qonto-assistant/pyproject.toml

53 lines
1.1 KiB
TOML
Raw Normal View History

[build-system]
requires = ["setuptools>=68", "wheel"]
build-backend = "setuptools.build_meta"
[project]
name = "qonto-assistant"
version = "0.1.0"
description = "Governed Qonto read-only REST assistant for multi-harness finance awareness."
readme = "README.md"
requires-python = ">=3.12"
license = { file = "LICENSE" }
authors = [{ name = "Coulomb" }]
dependencies = [
"fastapi>=0.115,<1.0",
"httpx>=0.27,<1.0",
"mcp>=1.9,<2.0",
QONTO-WP-0004-T03: verify key-cape IAM Profile tokens Replaces the interim shared-secret bearer token's role as the identity boundary with real key-cape JWKS-based verification, closing the gap docs/mcp-integration.md called out explicitly ("no OIDC issuer exists in this fleet yet") -- key-cape's /jwks is a standard RS256 endpoint and needed no key-cape-side work to consume. KeyCapeTokenVerifier fetches and caches signing keys over httpx (matching FlexAuthCheckClient's pattern elsewhere in this codebase), validates iss/aud/exp and the IAM Profile v0.3 required claims, and derives ActorClaims from the token (tenant, scopes, and a lane inferred from the roles claim). Wired into auth.actor_claims_from_headers, the single seam both REST and MCP already used -- a verified bearer token now takes precedence over self-asserted X-Actor-* headers, and can be made mandatory via QONTO_KEY_CAPE_REQUIRED once real tokens are issued to callers. Off by default (no QONTO_KEY_CAPE_JWKS_URL set) so existing deployments are unaffected until configured. The QONTO_ASSISTANT_MCP_TOKEN shared secret remains as a documented local-dev/legacy fallback, not the auth boundary going forward. Verified: 13 new tests (test_key_cape_auth.py) covering valid/expired/ wrong-audience/wrong-issuer/missing-claim/unknown-key/rotated-key tokens plus the auth.py precedence and required-vs-optional integration paths, using a real generated RSA keypair and JWKS served over httpx.MockTransport. Full suite -> 52 passed; REST and MCP smokes both still pass against fixtures; compileall clean. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:10:41 +02:00
"PyJWT[crypto]>=2.9,<3.0",
"PyYAML>=6.0,<7.0",
"uvicorn[standard]>=0.30,<1.0",
]
[project.optional-dependencies]
dev = [
"pytest>=8.2,<9.0",
"pytest-asyncio>=0.24,<1.0",
"ruff>=0.6,<1.0",
]
[project.scripts]
qonto-assistant = "qonto_assistant.main:main"
[tool.setuptools.packages.find]
where = ["src"]
[tool.setuptools.package-data]
qonto_assistant = ["policy/*.yaml"]
[tool.pytest.ini_options]
testpaths = ["tests"]
addopts = [
"--strict-markers",
"--disable-warnings",
"--tb=short",
]
asyncio_mode = "auto"
[tool.ruff]
line-length = 100
target-version = "py312"
[tool.ruff.lint]
select = ["E", "F", "I", "B"]