flex-auth/internal/policy/testdata/undeclared-ceiling/policy_package.md
tegwick c074237aac Make undeclared policy attribute reads a validate error.
FLEX-WP-0025-T03: flex-auth validate flags input.*.attributes keys that
no sibling registry or manifest supplies. A broken testdata package
proves tests can pass while the ceiling remains caller-only.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-14 09:54:09 +02:00

1.4 KiB

id name namespace version status package actions owner fixtures caring
testdata.undeclared-ceiling deliberately undeclared ceiling key testdata:secret v1 fixture flexauth.testdata.undeclared_ceiling
sign
team:platform-security
policy_fixtures.yaml
profile enforce canonical_roles organization_relations scopes planes capabilities exposure_modes conditions restrictions
caring-0.4.0-rc2 false
Operator
ServiceProvider
level id tenant
Platform platform:testdata tenant:platform
Secret
Use
Metadata
Logged
PrivilegeEscalationBlocked

Undeclared ceiling (FLEX-WP-0025-T03)

This package exists to prove flex-auth validate flags a ceiling read from a key the sibling registry never supplies. Do not copy it.

import future.keywords.if

default decision := {"effect": "deny", "reason": "no_matching_rule"}

decision := {"effect": "allow", "reason": "ttl_ok"} if {
  input.action == "sign"
  input.context.ttl_hours <= input.resource.attributes.max_ttl_hours
}
package flexauth.testdata.undeclared_ceiling_test
import future.keywords.if
import data.flexauth.testdata.undeclared_ceiling

test_allow if {
  undeclared_ceiling.decision.effect == "allow" with input as {
    "action": "sign",
    "context": {"ttl_hours": 1},
    "resource": {"attributes": {"max_ttl_hours": 8}}
  }
}