2026-05-17 04:59:18 +02:00
{
"$schema" : "https://json-schema.org/draft/2020-12/schema" ,
"$id" : "https://flex-auth.netkingdom/schemas/decision_envelope.schema.json" ,
"title" : "DecisionEnvelope" ,
2026-09-03 23:48:45 +02:00
"description" : "Published flex-auth decision-record contract (flex-auth.decision-record.v1). This is the PDP's output artifact under security-layer-model_v0.7 §17." ,
2026-05-17 04:59:18 +02:00
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "id" , "effect" , "resource" , "subject" , "provenance" ] ,
"properties" : {
"id" : { "type" : "string" , "minLength" : 1 } ,
2026-09-03 23:48:45 +02:00
"contract_version" : { "const" : "flex-auth.decision-record.v1" } ,
2026-05-17 04:59:18 +02:00
"request_id" : { "type" : "string" , "minLength" : 1 } ,
"effect" : { "enum" : [ "allow" , "deny" , "redact" , "audit_only" , "not_applicable" ] } ,
"reason" : { "type" : "string" } ,
"matched_policy_version" : { "type" : "string" , "minLength" : 1 } ,
"matched_rule" : { "type" : "string" , "minLength" : 1 } ,
"resource" : { "$ref" : "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/resource_ref" } ,
"subject" : { "$ref" : "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/subject_ref" } ,
2026-08-23 13:18:26 +02:00
"binding" : { "$ref" : "#/$defs/decision_binding" } ,
2026-09-03 23:48:45 +02:00
"lifetime" : { "$ref" : "#/$defs/lifetime" } ,
2026-05-17 04:59:18 +02:00
"obligations" : { "type" : "array" , "items" : { "$ref" : "#/$defs/obligation" } } ,
"diagnostics" : { "type" : "object" , "additionalProperties" : true } ,
"provenance" : { "$ref" : "#/$defs/provenance" } ,
"caring" : { "$ref" : "#/$defs/caring_decision_metadata" }
} ,
2026-09-03 23:48:45 +02:00
"allOf" : [
{
"if" : { "properties" : { "effect" : { "const" : "allow" } } , "required" : [ "effect" ] } ,
"then" : { "required" : [ "lifetime" ] }
}
] ,
2026-05-17 04:59:18 +02:00
"$defs" : {
2026-08-23 13:18:26 +02:00
"decision_binding" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "subject" , "action" , "resource" , "request_digest" ] ,
"properties" : {
"tenant" : { "type" : "string" , "minLength" : 1 } ,
"subject" : { "$ref" : "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/subject_ref" } ,
"action" : { "type" : "string" , "minLength" : 1 } ,
"resource" : { "$ref" : "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/resource_ref" } ,
"context" : { "type" : "object" , "additionalProperties" : true } ,
"request_digest" : { "type" : "string" , "pattern" : "^sha256:[0-9a-f]{64}$" }
}
} ,
2026-05-17 04:59:18 +02:00
"obligation" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "type" ] ,
"properties" : {
"type" : { "type" : "string" , "minLength" : 1 } ,
"parameters" : { "type" : "object" , "additionalProperties" : true }
}
} ,
2026-09-03 23:48:45 +02:00
"lifetime" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "kind" , "expires_at" ] ,
"properties" : {
"kind" : { "enum" : [ "ttl" ] } ,
"ttl" : { "type" : "string" , "minLength" : 1 } ,
"not_before" : { "type" : "string" , "minLength" : 1 } ,
"expires_at" : { "type" : "string" , "minLength" : 1 }
}
} ,
2026-05-17 04:59:18 +02:00
"provenance" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "evaluator" , "mode" ] ,
"properties" : {
"evaluator" : { "type" : "string" , "minLength" : 1 } ,
"mode" : { "type" : "string" , "minLength" : 1 } ,
"policy_package" : { "type" : "string" , "minLength" : 1 } ,
"policy_version" : { "type" : "string" , "minLength" : 1 } ,
2026-09-03 23:48:45 +02:00
"policy_package_digest" : { "type" : "string" , "pattern" : "^sha256:[0-9a-f]{64}$" } ,
"registry_snapshot_digest" : { "type" : "string" , "pattern" : "^sha256:[0-9a-f]{64}$" } ,
2026-05-17 04:59:18 +02:00
"directory_etag" : { "type" : "string" , "minLength" : 1 } ,
2026-09-03 23:48:45 +02:00
"input_claim_digests" : {
"type" : "object" ,
"additionalProperties" : { "type" : "string" , "pattern" : "^sha256:[0-9a-f]{64}$" }
} ,
2026-05-17 04:59:18 +02:00
"decision_time" : { "type" : "string" , "minLength" : 1 }
}
} ,
"caring_decision_metadata" : {
"type" : "object" ,
"additionalProperties" : false ,
"required" : [ "profile" ] ,
"properties" : {
"profile" : { "const" : "caring-0.4.0-rc2" } ,
"descriptor" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json" } ,
"restrictions_evaluated" : {
"type" : "array" ,
"items" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/restriction" } ,
"uniqueItems" : true
} ,
"exposure_modes" : {
"type" : "array" ,
"items" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/exposure_mode" } ,
"uniqueItems" : true
} ,
"derived_capabilities" : {
"type" : "array" ,
"items" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/derived_capability" }
} ,
"conformance_findings" : {
"type" : "array" ,
"items" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/conformance_finding" }
} ,
"exposure_event" : { "$ref" : "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/exposure_event" }
}
}
}
}