Implement authenticated alert receipt acknowledgments and audit delivery
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
parent
67283b66c2
commit
e7282e493d
25 changed files with 1881 additions and 0 deletions
42
tests_runtime/test_policy_native.py
Normal file
42
tests_runtime/test_policy_native.py
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
from dataclasses import replace
|
||||
import json
|
||||
import os
|
||||
from pathlib import Path
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import time
|
||||
import unittest
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[1]
|
||||
sys.path.insert(0, str(ROOT / 'scripts'))
|
||||
from alert_ack import Actor
|
||||
from alert_policy import Policy
|
||||
|
||||
|
||||
@unittest.skipUnless(os.environ.get('RTEL_FLEX_AUTH_BINARY'), 'set RTEL_FLEX_AUTH_BINARY')
|
||||
class NativePolicyTests(unittest.TestCase):
|
||||
def test_native_wire_digest_and_revoked_or_wrong_identity_denials(self):
|
||||
with tempfile.TemporaryDirectory() as directory:
|
||||
request_file = Path(directory) / 'request.json'
|
||||
class Native:
|
||||
def request(self, method, url, body=None, headers=None):
|
||||
request_file.write_bytes(body)
|
||||
result = subprocess.run([os.environ['RTEL_FLEX_AUTH_BINARY'], 'check', '--policy',
|
||||
str(ROOT / 'integration/telemetry-policy.md'), '--registry', str(ROOT / 'integration/registry.json'),
|
||||
'--request', str(request_file)], capture_output=True, check=True)
|
||||
return 200, json.loads(result.stdout)
|
||||
actor = Actor('https://kc.coulomb.social', 'uid=tegwick,ou=people,dc=netkingdom,dc=local',
|
||||
'tenant:platform', ('railiance-admin',), time.time() + 600, 'c' * 32,
|
||||
assurance=dict(level='aal2', mfa=True, source='key-cape', methods=['pwd', 'otp'], at=int(time.time())),
|
||||
groups=('railiance-admins',), tenant_source='directory')
|
||||
# Native digest is pinned by the owner packet, not inferred from a response.
|
||||
policy = Policy('https://policy.example', lambda: 'fixture-only',
|
||||
'railiance-telemetry.alert-acknowledgment', 'v1',
|
||||
'sha256:02938202cf75140d6ab638b8d0fbce6ebb22832354efc89cab040b13e8943f09', transport=Native())
|
||||
resource = 'alert:11111111-1111-1111-1111-111111111111'
|
||||
self.assertEqual(policy(actor, 'acknowledge', resource)['effect'], 'allow')
|
||||
for changed in (replace(actor, roles=()), replace(actor, groups=()), replace(actor, subject='other'),
|
||||
replace(actor, tenant='tenant:other'), replace(actor, issuer='https://other.example'),
|
||||
replace(actor, assurance=dict(actor.assurance, at=1))):
|
||||
self.assertEqual(policy(changed, 'acknowledge', resource)['effect'], 'deny')
|
||||
Loading…
Add table
Add a link
Reference in a new issue