56 lines
1.4 KiB
Markdown
56 lines
1.4 KiB
Markdown
|
|
---
|
||
|
|
id: testdata.undeclared-ceiling
|
||
|
|
name: deliberately undeclared ceiling key
|
||
|
|
namespace: testdata:secret
|
||
|
|
version: v1
|
||
|
|
status: fixture
|
||
|
|
package: flexauth.testdata.undeclared_ceiling
|
||
|
|
actions:
|
||
|
|
- sign
|
||
|
|
owner: team:platform-security
|
||
|
|
fixtures:
|
||
|
|
- policy_fixtures.yaml
|
||
|
|
caring:
|
||
|
|
profile: caring-0.4.0-rc2
|
||
|
|
enforce: false
|
||
|
|
canonical_roles: [Operator]
|
||
|
|
organization_relations: [ServiceProvider]
|
||
|
|
scopes:
|
||
|
|
- {level: Platform, id: platform:testdata, tenant: tenant:platform}
|
||
|
|
planes: [Secret]
|
||
|
|
capabilities: [Use]
|
||
|
|
exposure_modes: [Metadata]
|
||
|
|
conditions: [Logged]
|
||
|
|
restrictions: [PrivilegeEscalationBlocked]
|
||
|
|
---
|
||
|
|
|
||
|
|
# Undeclared ceiling (FLEX-WP-0025-T03)
|
||
|
|
|
||
|
|
This package exists to prove `flex-auth validate` flags a ceiling read from a
|
||
|
|
key the sibling registry never supplies. Do not copy it.
|
||
|
|
|
||
|
|
```rego
|
||
|
|
import future.keywords.if
|
||
|
|
|
||
|
|
default decision := {"effect": "deny", "reason": "no_matching_rule"}
|
||
|
|
|
||
|
|
decision := {"effect": "allow", "reason": "ttl_ok"} if {
|
||
|
|
input.action == "sign"
|
||
|
|
input.context.ttl_hours <= input.resource.attributes.max_ttl_hours
|
||
|
|
}
|
||
|
|
```
|
||
|
|
|
||
|
|
```rego test
|
||
|
|
package flexauth.testdata.undeclared_ceiling_test
|
||
|
|
import future.keywords.if
|
||
|
|
import data.flexauth.testdata.undeclared_ceiling
|
||
|
|
|
||
|
|
test_allow if {
|
||
|
|
undeclared_ceiling.decision.effect == "allow" with input as {
|
||
|
|
"action": "sign",
|
||
|
|
"context": {"ttl_hours": 1},
|
||
|
|
"resource": {"attributes": {"max_ttl_hours": 8}}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
```
|