feat: integrate durable authorization audit and runtime composition
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
3e386147fd
commit
c9b6916dac
14 changed files with 767 additions and 16 deletions
|
|
@ -92,6 +92,20 @@ def _time(value: str) -> datetime:
|
|||
def verify_decision(envelope: dict, *, request: dict, keys: dict,
|
||||
caller: str, now: datetime | None = None) -> Decision:
|
||||
verify_signature(envelope, keys)
|
||||
# The exact signed artifact is retained for independent verification. Do
|
||||
# not hide secret-shaped fields in its serialized audit representation.
|
||||
def check_fields(value):
|
||||
if isinstance(value, dict):
|
||||
for key, item in value.items():
|
||||
if any(fragment in key.lower() for fragment in (
|
||||
"password", "secret", "token", "credential", "private_key",
|
||||
)):
|
||||
raise ValueError("sensitive decision field is outside the audit profile")
|
||||
check_fields(item)
|
||||
elif isinstance(value, list):
|
||||
for item in value:
|
||||
check_fields(item)
|
||||
check_fields(envelope)
|
||||
now = now or datetime.now(timezone.utc)
|
||||
if (envelope["contract_version"] != "flex-auth.decision-record.v1"
|
||||
or envelope["request_id"] != request["id"] or not envelope["id"]):
|
||||
|
|
@ -132,7 +146,8 @@ def verify_decision(envelope: dict, *, request: dict, keys: dict,
|
|||
if (lifetime["kind"] != "ttl" or not
|
||||
_time(lifetime["not_before"]) <= now < _time(lifetime["expires_at"])):
|
||||
raise ValueError("invalid decision lifetime")
|
||||
return Decision(envelope["effect"] == "allow", envelope["id"], provenance["policy_version"], caller)
|
||||
return Decision(envelope["effect"] == "allow", envelope["id"], provenance["policy_version"],
|
||||
caller, go_json(envelope).decode())
|
||||
|
||||
|
||||
class FlexPolicy:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue