Finish FLEX-WP-0019 layer-model v0.7 conformance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 57s

Close the remaining PDP obligations: mechanical layer declaration check,
registry-snapshot digest in provenance, explicit allow TTL, per-input-class
freshness deadlines, and the published decision-record contract. Document
the canonical request digest as the §6.4.2 replay test.

Assistant: grok
Assistant-Session: 01a06256-fb71-7102-b3a9-27e6734257d0
This commit is contained in:
tegwick 2026-09-03 23:48:45 +02:00
parent 9689894c15
commit 56940727bf
32 changed files with 1194 additions and 111 deletions

View file

@ -2,11 +2,13 @@
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://flex-auth.netkingdom/schemas/decision_envelope.schema.json",
"title": "DecisionEnvelope",
"description": "Published flex-auth decision-record contract (flex-auth.decision-record.v1). This is the PDP's output artifact under security-layer-model_v0.7 §17.",
"type": "object",
"additionalProperties": false,
"required": ["id", "effect", "resource", "subject", "provenance"],
"properties": {
"id": {"type": "string", "minLength": 1},
"contract_version": {"const": "flex-auth.decision-record.v1"},
"request_id": {"type": "string", "minLength": 1},
"effect": {"enum": ["allow", "deny", "redact", "audit_only", "not_applicable"]},
"reason": {"type": "string"},
@ -15,11 +17,18 @@
"resource": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/resource_ref"},
"subject": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/subject_ref"},
"binding": {"$ref": "#/$defs/decision_binding"},
"lifetime": {"$ref": "#/$defs/lifetime"},
"obligations": {"type": "array", "items": {"$ref": "#/$defs/obligation"}},
"diagnostics": {"type": "object", "additionalProperties": true},
"provenance": {"$ref": "#/$defs/provenance"},
"caring": {"$ref": "#/$defs/caring_decision_metadata"}
},
"allOf": [
{
"if": {"properties": {"effect": {"const": "allow"}}, "required": ["effect"]},
"then": {"required": ["lifetime"]}
}
],
"$defs": {
"decision_binding": {
"type": "object",
@ -43,6 +52,17 @@
"parameters": {"type": "object", "additionalProperties": true}
}
},
"lifetime": {
"type": "object",
"additionalProperties": false,
"required": ["kind", "expires_at"],
"properties": {
"kind": {"enum": ["ttl"]},
"ttl": {"type": "string", "minLength": 1},
"not_before": {"type": "string", "minLength": 1},
"expires_at": {"type": "string", "minLength": 1}
}
},
"provenance": {
"type": "object",
"additionalProperties": false,
@ -52,7 +72,13 @@
"mode": {"type": "string", "minLength": 1},
"policy_package": {"type": "string", "minLength": 1},
"policy_version": {"type": "string", "minLength": 1},
"policy_package_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"},
"registry_snapshot_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"},
"directory_etag": {"type": "string", "minLength": 1},
"input_claim_digests": {
"type": "object",
"additionalProperties": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"}
},
"decision_time": {"type": "string", "minLength": 1}
}
},