fix: recheck policy decision expiry after audit custody
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 15:56:52 +02:00
parent 72f3513954
commit f11b948e8c
7 changed files with 126 additions and 8 deletions

View file

@ -4,7 +4,7 @@ from __future__ import annotations
import base64
import hashlib
import json
from datetime import datetime, timezone
from datetime import datetime, timedelta, timezone
from pathlib import Path
import httpx
@ -133,7 +133,7 @@ def verify_decision(envelope: dict, *, request: dict, keys: dict,
if not provenance["policy_version"] or not provenance["policy_package_digest"]:
raise ValueError("missing policy provenance")
age = (now - _time(provenance["decision_time"])).total_seconds()
if not 0 <= age <= 30:
if not 0 <= age < 30:
raise ValueError("stale decision")
if envelope.get("obligations"):
# No obligation is silently treated as satisfied. Owner-specific
@ -141,13 +141,16 @@ def verify_decision(envelope: dict, *, request: dict, keys: dict,
raise ValueError("unsupported decision obligations")
if envelope["effect"] not in {"allow", "deny"}:
raise ValueError("unsupported effect")
deadline = min(_time(caller_record["not_after"]),
_time(provenance["decision_time"]) + timedelta(seconds=30))
if envelope["effect"] == "allow":
lifetime = envelope["lifetime"]
if (lifetime["kind"] != "ttl" or not
_time(lifetime["not_before"]) <= now < _time(lifetime["expires_at"])):
raise ValueError("invalid decision lifetime")
deadline = min(deadline, _time(lifetime["expires_at"]))
return Decision(envelope["effect"] == "allow", envelope["id"], provenance["policy_version"],
caller, go_json(envelope).decode())
deadline.timestamp(), caller, go_json(envelope).decode())
class FlexPolicy: