Implement authenticated alert receipt acknowledgments and audit delivery
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
parent
67283b66c2
commit
e7282e493d
25 changed files with 1881 additions and 0 deletions
42
integration/railiance-admin-directory.py
Normal file
42
integration/railiance-admin-directory.py
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
"""Run inside the existing identity-provisioner pod; never print credentials.
|
||||
|
||||
Default is read-only. --apply adds only the approved user's named group.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
from provisioner import LLDAPProvisioner
|
||||
|
||||
|
||||
def main():
|
||||
apply = sys.argv[1:] == ['--apply']
|
||||
if sys.argv[1:] not in ([], ['--apply']):
|
||||
raise ValueError()
|
||||
if os.environ['LLDAP_URL'] != 'http://lldap.sso.svc.cluster.local:17170':
|
||||
raise ValueError()
|
||||
client = LLDAPProvisioner(base_url=os.environ['LLDAP_URL'], admin_password=os.environ['LLDAP_ADMIN_PASSWORD'])
|
||||
token = client._login()
|
||||
user = client._user(token, 'tegwick')
|
||||
if not user or user['id'] != 'tegwick' or user['email'].lower() != 'bernd.worsch@gmail.com':
|
||||
raise ValueError()
|
||||
before = {g['displayName'] for g in user['groups']}
|
||||
if apply and 'railiance-admins' not in before:
|
||||
groups = client._gql(token, 'query { groups { id displayName } }', {})['groups']
|
||||
group = client._ensure_group(token, groups, 'railiance-admins')
|
||||
client._add_group(token, 'tegwick', group)
|
||||
after = {g['displayName'] for g in client._user(token, 'tegwick')['groups']}
|
||||
if not before <= after or after - before - {'railiance-admins'}:
|
||||
raise ValueError()
|
||||
if apply and 'railiance-admins' not in after:
|
||||
raise ValueError()
|
||||
print(json.dumps({'mode': 'apply' if apply else 'inspect', 'directory_user': 'tegwick',
|
||||
'email_matches_requested_recipient': True, 'group': 'railiance-admins',
|
||||
'member': 'railiance-admins' in after, 'other_memberships_preserved': True,
|
||||
'signed_role_claim_verified': False}))
|
||||
|
||||
|
||||
try:
|
||||
main()
|
||||
except Exception:
|
||||
print('{"status":"directory-operation-refused"}')
|
||||
sys.exit(1)
|
||||
Loading…
Add table
Add a link
Reference in a new issue