feat: add fail-closed Hub access profile foundation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
df39fd5f43
commit
3e386147fd
35 changed files with 2009 additions and 195 deletions
|
|
@ -44,8 +44,9 @@ PYTHONDONTWRITEBYTECODE=1 .venv/bin/python tools/build_access_inventory.py \
|
|||
Omit `--check` to refresh source rows after intentional changes, then review the
|
||||
diff. Cluster metadata is a dated reviewed input, not silently refreshed by this
|
||||
command. The checker detects source drift, missing profile/test references and
|
||||
missing/duplicate cluster-object mappings. It does not test authorization. Actual
|
||||
allow/deny cases are all marked `not-run`; implementation tasks must supply the
|
||||
missing/duplicate cluster-object mappings. It does not test authorization. Live
|
||||
allow/deny cases remain marked `not-run`; the [source candidate](access-profile-v1.md)
|
||||
adds local enforcement tests. Implementation tasks must still supply the
|
||||
client fixtures, isolated mutations, independent readbacks and live receipts.
|
||||
|
||||
## Findings that affect implementation
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue