Implement the engine spine: claim, outbox, machine, API
Contracts first (T02–T04): approval claim schema with issuer, freshness,
and binding digest; local transactional outbox wire; load-bearing cadence
as heartbeat or reconciliation (layer.yaml declared).
Then the object (T06–T08): SQLite closed state machine, CAS supersession,
distinct-approver fail-closed, revocation without holder cooperation,
outbox insert in the same transaction. Tests fail the mutation when
emission fails, and revoke while the drain sink is down.
Introspection GET /v1/approvals/{id}/claim is a PIP fact, not a decision.
No public consume (T05 waits on GH-WP-0002-T06). Canon T-06 coverage for
wrong binding, expiry, revoke, and supersede.
FLEX-WP-0017 T03 is unblocked on this object; T05 remains blocked only on
consumption ordering.
Assistant: grok
Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
This commit is contained in:
parent
624e43f554
commit
9c9528f5b2
29 changed files with 2121 additions and 26 deletions
115
schemas/approval_claim.schema.json
Normal file
115
schemas/approval_claim.schema.json
Normal file
|
|
@ -0,0 +1,115 @@
|
|||
{
|
||||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||
"$id": "https://approval-engine.netkingdom/schemas/approval_claim.schema.json",
|
||||
"title": "ApprovalClaim",
|
||||
"description": "Input claim that access-engine consumes. This is a fact about an approval object, not a decision. Yields to the Taxonomy request-claim schema (statute §17) when that artifact exists and is assented; do not treat this local shape as permanent.",
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": [
|
||||
"schema_version",
|
||||
"kind",
|
||||
"issuer",
|
||||
"approval_id",
|
||||
"state",
|
||||
"valid_now",
|
||||
"consumed",
|
||||
"binding",
|
||||
"freshness",
|
||||
"validity",
|
||||
"reason_code"
|
||||
],
|
||||
"properties": {
|
||||
"schema_version": { "const": "0.1" },
|
||||
"kind": { "const": "approval-claim" },
|
||||
"yields_to": {
|
||||
"type": "string",
|
||||
"description": "Taxonomy artifact this contract yields to. Informational; consumers must not branch on it."
|
||||
},
|
||||
"issuer": { "const": "approval-engine" },
|
||||
"approval_id": { "type": "string", "format": "uuid" },
|
||||
"state": {
|
||||
"type": "string",
|
||||
"enum": [
|
||||
"requested",
|
||||
"approved",
|
||||
"valid",
|
||||
"consumed",
|
||||
"superseded",
|
||||
"revoked",
|
||||
"expired"
|
||||
]
|
||||
},
|
||||
"valid_now": {
|
||||
"type": "boolean",
|
||||
"description": "True only when the object is approved, inside its validity window, and not consumed, superseded, revoked, or expired. Not a permission."
|
||||
},
|
||||
"consumed": { "type": "boolean" },
|
||||
"binding": { "$ref": "#/$defs/binding" },
|
||||
"freshness": { "$ref": "#/$defs/freshness" },
|
||||
"validity": { "$ref": "#/$defs/validity" },
|
||||
"reason_code": {
|
||||
"type": "string",
|
||||
"enum": [
|
||||
"ok",
|
||||
"requested",
|
||||
"not_yet_valid",
|
||||
"insufficient_approvers",
|
||||
"expired",
|
||||
"revoked",
|
||||
"superseded",
|
||||
"consumed"
|
||||
]
|
||||
}
|
||||
},
|
||||
"not": {
|
||||
"anyOf": [
|
||||
{ "required": ["effect"] },
|
||||
{ "required": ["decision"] },
|
||||
{ "required": ["allow"] },
|
||||
{ "required": ["deny"] }
|
||||
]
|
||||
},
|
||||
"$defs": {
|
||||
"binding": {
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": ["action", "target", "actor", "principal", "purpose", "digest"],
|
||||
"properties": {
|
||||
"action": { "type": "string", "minLength": 1 },
|
||||
"target": { "type": "object" },
|
||||
"actor": { "type": "string", "minLength": 1 },
|
||||
"principal": { "type": "string", "minLength": 1 },
|
||||
"purpose": { "type": "string", "minLength": 1 },
|
||||
"digest": {
|
||||
"type": "string",
|
||||
"pattern": "^sha256:[0-9a-f]{64}$",
|
||||
"description": "SHA-256 over the canonical JSON of action, actor, principal, purpose, target (sorted keys, RFC 8259). Distinguishes approved from approved-for-this-exact-request."
|
||||
},
|
||||
"pdp_digest": {
|
||||
"type": "string",
|
||||
"pattern": "^sha256:[0-9a-f]{64}$",
|
||||
"description": "Optional. The flex-auth NewDecisionBinding request_digest recorded at issue time. When present, access-engine MUST compare this to the digest it already computes, not re-derive our native digest as a substitute."
|
||||
}
|
||||
}
|
||||
},
|
||||
"freshness": {
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": ["observed_at", "ttl_seconds", "not_after"],
|
||||
"properties": {
|
||||
"observed_at": { "type": "string", "format": "date-time" },
|
||||
"ttl_seconds": { "type": "integer", "minimum": 1 },
|
||||
"not_after": { "type": "string", "format": "date-time" }
|
||||
}
|
||||
},
|
||||
"validity": {
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": ["not_before", "expires_at"],
|
||||
"properties": {
|
||||
"not_before": { "type": "string", "format": "date-time" },
|
||||
"expires_at": { "type": "string", "format": "date-time" }
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue