feat: add OIDC browser sessions with live access enforcement
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
fdea2f5192
commit
a15fe032b0
14 changed files with 807 additions and 31 deletions
|
|
@ -17,6 +17,7 @@ def discover(root):
|
|||
from hub_core.runtime.app import create_app
|
||||
from hub_core.runtime.config import RuntimeSettings
|
||||
from hub_core.runtime.inbox_projection import create_inbox_projection_router
|
||||
from hub_core.security.browser import create_browser_router
|
||||
|
||||
rows = []
|
||||
|
||||
|
|
@ -31,7 +32,7 @@ def discover(root):
|
|||
|
||||
# Construction only: no lifespan/startup and no requests or DB connection.
|
||||
app = create_app(settings=RuntimeSettings())
|
||||
for route in [*routes(app), *routes(create_inbox_projection_router())]:
|
||||
for route in [*routes(app), *routes(create_inbox_projection_router()), *routes(create_browser_router())]:
|
||||
endpoint = route.endpoint
|
||||
source = inspect.getsource(endpoint)
|
||||
module = endpoint.__module__
|
||||
|
|
@ -39,11 +40,14 @@ def discover(root):
|
|||
else 'no-identity-check-in-handler')
|
||||
if route.path != '/healthz':
|
||||
gate = 'access-profile-v1 in enforcement mode; development: ' + gate
|
||||
browser = module.endswith("security.browser")
|
||||
if browser:
|
||||
gate = "OIDC state/PKCE callback or server-side session; explicit browser composition only"
|
||||
for method in sorted(route.methods):
|
||||
rows.append(dict(id=f'http:{method}:{route.path}:{module}.{endpoint.__name__}', kind='runtime-http',
|
||||
method=method, path=route.path, profile=('minimal-health' if route.path == '/healthz' else 'hub-api'),
|
||||
method=method, path=route.path, profile=('minimal-health' if route.path == '/healthz' else 'browser-session' if browser else 'hub-api'),
|
||||
current_gate=gate, source=module,
|
||||
conditional=module.endswith('inbox_projection'),
|
||||
conditional=browser or module.endswith('inbox_projection'),
|
||||
handler=endpoint.__name__))
|
||||
|
||||
verbs = {'get', 'post', 'patch', 'put', 'delete', 'head', 'options'}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue