State pdp_digest explicitly; decline to publish a vocabulary mapping
flex-auth asked whether this engine should publish an action/target
mapping between the claim binding's vocabulary (secrets.kv.destroy,
{"id": "lane-openbao-root"}) and a policy package's (destroy, lane:...),
since their package makes no cross-check that a claim was approved for
the action being decided.
Answered no. A PIP asserting that one vocabulary's action means
another's would author policy semantics it does not own, over
vocabularies it does not own, and the failure mode is asymmetric: a wrong
mapping silently accepts a claim approved for a different action, which
is worse than no mapping. binding.pdp_digest is the correspondence and
sidesteps vocabulary entirely -- it compares the PDP's own digest to the
PDP's own digest, with no translation by anyone.
Implemented the part that was ours. pdp_digest was emitted only when
recorded, so a consumer could not distinguish "not issued against a
decision" from "we forgot to look". It is now always present and null in
that case, required-but-nullable in the schema, and documented as
something a PEP on a privileged lane must refuse. This engine states the
fact; enforcing the lane's policy stays with the consumer.
Both published examples were already contradicting the updated schema by
omitting the field -- the same fixture-versus-contract defect flex-auth
hit twice this week and that secrets-engine implemented. Fixed both, made
them cover the PDP-bound and unbound shapes so neither is inferred from
the other, and added tests/test_examples.py to validate every example
against the schema so the class cannot recur here. jsonschema added as a
dev dependency.
94 tests pass (6 new).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 411227@bnt-lap001
Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
This commit is contained in:
parent
87e55e2bca
commit
6d0dfc8010
8 changed files with 224 additions and 38 deletions
|
|
@ -223,3 +223,17 @@ this engine's state transitions and its use outbox row under §9.6. Implemented:
|
|||
with `approved_at` plus assurance/evidence refs). Tests prove reconstruction
|
||||
from the use row alone and that the claim still discloses no approver
|
||||
identities. Documented in `docs/outbox-contract.md`.
|
||||
|
||||
2026-09-06 follow-on (T05): flex-auth asked whether this engine should publish
|
||||
an action/target vocabulary mapping between the claim binding and their policy
|
||||
package before `SECRETS-WP-0007-T04` makes destroy reachable. Answered no, and
|
||||
recorded why in `docs/approval-claim.md`: a PIP asserting that one vocabulary's
|
||||
action *means* another's would author policy semantics it does not own, and a
|
||||
wrong mapping silently accepts a claim approved for a different action.
|
||||
`binding.pdp_digest` is the correspondence — it compares the PDP's digest to
|
||||
the PDP's digest with no translation. Implemented the part that was ours:
|
||||
`pdp_digest` is now always present on the claim and `null` when the approval
|
||||
was not issued against a PDP decision, so absence is a stated fact rather than
|
||||
a missing key, and the schema requires it as nullable. A PEP on a privileged
|
||||
lane must refuse a null. Both published examples were contradicting the schema;
|
||||
fixed, and `tests/test_examples.py` now validates every example against it.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue