feat: add OIDC browser sessions with live access enforcement
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:17:16 +02:00
parent fdea2f5192
commit a15fe032b0
14 changed files with 807 additions and 31 deletions

View file

@ -227,3 +227,24 @@ def test_fact_strings_cannot_be_truthy_grants_and_denials_retain_actor():
assert owners.records[-1]['subject'] == 'ordinary'
assert owners.records[-1]['action']
assert owners.records[-1]['request_digest']
def test_slow_request_body_times_out_before_authority_or_handler():
from hub_core.security.boundary import AccessBoundary
owners = Owners()
host = runtime(owners)
called = []
messages = []
async def handler(scope, receive, send):
called.append(True)
boundary = AccessBoundary(handler, host=host, controller=owners.controller(), body_timeout=0.01)
scope = {'type':'http','method':'POST','path':'/ports/messaging/messages',
'headers':[(b'authorization',b'Bearer verified-root')], 'query_string':b''}
async def receive():
await asyncio.Future()
async def send(message):
messages.append(message)
asyncio.run(boundary(scope,receive,send))
assert messages[0]['status'] == 408
assert not called and not owners.requests
assert owners.records[-1]['reason'] == 'request_body_timeout'