flex-auth asked whether this engine should publish an action/target
mapping between the claim binding's vocabulary (secrets.kv.destroy,
{"id": "lane-openbao-root"}) and a policy package's (destroy, lane:...),
since their package makes no cross-check that a claim was approved for
the action being decided.
Answered no. A PIP asserting that one vocabulary's action means
another's would author policy semantics it does not own, over
vocabularies it does not own, and the failure mode is asymmetric: a wrong
mapping silently accepts a claim approved for a different action, which
is worse than no mapping. binding.pdp_digest is the correspondence and
sidesteps vocabulary entirely -- it compares the PDP's own digest to the
PDP's own digest, with no translation by anyone.
Implemented the part that was ours. pdp_digest was emitted only when
recorded, so a consumer could not distinguish "not issued against a
decision" from "we forgot to look". It is now always present and null in
that case, required-but-nullable in the schema, and documented as
something a PEP on a privileged lane must refuse. This engine states the
fact; enforcing the lane's policy stays with the consumer.
Both published examples were already contradicting the updated schema by
omitting the field -- the same fixture-versus-contract defect flex-auth
hit twice this week and that secrets-engine implemented. Fixed both, made
them cover the PDP-bound and unbound shapes so neither is inferred from
the other, and added tests/test_examples.py to validate every example
against the schema so the class cannot recur here. jsonschema added as a
dev dependency.
94 tests pass (6 new).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 411227@bnt-lap001
Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
32 lines
987 B
JSON
32 lines
987 B
JSON
{
|
|
"schema_version": "0.1",
|
|
"kind": "approval-claim",
|
|
"yields_to": "net-kingdom taxonomy request-claim schema (statute \u00a717; unassigned)",
|
|
"issuer": "approval-engine",
|
|
"approval_id": "3d1c0a8e-6b7f-4c21-9a0e-1f2b3c4d5e6f",
|
|
"state": "valid",
|
|
"valid_now": true,
|
|
"consumed": false,
|
|
"binding": {
|
|
"action": "secrets.kv.destroy",
|
|
"target": {
|
|
"id": "lane-openbao-root",
|
|
"stage": "prod"
|
|
},
|
|
"actor": "agt-secrets-engine",
|
|
"principal": "bernd",
|
|
"purpose": "rotate-exposed-key",
|
|
"digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
|
|
"pdp_digest": "sha256:3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f"
|
|
},
|
|
"freshness": {
|
|
"observed_at": "2026-08-29T12:00:00+00:00",
|
|
"ttl_seconds": 30,
|
|
"not_after": "2026-08-29T12:00:30+00:00"
|
|
},
|
|
"validity": {
|
|
"not_before": "2026-08-29T11:00:00+00:00",
|
|
"expires_at": "2026-08-29T15:00:00+00:00"
|
|
},
|
|
"reason_code": "ok"
|
|
}
|