Implement authenticated alert receipt acknowledgments and audit delivery

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
tegwick 2026-09-28 11:11:33 +02:00
parent 67283b66c2
commit e7282e493d
25 changed files with 1881 additions and 0 deletions

View file

@ -0,0 +1,42 @@
"""Run inside the existing identity-provisioner pod; never print credentials.
Default is read-only. --apply adds only the approved user's named group.
"""
import json
import os
import sys
from provisioner import LLDAPProvisioner
def main():
apply = sys.argv[1:] == ['--apply']
if sys.argv[1:] not in ([], ['--apply']):
raise ValueError()
if os.environ['LLDAP_URL'] != 'http://lldap.sso.svc.cluster.local:17170':
raise ValueError()
client = LLDAPProvisioner(base_url=os.environ['LLDAP_URL'], admin_password=os.environ['LLDAP_ADMIN_PASSWORD'])
token = client._login()
user = client._user(token, 'tegwick')
if not user or user['id'] != 'tegwick' or user['email'].lower() != 'bernd.worsch@gmail.com':
raise ValueError()
before = {g['displayName'] for g in user['groups']}
if apply and 'railiance-admins' not in before:
groups = client._gql(token, 'query { groups { id displayName } }', {})['groups']
group = client._ensure_group(token, groups, 'railiance-admins')
client._add_group(token, 'tegwick', group)
after = {g['displayName'] for g in client._user(token, 'tegwick')['groups']}
if not before <= after or after - before - {'railiance-admins'}:
raise ValueError()
if apply and 'railiance-admins' not in after:
raise ValueError()
print(json.dumps({'mode': 'apply' if apply else 'inspect', 'directory_user': 'tegwick',
'email_matches_requested_recipient': True, 'group': 'railiance-admins',
'member': 'railiance-admins' in after, 'other_memberships_preserved': True,
'signed_role_claim_verified': False}))
try:
main()
except Exception:
print('{"status":"directory-operation-refused"}')
sys.exit(1)