fix: recheck policy decision expiry after audit custody
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 15:56:52 +02:00
parent 72f3513954
commit f11b948e8c
7 changed files with 126 additions and 8 deletions

View file

@ -89,8 +89,15 @@ A separate refusal-audit attempt is bounded at three seconds.
The verifier requires Ed25519 signing, the submitted request digest, matching
request ID and structured actor/action/resource/tenant/context, enforced caller
provenance, policy version/digest, a decision age at most 30 seconds and a valid
allow lifetime. It never caches decisions. Every unimplemented obligation and
provenance, policy version/digest, a decision age below 30 seconds and a valid
allow lifetime. `Decision.valid_until` is a required finite epoch deadline, derived
from the earliest signed allow expiry, caller expiry and decision-time freshness
limit. The controller checks it before audit and again after durable acceptance,
before returning authority to HTTP, browser or direct SDK callers. Expiry during
custody returns `503 policy_decision_expired`; an authorization receipt is not
permission to execute after expiry. Custom policy adapters must supply this field
from verified provenance, never a fresh deadline invented at receipt time.
It never caches decisions. Every unimplemented obligation and
non-allow/non-deny effect fails closed; approval requirements cannot be waived.
A malformed/untrusted/unavailable decision returns 503, a verified denial 403,
and invalid authentication 401. Responses are `no-store` and do not expose backend

View file

@ -21,7 +21,8 @@ cancellation mark it unavailable immediately. Successful observations expire to
`stale` after ten seconds using a monotonic clock. Invalid user-token refusals
neither poison a previously healthy identity sample nor refresh its age. Invalid
facts and malformed policy adapter results do not count as success. A fact that
expires while policy/audit run also becomes unavailable. The aggregate is `ok`
expires while policy/audit run also becomes unavailable. A decision that expires
before dispatch marks policy unavailable, even if audit custody succeeded. The aggregate is `ok`
only when all four samples are fresh successes.
These process-local observations are diagnostics, never cached authorization.