fix: recheck policy decision expiry after audit custody
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
72f3513954
commit
f11b948e8c
7 changed files with 126 additions and 8 deletions
|
|
@ -89,8 +89,15 @@ A separate refusal-audit attempt is bounded at three seconds.
|
|||
|
||||
The verifier requires Ed25519 signing, the submitted request digest, matching
|
||||
request ID and structured actor/action/resource/tenant/context, enforced caller
|
||||
provenance, policy version/digest, a decision age at most 30 seconds and a valid
|
||||
allow lifetime. It never caches decisions. Every unimplemented obligation and
|
||||
provenance, policy version/digest, a decision age below 30 seconds and a valid
|
||||
allow lifetime. `Decision.valid_until` is a required finite epoch deadline, derived
|
||||
from the earliest signed allow expiry, caller expiry and decision-time freshness
|
||||
limit. The controller checks it before audit and again after durable acceptance,
|
||||
before returning authority to HTTP, browser or direct SDK callers. Expiry during
|
||||
custody returns `503 policy_decision_expired`; an authorization receipt is not
|
||||
permission to execute after expiry. Custom policy adapters must supply this field
|
||||
from verified provenance, never a fresh deadline invented at receipt time.
|
||||
It never caches decisions. Every unimplemented obligation and
|
||||
non-allow/non-deny effect fails closed; approval requirements cannot be waived.
|
||||
A malformed/untrusted/unavailable decision returns 503, a verified denial 403,
|
||||
and invalid authentication 401. Responses are `no-store` and do not expose backend
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue