feat: add fail-closed Hub access profile foundation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
df39fd5f43
commit
3e386147fd
35 changed files with 2009 additions and 195 deletions
|
|
@ -37,6 +37,8 @@ def discover(root):
|
|||
module = endpoint.__module__
|
||||
gate = ('shared-bearer' if '_protected(' in source or module.endswith('inbox_projection')
|
||||
else 'no-identity-check-in-handler')
|
||||
if route.path != '/healthz':
|
||||
gate = 'access-profile-v1 in enforcement mode; development: ' + gate
|
||||
for method in sorted(route.methods):
|
||||
rows.append(dict(id=f'http:{method}:{route.path}:{module}.{endpoint.__name__}', kind='runtime-http',
|
||||
method=method, path=route.path, profile=('minimal-health' if route.path == '/healthz' else 'hub-api'),
|
||||
|
|
@ -94,7 +96,7 @@ def discover(root):
|
|||
calls.append(dict(method=call.func.attr[1:].upper(), path_expression=ast.unparse(call.args[0])))
|
||||
rows.append(dict(id=f'mcp:{name}', kind='mcp', tool=name, profile='mcp-client',
|
||||
source=str(path.relative_to(root)), line=node.lineno,
|
||||
target_calls=calls, current_gate='no per-user credential forwarding in base wrapper'))
|
||||
target_calls=calls, current_gate='per-invocation token provider available; host adoption required'))
|
||||
assert expected == {r['tool'] for r in rows if r['kind'] == 'mcp'}
|
||||
assert len(rows) == len({r['id'] for r in rows}), 'Duplicate surface identity'
|
||||
return sorted(rows, key=lambda r:r['id'])
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue