Close the remaining PDP obligations: mechanical layer declaration check, registry-snapshot digest in provenance, explicit allow TTL, per-input-class freshness deadlines, and the published decision-record contract. Document the canonical request digest as the §6.4.2 replay test. Assistant: grok Assistant-Session: 01a06256-fb71-7102-b3a9-27e6734257d0
114 lines
5 KiB
JSON
114 lines
5 KiB
JSON
{
|
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
"$id": "https://flex-auth.netkingdom/schemas/decision_envelope.schema.json",
|
|
"title": "DecisionEnvelope",
|
|
"description": "Published flex-auth decision-record contract (flex-auth.decision-record.v1). This is the PDP's output artifact under security-layer-model_v0.7 §17.",
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["id", "effect", "resource", "subject", "provenance"],
|
|
"properties": {
|
|
"id": {"type": "string", "minLength": 1},
|
|
"contract_version": {"const": "flex-auth.decision-record.v1"},
|
|
"request_id": {"type": "string", "minLength": 1},
|
|
"effect": {"enum": ["allow", "deny", "redact", "audit_only", "not_applicable"]},
|
|
"reason": {"type": "string"},
|
|
"matched_policy_version": {"type": "string", "minLength": 1},
|
|
"matched_rule": {"type": "string", "minLength": 1},
|
|
"resource": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/resource_ref"},
|
|
"subject": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/subject_ref"},
|
|
"binding": {"$ref": "#/$defs/decision_binding"},
|
|
"lifetime": {"$ref": "#/$defs/lifetime"},
|
|
"obligations": {"type": "array", "items": {"$ref": "#/$defs/obligation"}},
|
|
"diagnostics": {"type": "object", "additionalProperties": true},
|
|
"provenance": {"$ref": "#/$defs/provenance"},
|
|
"caring": {"$ref": "#/$defs/caring_decision_metadata"}
|
|
},
|
|
"allOf": [
|
|
{
|
|
"if": {"properties": {"effect": {"const": "allow"}}, "required": ["effect"]},
|
|
"then": {"required": ["lifetime"]}
|
|
}
|
|
],
|
|
"$defs": {
|
|
"decision_binding": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["subject", "action", "resource", "request_digest"],
|
|
"properties": {
|
|
"tenant": {"type": "string", "minLength": 1},
|
|
"subject": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/subject_ref"},
|
|
"action": {"type": "string", "minLength": 1},
|
|
"resource": {"$ref": "https://flex-auth.netkingdom/schemas/check_request.schema.json#/$defs/resource_ref"},
|
|
"context": {"type": "object", "additionalProperties": true},
|
|
"request_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"}
|
|
}
|
|
},
|
|
"obligation": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["type"],
|
|
"properties": {
|
|
"type": {"type": "string", "minLength": 1},
|
|
"parameters": {"type": "object", "additionalProperties": true}
|
|
}
|
|
},
|
|
"lifetime": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["kind", "expires_at"],
|
|
"properties": {
|
|
"kind": {"enum": ["ttl"]},
|
|
"ttl": {"type": "string", "minLength": 1},
|
|
"not_before": {"type": "string", "minLength": 1},
|
|
"expires_at": {"type": "string", "minLength": 1}
|
|
}
|
|
},
|
|
"provenance": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["evaluator", "mode"],
|
|
"properties": {
|
|
"evaluator": {"type": "string", "minLength": 1},
|
|
"mode": {"type": "string", "minLength": 1},
|
|
"policy_package": {"type": "string", "minLength": 1},
|
|
"policy_version": {"type": "string", "minLength": 1},
|
|
"policy_package_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"},
|
|
"registry_snapshot_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"},
|
|
"directory_etag": {"type": "string", "minLength": 1},
|
|
"input_claim_digests": {
|
|
"type": "object",
|
|
"additionalProperties": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"}
|
|
},
|
|
"decision_time": {"type": "string", "minLength": 1}
|
|
}
|
|
},
|
|
"caring_decision_metadata": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["profile"],
|
|
"properties": {
|
|
"profile": {"const": "caring-0.4.0-rc2"},
|
|
"descriptor": {"$ref": "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json"},
|
|
"restrictions_evaluated": {
|
|
"type": "array",
|
|
"items": {"$ref": "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/restriction"},
|
|
"uniqueItems": true
|
|
},
|
|
"exposure_modes": {
|
|
"type": "array",
|
|
"items": {"$ref": "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/exposure_mode"},
|
|
"uniqueItems": true
|
|
},
|
|
"derived_capabilities": {
|
|
"type": "array",
|
|
"items": {"$ref": "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/derived_capability"}
|
|
},
|
|
"conformance_findings": {
|
|
"type": "array",
|
|
"items": {"$ref": "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/conformance_finding"}
|
|
},
|
|
"exposure_event": {"$ref": "https://flex-auth.netkingdom/schemas/caring_access_descriptor.schema.json#/$defs/exposure_event"}
|
|
}
|
|
}
|
|
}
|
|
}
|