2026-05-17 04:59:18 +02:00
{
"$schema" : "https://json-schema.org/draft/2020-12/schema" ,
"$id" : "https://flex-auth.netkingdom/schemas/check_request.schema.json" ,
"title" : "CheckRequest" ,
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "subject" , "action" , "resource" ] ,
"properties" : {
"id" : { "type" : "string" , "minLength" : 1 } ,
2026-06-23 21:17:42 +02:00
"tenant" : { "type" : "string" , "minLength" : 1 } ,
2026-05-17 04:59:18 +02:00
"subject" : { "$ref" : "#/$defs/subject_ref" } ,
"action" : { "type" : "string" , "minLength" : 1 } ,
"resource" : { "$ref" : "#/$defs/resource_ref" } ,
"context" : { "type" : "object" , "additionalProperties" : true } ,
"caring_context" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json" } ,
"policy_version" : { "type" : "string" , "minLength" : 1 }
} ,
"$defs" : {
"subject_ref" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "id" ] ,
"properties" : {
"id" : { "type" : "string" , "minLength" : 1 } ,
Add schemaguard; correct check_request subject.type against shipped reality
approval-engine suggested a conformance check after the examples-contradict-
prose class hit a third repository -- theirs. Fifteen lines, they said, and
it would have caught our caring fixture and our provenance omission. Worth
stealing, so we stole it.
internal/schemaguard validates published examples against published schemas.
It implements only the JSON Schema subset these schemas use, and the property
that makes it trustworthy is that an unrecognised keyword FAILS rather than
skips: a validator that silently approves what it does not understand invites
reliance it cannot support. It found three things on first run.
ONE, AND THE LARGEST: check_request.schema.json pointed subject.type at
CARING's subject_type enum (Human, Service, ...), and no consumer sends that
vocabulary. user-engine sends human, tenant-engine and secrets-engine send
service, and ops-warden sends adm/agt/atm -- an actor-type vocabulary CARING
does not model at all. Our published schema declared three live integrations
non-conformant. A rule that outlaws shipped correct behaviour is the rule
that is wrong, so the $ref is replaced with an opaque non-empty string and a
description saying why. CARING's enum remains correct where it belongs: the
registry's subject_manifest.yaml, where Service is right.
TWO: policy_package_note, which this session added to the caring example's
decision provenance, is undeclared under additionalProperties:false. Our own
annotation broke the conformance it was annotating. Moved to the envelope's
outer provenance.
THREE: the secrets-engine fixtures carried partial approval-claims, missing
binding, freshness and validity. A partial claim in a fixture is how a
consumer learns the wrong shape -- the same mechanism that produced the
destroy defect. They are now complete and valid against approval-engine's
schema, including the now-required binding.pdp_digest, and a test validates
them against that schema when the sibling repo is present.
The destroy replay fixture is regenerated accordingly and the replay README's
pinned digests updated, since a stale digest table is the same defect wearing
a different hat.
Closed the binding-mapping open item. approval-engine declined to publish a
vocabulary mapping and their reasoning is better than the request: a PIP
asserting secrets.kv.destroy MEANS destroy would author semantics over two
vocabularies it owns neither of, and a wrong mapping silently accepts a claim
approved for a different action. pdp_digest is the mapping precisely because
it does not translate. It is now always present and nullable, so the destroy
gate is pdp_digest non-null and equal, enforced at the PEP.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 412054@bnt-lap001
Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
2026-09-06 14:21:28 +02:00
"type" : {
"type" : "string" ,
"minLength" : 1 ,
"description" : "The requesting system's own subject-type vocabulary, evaluated by its policy package as an opaque string. Deliberately NOT the CARING subject_type enum: that enum is the registry's vocabulary (subject_manifest.yaml, where Service is correct), and every shipped consumer sends its own on the request instead -- human (user-engine), service (tenant-engine, secrets-engine), adm/agt/atm (ops-warden, which is an actor-type vocabulary CARING does not model at all). Corrected 2026-09-06: the $ref to the CARING enum declared three live integrations non-conformant, and a rule that outlaws shipped correct behaviour is the rule that is wrong."
} ,
2026-05-17 04:59:18 +02:00
"tenant" : { "type" : "string" , "minLength" : 1 } ,
"attributes" : { "type" : "object" , "additionalProperties" : true }
}
} ,
"resource_ref" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "id" ] ,
"properties" : {
"id" : { "type" : "string" , "minLength" : 1 } ,
"type" : { "type" : "string" , "minLength" : 1 } ,
"system" : { "type" : "string" , "minLength" : 1 } ,
"tenant" : { "type" : "string" , "minLength" : 1 } ,
"attributes" : { "type" : "object" , "additionalProperties" : true }
}
}
}
}