flex-auth/internal/policy/testdata/undeclared-ceiling/policy_package.md

56 lines
1.4 KiB
Markdown
Raw Normal View History

---
id: testdata.undeclared-ceiling
name: deliberately undeclared ceiling key
namespace: testdata:secret
version: v1
status: fixture
package: flexauth.testdata.undeclared_ceiling
actions:
- sign
owner: team:platform-security
fixtures:
- policy_fixtures.yaml
caring:
profile: caring-0.4.0-rc2
enforce: false
canonical_roles: [Operator]
organization_relations: [ServiceProvider]
scopes:
- {level: Platform, id: platform:testdata, tenant: tenant:platform}
planes: [Secret]
capabilities: [Use]
exposure_modes: [Metadata]
conditions: [Logged]
restrictions: [PrivilegeEscalationBlocked]
---
# Undeclared ceiling (FLEX-WP-0025-T03)
This package exists to prove `flex-auth validate` flags a ceiling read from a
key the sibling registry never supplies. Do not copy it.
```rego
import future.keywords.if
default decision := {"effect": "deny", "reason": "no_matching_rule"}
decision := {"effect": "allow", "reason": "ttl_ok"} if {
input.action == "sign"
input.context.ttl_hours <= input.resource.attributes.max_ttl_hours
}
```
```rego test
package flexauth.testdata.undeclared_ceiling_test
import future.keywords.if
import data.flexauth.testdata.undeclared_ceiling
test_allow if {
undeclared_ceiling.decision.effect == "allow" with input as {
"action": "sign",
"context": {"ttl_hours": 1},
"resource": {"attributes": {"max_ttl_hours": 8}}
}
}
```