a layer boundary, not an omission. A PIP that asserted
|
||||
`secrets.kv.destroy` *means* `destroy` would be authoring policy semantics it
|
||||
does not own, over vocabularies it does not own. The failure mode is also
|
||||
asymmetric: a wrong mapping silently accepts a claim approved for a
|
||||
*different* action, which is worse than no mapping at all. A consumer that
|
||||
finds itself wanting one should read that as a signal it is about to compare
|
||||
the wrong two things.
|
||||
|
||||
**`binding.pdp_digest` is the correspondence.** It sidesteps vocabulary
|
||||
entirely: it is the PDP's own `NewDecisionBinding.request_digest`, recorded at
|
||||
issue time, so comparing
|
||||
|
||||
```text
|
||||
claim.binding.pdp_digest == decision.binding.request_digest
|
||||
```
|
||||
|
||||
compares the PDP's digest to the PDP's digest, in one vocabulary, with no
|
||||
translation by anyone. That is strictly stronger than a name-to-name mapping
|
||||
could be.
|
||||
|
||||
`pdp_digest` is **always present** on the claim and is `null` when the approval
|
||||
was not issued against a PDP decision — a stated fact rather than a missing
|
||||
key, so a consumer cannot read absence as an oversight. It is not required on
|
||||
every approval, because approvals legitimately exist that no decision preceded.
|
||||
|
||||
**A PEP on a privileged lane MUST refuse a claim whose `pdp_digest` is
|
||||
`null`.** Such a claim proves an approval exists; it does not prove the
|
||||
approval was issued against the request now being decided, and no vocabulary
|
||||
comparison recovers that. Requiring it is the consumer's own gate — this engine
|
||||
states the fact and does not enforce the lane's policy.
|
||||
|
||||
Go's `json.Marshal` of a `CheckRequest` is **not** this canonical JSON (field
|
||||
order and `omitempty` differ). Do not hash a CheckRequest with this function
|
||||
and expect it to equal `NewDecisionBinding.request_digest`.
|
||||
|
|
@ -124,7 +163,9 @@ A production consumer of this claim, before treating it as an input, checks:
|
|||
3. `valid_now` is true and `consumed` is false.
|
||||
4. `binding.digest` equals the digest of the binding the consumer computed
|
||||
from the proposed action, **or** `binding.pdp_digest` equals the
|
||||
`NewDecisionBinding` digest of that request.
|
||||
`NewDecisionBinding` digest of that request. On a privileged lane, take the
|
||||
second: require `binding.pdp_digest` to be non-null and equal, and refuse
|
||||
the claim otherwise. See "Action and target vocabulary" above.
|
||||
5. `freshness.not_after` is still in the future.
|
||||
6. `reason_code` is `ok`.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue