fix: recheck policy decision expiry after audit custody
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
72f3513954
commit
f11b948e8c
7 changed files with 126 additions and 8 deletions
|
|
@ -89,8 +89,15 @@ A separate refusal-audit attempt is bounded at three seconds.
|
|||
|
||||
The verifier requires Ed25519 signing, the submitted request digest, matching
|
||||
request ID and structured actor/action/resource/tenant/context, enforced caller
|
||||
provenance, policy version/digest, a decision age at most 30 seconds and a valid
|
||||
allow lifetime. It never caches decisions. Every unimplemented obligation and
|
||||
provenance, policy version/digest, a decision age below 30 seconds and a valid
|
||||
allow lifetime. `Decision.valid_until` is a required finite epoch deadline, derived
|
||||
from the earliest signed allow expiry, caller expiry and decision-time freshness
|
||||
limit. The controller checks it before audit and again after durable acceptance,
|
||||
before returning authority to HTTP, browser or direct SDK callers. Expiry during
|
||||
custody returns `503 policy_decision_expired`; an authorization receipt is not
|
||||
permission to execute after expiry. Custom policy adapters must supply this field
|
||||
from verified provenance, never a fresh deadline invented at receipt time.
|
||||
It never caches decisions. Every unimplemented obligation and
|
||||
non-allow/non-deny effect fails closed; approval requirements cannot be waived.
|
||||
A malformed/untrusted/unavailable decision returns 503, a verified denial 403,
|
||||
and invalid authentication 401. Responses are `no-store` and do not expose backend
|
||||
|
|
|
|||
|
|
@ -21,7 +21,8 @@ cancellation mark it unavailable immediately. Successful observations expire to
|
|||
`stale` after ten seconds using a monotonic clock. Invalid user-token refusals
|
||||
neither poison a previously healthy identity sample nor refresh its age. Invalid
|
||||
facts and malformed policy adapter results do not count as success. A fact that
|
||||
expires while policy/audit run also becomes unavailable. The aggregate is `ok`
|
||||
expires while policy/audit run also becomes unavailable. A decision that expires
|
||||
before dispatch marks policy unavailable, even if audit custody succeeded. The aggregate is `ok`
|
||||
only when all four samples are fresh successes.
|
||||
|
||||
These process-local observations are diagnostics, never cached authorization.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue