feat: integrate durable authorization audit and runtime composition
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:01:42 +02:00
parent 3e386147fd
commit c9b6916dac
14 changed files with 767 additions and 16 deletions

View file

@ -92,6 +92,20 @@ def _time(value: str) -> datetime:
def verify_decision(envelope: dict, *, request: dict, keys: dict,
caller: str, now: datetime | None = None) -> Decision:
verify_signature(envelope, keys)
# The exact signed artifact is retained for independent verification. Do
# not hide secret-shaped fields in its serialized audit representation.
def check_fields(value):
if isinstance(value, dict):
for key, item in value.items():
if any(fragment in key.lower() for fragment in (
"password", "secret", "token", "credential", "private_key",
)):
raise ValueError("sensitive decision field is outside the audit profile")
check_fields(item)
elif isinstance(value, list):
for item in value:
check_fields(item)
check_fields(envelope)
now = now or datetime.now(timezone.utc)
if (envelope["contract_version"] != "flex-auth.decision-record.v1"
or envelope["request_id"] != request["id"] or not envelope["id"]):
@ -132,7 +146,8 @@ def verify_decision(envelope: dict, *, request: dict, keys: dict,
if (lifetime["kind"] != "ttl" or not
_time(lifetime["not_before"]) <= now < _time(lifetime["expires_at"])):
raise ValueError("invalid decision lifetime")
return Decision(envelope["effect"] == "allow", envelope["id"], provenance["policy_version"], caller)
return Decision(envelope["effect"] == "allow", envelope["id"], provenance["policy_version"],
caller, go_json(envelope).decode())
class FlexPolicy: