feat: integrate durable authorization audit and runtime composition
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
3e386147fd
commit
c9b6916dac
14 changed files with 767 additions and 16 deletions
|
|
@ -67,6 +67,7 @@ class Decision:
|
|||
decision_id: str
|
||||
policy_version: str
|
||||
caller: str = ""
|
||||
signed_envelope: str | None = None
|
||||
|
||||
def __post_init__(self):
|
||||
if type(self.allowed) is not bool or not self.decision_id or not self.policy_version:
|
||||
|
|
@ -146,6 +147,7 @@ class AccessController:
|
|||
"request_digest": request_digest, "facts_evidence": facts.evidence_id,
|
||||
"decision_id": decision.decision_id, "policy_version": decision.policy_version,
|
||||
"policy_caller": decision.caller,
|
||||
"signed_decision": decision.signed_envelope,
|
||||
"outcome": "authorized" if decision.allowed else "denied",
|
||||
})
|
||||
if not decision.allowed:
|
||||
|
|
@ -196,6 +198,8 @@ class AccessBoundary:
|
|||
return
|
||||
correlation = str(uuid4())
|
||||
context = None
|
||||
action = None
|
||||
digest = None
|
||||
try:
|
||||
headers = Request(scope).headers.getlist("authorization")
|
||||
if len(headers) != 1 or not headers[0].startswith("Bearer "):
|
||||
|
|
@ -250,6 +254,11 @@ class AccessBoundary:
|
|||
"subject": actor.subject if actor else None,
|
||||
"issuer": actor.issuer if actor else None,
|
||||
"actor_tenant": actor.tenant if actor else None,
|
||||
"principal_type": actor.principal_type if actor else None,
|
||||
"action": action,
|
||||
"resource_digest": hashlib.sha256(scope["path"].encode()).hexdigest(),
|
||||
"request_digest": digest,
|
||||
"target_tenant": "tenant:platform",
|
||||
})
|
||||
except Exception:
|
||||
failure = AccessFailure(503, "audit_unavailable")
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue