Enforce companion-only credential delivery and refresh activation handoff
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
303cbf652b
commit
5c6f2b319d
8 changed files with 150 additions and 24 deletions
|
|
@ -109,7 +109,9 @@ The companion lane must consent in its own catalog entry with
|
|||
the same stage, declare the field and `exec-env`, and bind no exec owner of its
|
||||
own. Env names must be unique, must not match the fixed environment or the
|
||||
primary field's name, and must not use loader or engine credential prefixes.
|
||||
Pending owners cannot list companions.
|
||||
Pending owners cannot list companions. A lane declaring `companion_of` cannot
|
||||
be selected as the primary `exec` lane: it is delivered only through a listed
|
||||
primary with a configured owner, even if standalone lane approval exists.
|
||||
|
||||
Companions are part of the owner binding, so changing a companion's lane, field
|
||||
or env name changes the owner digest and invalidates earlier decisions.
|
||||
|
|
@ -120,6 +122,9 @@ consume for action `exec`. No lane's decision covers another lane. After every
|
|||
gate passes, each value is read through its own lane's AppRole session. A
|
||||
failure on any lane starts no child. The binding is checked again after the
|
||||
reads, and all values are injected together and redacted from the output.
|
||||
The delivery helper independently checks that the supplied companions exactly
|
||||
match the pinned lane/field/environment list and still satisfy consent and stage
|
||||
constraints before reading the primary or any companion.
|
||||
|
||||
Proof: `tests/test_exec_owner_companions.py`, plus
|
||||
`tests/test_integration_companions.py` on a throwaway OpenBao (two lanes, one
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue