feat: adopt the owner-documented PDP access path, and prove it live
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Adoption asked for by flex-auth (FLEX-WP-0021-T05) and glas-harness
(GLAS-WP-0015), plus the first real decision this engine has obtained from
the deployed pin -- which found a defect the fixtures could not.

ACCESS PATH. require_supported_pdp_address refuses in-cluster Service names
and any non-loopback host. This is no longer a unilateral call: the owner
path is documented as loopback kubectl port-forward over the authenticated
Kubernetes API, which is what authenticates the responder transitively
(FLEX-DEC-2026-010). A Service name from a workstation does not fail, it
resolves through the DNS search suffix to an unrelated public host, and
since decision records carry no signature, a responder knowing the
published package and version can return an allow that passes every check
we make. Fail-closed protects against a PDP that is absent, not one that
lies. The guard runs before the token is read, so a misdirected request
cannot leak it; a test pins that ordering.

LIVE PROOF. Minted a 10-minute TokenRequest token (audience flex-auth, SA
secrets-engine/secrets-engine, mode 0600 outside the worktree, shredded
after), forwarded to the named pod, and sent a real CheckRequest for
glas-claude-agent-dev-anthropic. Result: allow, catalog_lane_policy_matched,
served by v2 (sha256:bd11c5fe...) -- so the redeploy flex-auth flagged as
outstanding has landed and the pin no longer serves the tenant-blind v1.
Our tenant fix is confirmed against the real service: binding.tenant is
tenant:platform.

THE DEFECT IT FOUND. The evaluator enriches from its registry before
hashing -- subject gains attributes and tenant, resource gains tenant --
so binding.request_digest is over material we never sent and cannot
reproduce. validate_decision_envelope rejects every real allow.

Every replay test passes because _request_from() rebuilds the request out
of the binding, i.e. the enriched form: a self-consistent fake agreeing
with itself, which hid this through three rounds of digest work. Third
time a real artifact has beaten a fake in this integration.

NOT FIXED, DELIBERATELY. Rejecting a valid allow is wrong in the safe
direction. Which fields may be enriched is flex-auth's contract to publish;
inferring it means accepting a binding that differs from our proposal in a
way we decided was benign -- the fail-open shape GH-DEC-2026-008 rejected
for vocabularies and FLEX-DEC-2026-007 for digests. Raised with them.

Tenant question closed by operator decision 5ed3fb35: tenant:platform
exactly, and service_auth.TENANT stays tenant:coulomb because the two
identity layers are to remain distinct. Declining to author that mapping
was right -- the answer was neither reading offered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E4tNMAYcSQmZWUE4wqP4ij

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715726@bnt-lap001
Assistant-Session: 80a42b32-cba6-4b23-8be0-68819b1a6092
This commit is contained in:
tegwick 2026-09-07 00:22:12 +02:00
parent 7cab4bfcb3
commit 03c0569820
7 changed files with 488 additions and 3 deletions

View file

@ -27,6 +27,10 @@ from secrets_engine.authorization import (
request_digest,
validate_decision_envelope,
)
from secrets_engine.decision_check import (
check_decision,
require_supported_pdp_address,
)
from secrets_engine.errors import DecisionError
FIXTURES = Path(__file__).parent / "fixtures" / "flex-auth-replay"
@ -429,3 +433,57 @@ def test_the_superseded_v1_package_is_not_accepted():
accepted_policy_packages={"secrets-engine.catalog-lane.lifecycle"},
accepted_policy_versions={"v1"},
)
# --- supported PDP address (FLEX-DEC-2026-010) -------------------------------
@pytest.mark.parametrize(
"url,fragment",
[
# The exact address flex-auth originally handed over. It does not fail
# to resolve from a workstation, it resolves to an unrelated public host.
("http://flex-auth-secrets-engine.flex-auth.svc.cluster.local:8080",
"in-cluster Service name"),
("http://flex-auth-secrets-engine.flex-auth.svc.cluster.local.:8080",
"in-cluster Service name"),
("http://flex-auth-secrets-engine.flex-auth.svc:8080",
"in-cluster Service name"),
# A public address is refused even though it would "work": nothing
# authenticates the responder, so reaching something is not reaching
# the pin.
("http://80.158.43.29:8080", "is not loopback"),
("https://flex-auth.example.com", "is not loopback"),
],
)
def test_unsupported_pdp_addresses_are_refused(url, fragment):
with pytest.raises(DecisionError, match=fragment):
require_supported_pdp_address(url)
@pytest.mark.parametrize(
"url",
[
"http://127.0.0.1:18080",
"http://localhost:18080",
"http://[::1]:18080",
],
)
def test_loopback_forward_addresses_are_accepted(url):
require_supported_pdp_address(url)
def test_the_guard_runs_before_the_token_is_read(tmp_path):
"""A bad address must not cause the bearer token to be read, let alone sent.
The token is the thing a misdirected request would leak, so the address
check has to come first rather than alongside.
"""
missing = tmp_path / "never-read.token"
with pytest.raises(DecisionError, match="in-cluster Service name"):
check_decision(
base_url="http://flex-auth-secrets-engine.flex-auth.svc.cluster.local:8080",
token_file=missing,
request={},
)
assert not missing.exists()