feat: add OIDC browser sessions with live access enforcement
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
fdea2f5192
commit
a15fe032b0
14 changed files with 807 additions and 31 deletions
|
|
@ -12,7 +12,7 @@ upgrade:** the default production factory has no admitted owner adapters yet and
|
|||
returns 401 for missing credentials and 503 for credential-bearing requests.
|
||||
The current deployed image and its release configuration have not been changed.
|
||||
|
||||
Only exact `GET /healthz` is public, returning `{"status":"ok"}`. The shared
|
||||
Without explicit browser composition, only exact `GET /healthz` is public, returning `{"status":"ok"}`. The shared
|
||||
ASGI boundary protects docs, readiness, native ports, projections, compatibility
|
||||
aliases and subsequently attached routes. Unknown method/route/handler combinations,
|
||||
WebSockets, mounts without admission, and slash redirects without catalog entries
|
||||
|
|
@ -26,6 +26,10 @@ It is packaged in the wheel and tested against actual route construction. Source
|
|||
inventory generation does **not** auto-admit a new route. Duplicate docs handlers
|
||||
remain separately inventoried; the boundary selects the first effective route.
|
||||
These technical action names require flex-auth/owner review before policy delivery.
|
||||
Optional browser composition adds four exact `/auth/*` protocol routes and the
|
||||
`hub.browser.session` action; login initiation is public, callback state is
|
||||
browser-bound, and session access requires current root authority. See the
|
||||
[browser integration contract](owner-access-integration.md#browser-composition-source-candidate).
|
||||
|
||||
## Composition and trust
|
||||
|
||||
|
|
@ -76,7 +80,7 @@ and Phase 2 storage/query isolation are not implemented by this classification.
|
|||
The PDP request carries actor, target tenant, action, concrete resource path,
|
||||
assurance, root entitlement, authoritative evidence reference, and a digest of
|
||||
HTTP method/path/query/body. Client bodies and bearer tokens are not sent to the
|
||||
PDP or audit sink. Body size is bounded at 1 MiB. The controller's identity/facts/
|
||||
PDP or audit sink. Body size is bounded at 1 MiB with a ten-second receive deadline. The controller's identity/facts/
|
||||
policy/audit chain has a ten-second timeout; individual HTTP calls have three seconds.
|
||||
A separate refusal-audit attempt is bounded at three seconds.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue