Finish FLEX-WP-0019 layer-model v0.7 conformance
Close the remaining PDP obligations: mechanical layer declaration check, registry-snapshot digest in provenance, explicit allow TTL, per-input-class freshness deadlines, and the published decision-record contract. Document the canonical request digest as the §6.4.2 replay test. Assistant: grok Assistant-Session: 01a06256-fb71-7102-b3a9-27e6734257d0
This commit is contained in:
parent
9689894c15
commit
56940727bf
32 changed files with 1194 additions and 111 deletions
|
|
@ -2,11 +2,13 @@
|
|||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||
"$id": "https://flex-auth.netkingdom/schemas/decision_envelope.schema.json",
|
||||
"title": "DecisionEnvelope",
|
||||
"description": "Published flex-auth decision-record contract (flex-auth.decision-record.v1). This is the PDP's output artifact under security-layer-model_v0.7 §17.",
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": ["id", "effect", "resource", "subject", "provenance"],
|
||||
"properties": {
|
||||
"id": {"type": "string", "minLength": 1},
|
||||
"contract_version": {"const": "flex-auth.decision-record.v1"},
|
||||
"request_id": {"type": "string", "minLength": 1},
|
||||
"effect": {"enum": ["allow", "deny", "redact", "audit_only", "not_applicable"]},
|
||||
"reason": {"type": "string"},
|
||||
|
|
@ -15,11 +17,18 @@
|
|||
"resource": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/resource_ref"},
|
||||
"subject": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/subject_ref"},
|
||||
"binding": {"$ref": "#/$defs/decision_binding"},
|
||||
"lifetime": {"$ref": "#/$defs/lifetime"},
|
||||
"obligations": {"type": "array", "items": {"$ref": "#/$defs/obligation"}},
|
||||
"diagnostics": {"type": "object", "additionalProperties": true},
|
||||
"provenance": {"$ref": "#/$defs/provenance"},
|
||||
"caring": {"$ref": "#/$defs/caring_decision_metadata"}
|
||||
},
|
||||
"allOf": [
|
||||
{
|
||||
"if": {"properties": {"effect": {"const": "allow"}}, "required": ["effect"]},
|
||||
"then": {"required": ["lifetime"]}
|
||||
}
|
||||
],
|
||||
"$defs": {
|
||||
"decision_binding": {
|
||||
"type": "object",
|
||||
|
|
@ -43,6 +52,17 @@
|
|||
"parameters": {"type": "object", "additionalProperties": true}
|
||||
}
|
||||
},
|
||||
"lifetime": {
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": ["kind", "expires_at"],
|
||||
"properties": {
|
||||
"kind": {"enum": ["ttl"]},
|
||||
"ttl": {"type": "string", "minLength": 1},
|
||||
"not_before": {"type": "string", "minLength": 1},
|
||||
"expires_at": {"type": "string", "minLength": 1}
|
||||
}
|
||||
},
|
||||
"provenance": {
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
|
|
@ -52,7 +72,13 @@
|
|||
"mode": {"type": "string", "minLength": 1},
|
||||
"policy_package": {"type": "string", "minLength": 1},
|
||||
"policy_version": {"type": "string", "minLength": 1},
|
||||
"policy_package_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"},
|
||||
"registry_snapshot_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"},
|
||||
"directory_etag": {"type": "string", "minLength": 1},
|
||||
"input_claim_digests": {
|
||||
"type": "object",
|
||||
"additionalProperties": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"}
|
||||
},
|
||||
"decision_time": {"type": "string", "minLength": 1}
|
||||
}
|
||||
},
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue