feat: integrate durable authorization audit and runtime composition
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
3e386147fd
commit
c9b6916dac
14 changed files with 767 additions and 16 deletions
|
|
@ -157,3 +157,14 @@ def test_policy_client_rotates_workload_credentials_and_retains_no_user_token(tm
|
|||
asyncio.run(run())
|
||||
assert seen == ['Bearer first-workload-token', 'Bearer second-workload-token',
|
||||
'Bearer second-workload-token']
|
||||
|
||||
|
||||
def test_signed_decision_is_retained_exactly_and_sensitive_fields_are_refused():
|
||||
request,envelope,now = case()
|
||||
keys = sign(envelope)
|
||||
result = verify_decision(envelope,request=request,keys=keys,caller='workload:hub',now=now)
|
||||
assert result.signed_envelope == go_json(envelope).decode()
|
||||
verify_signature(parse_json(result.signed_envelope),keys)
|
||||
envelope['diagnostics'] = {'access_token':'must-not-be-archived'}
|
||||
with pytest.raises(ValueError,match='sensitive decision field'):
|
||||
verify_decision(envelope,request=request,keys=sign(envelope),caller='workload:hub',now=now)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue