feat: integrate durable authorization audit and runtime composition
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:01:42 +02:00
parent 3e386147fd
commit c9b6916dac
14 changed files with 767 additions and 16 deletions

View file

@ -157,3 +157,14 @@ def test_policy_client_rotates_workload_credentials_and_retains_no_user_token(tm
asyncio.run(run())
assert seen == ['Bearer first-workload-token', 'Bearer second-workload-token',
'Bearer second-workload-token']
def test_signed_decision_is_retained_exactly_and_sensitive_fields_are_refused():
request,envelope,now = case()
keys = sign(envelope)
result = verify_decision(envelope,request=request,keys=keys,caller='workload:hub',now=now)
assert result.signed_envelope == go_json(envelope).decode()
verify_signature(parse_json(result.signed_envelope),keys)
envelope['diagnostics'] = {'access_token':'must-not-be-archived'}
with pytest.raises(ValueError,match='sensitive decision field'):
verify_decision(envelope,request=request,keys=sign(envelope),caller='workload:hub',now=now)