flex-auth published binding.approval_binding_digest (FLEX-DEC-2026-007) after
secrets-engine found that a claim-bearing request's request_digest covers the
carried claim, so it can never equal a pdp_digest recorded before that claim
existed. A consumer obeying GH-DEC-2026-008 against request_digest would have
failed closed permanently on every claim rather than on a bad one.
The value recorded at issue was already correct, so no code changes. What was
wrong was this repo's description of the comparison target: a reader would
reach for request_digest and fail closed forever. The schema and
docs/approval-claim.md now name approval_binding_digest as the execute-time
target and state that request_digest is never it, while leaving the issue-time
description as it stood.
Separately, docs/keycape-service-registrations.md now records a live collision
in the deployment inputs: the manifest serves --tenant platform while the
requested registrations issue tenant:coulomb, and ApiApplication.identity
compares them with exact string equality before any object lookup, so those
tokens would be denied 403 on every non-health route. flex-auth's
tenant:platform is a PDP subject this engine never reads and cannot bridge the
two. The values are left as-is on purpose — resolving it needs an owner
statement on whether the two name the same layer, and guessing grants
cross-tenant access to the approval store. The doc's stale issuer is corrected
to the live https://kc.coulomb.social from 06544b0.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
200 lines
5.6 KiB
JSON
200 lines
5.6 KiB
JSON
{
|
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
"$id": "https://approval-engine.netkingdom/schemas/approval_claim.schema.json",
|
|
"title": "ApprovalClaim",
|
|
"description": "Input claim that access-engine consumes. This is a fact about an approval object, not a decision. Yields to the Taxonomy request-claim schema (statute \u00a717) when that artifact exists and is assented; do not treat this local shape as permanent.",
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": [
|
|
"schema_version",
|
|
"kind",
|
|
"issuer",
|
|
"approval_id",
|
|
"state",
|
|
"valid_now",
|
|
"consumed",
|
|
"binding",
|
|
"freshness",
|
|
"validity",
|
|
"reason_code"
|
|
],
|
|
"properties": {
|
|
"schema_version": {
|
|
"const": "0.1"
|
|
},
|
|
"kind": {
|
|
"const": "approval-claim"
|
|
},
|
|
"yields_to": {
|
|
"type": "string",
|
|
"description": "Taxonomy artifact this contract yields to. Informational; consumers must not branch on it."
|
|
},
|
|
"issuer": {
|
|
"const": "approval-engine"
|
|
},
|
|
"approval_id": {
|
|
"type": "string",
|
|
"format": "uuid"
|
|
},
|
|
"state": {
|
|
"type": "string",
|
|
"enum": [
|
|
"requested",
|
|
"approved",
|
|
"valid",
|
|
"consumed",
|
|
"superseded",
|
|
"revoked",
|
|
"expired"
|
|
]
|
|
},
|
|
"valid_now": {
|
|
"type": "boolean",
|
|
"description": "True only when the object is approved, inside its validity window, and not consumed, superseded, revoked, or expired. Not a permission."
|
|
},
|
|
"consumed": {
|
|
"type": "boolean"
|
|
},
|
|
"binding": {
|
|
"$ref": "#/$defs/binding"
|
|
},
|
|
"freshness": {
|
|
"$ref": "#/$defs/freshness"
|
|
},
|
|
"validity": {
|
|
"$ref": "#/$defs/validity"
|
|
},
|
|
"reason_code": {
|
|
"type": "string",
|
|
"enum": [
|
|
"ok",
|
|
"requested",
|
|
"not_yet_valid",
|
|
"insufficient_approvers",
|
|
"expired",
|
|
"revoked",
|
|
"superseded",
|
|
"consumed"
|
|
]
|
|
}
|
|
},
|
|
"not": {
|
|
"anyOf": [
|
|
{
|
|
"required": [
|
|
"effect"
|
|
]
|
|
},
|
|
{
|
|
"required": [
|
|
"decision"
|
|
]
|
|
},
|
|
{
|
|
"required": [
|
|
"allow"
|
|
]
|
|
},
|
|
{
|
|
"required": [
|
|
"deny"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"$defs": {
|
|
"binding": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": [
|
|
"action",
|
|
"target",
|
|
"actor",
|
|
"principal",
|
|
"purpose",
|
|
"digest",
|
|
"pdp_digest",
|
|
"pdp_path"
|
|
],
|
|
"properties": {
|
|
"action": {
|
|
"type": "string",
|
|
"minLength": 1
|
|
},
|
|
"target": {
|
|
"type": "object"
|
|
},
|
|
"actor": {
|
|
"type": "string",
|
|
"minLength": 1
|
|
},
|
|
"principal": {
|
|
"type": "string",
|
|
"minLength": 1
|
|
},
|
|
"purpose": {
|
|
"type": "string",
|
|
"minLength": 1
|
|
},
|
|
"digest": {
|
|
"type": "string",
|
|
"pattern": "^sha256:[0-9a-f]{64}$",
|
|
"description": "SHA-256 over the canonical JSON of action, actor, principal, purpose, target (sorted keys, RFC 8259). Distinguishes approved from approved-for-this-exact-request."
|
|
},
|
|
"pdp_digest": {
|
|
"type": [
|
|
"string",
|
|
"null"
|
|
],
|
|
"pattern": "^sha256:[0-9a-f]{64}$",
|
|
"description": "The flex-auth NewDecisionBinding request_digest recorded at issue time, or null when the approval was not issued against a PDP decision. Always present so its absence is a stated fact rather than a missing key. Recorded at issue, so it is the digest of the action request as it stands before this claim is embedded in it. At execute time on a claim-bearing request the comparison target is the PDP's claim-excluded digest -- flex-auth publishes it as binding.approval_binding_digest (FLEX-DEC-2026-007) -- and NOT binding.request_digest, which covers the carried claim and therefore can never equal a digest recorded before that claim existed. When non-null, a consumer MUST compare this to the PDP's published exclusion-scoped digest and MUST NOT re-derive the native digest as a substitute, and MUST NOT guess the exclusion rule. A PEP on a privileged lane MUST refuse a claim whose pdp_digest is null."
|
|
},
|
|
"pdp_path": {
|
|
"type": "boolean",
|
|
"description": "Whether this approval was declared at issue for the GH-DEC-2026-003 PDP consumption path. GH-DEC-2026-008 requires pdp_digest on that path, so this engine refuses to create a pdp_path approval without one; a true value therefore guarantees pdp_digest is non-null. A consumer on that path MUST require pdp_path true and MUST NOT infer path intent from a pdp_digest that merely happens to be present."
|
|
}
|
|
}
|
|
},
|
|
"freshness": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": [
|
|
"observed_at",
|
|
"ttl_seconds",
|
|
"not_after"
|
|
],
|
|
"properties": {
|
|
"observed_at": {
|
|
"type": "string",
|
|
"format": "date-time"
|
|
},
|
|
"ttl_seconds": {
|
|
"type": "integer",
|
|
"minimum": 1
|
|
},
|
|
"not_after": {
|
|
"type": "string",
|
|
"format": "date-time"
|
|
}
|
|
}
|
|
},
|
|
"validity": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": [
|
|
"not_before",
|
|
"expires_at"
|
|
],
|
|
"properties": {
|
|
"not_before": {
|
|
"type": "string",
|
|
"format": "date-time"
|
|
},
|
|
"expires_at": {
|
|
"type": "string",
|
|
"format": "date-time"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|