flex-auth regenerated decision_destroy_dual_control so context.approval
carries a complete approval-claim including the now-required
binding.pdp_digest. Because context is part of the digest material, that
changed both the request digest and the context input-claim digest; the
vendored copy and its pins are updated. Our digest join reproduces the new
envelope digest exactly, so the digest_material fix holds.
Two properties are now asserted rather than described:
- The embedded claim's binding speaks approval-engine's vocabulary
(secrets.kv.destroy, target {id, stage}) while the decision speaks ours
(destroy, lane:...). That is the unpublished mapping, now a test.
- The claim's pdp_digest cannot equal the request digest of the request that
carries it: embedding the claim in a hashed context changes that digest.
It matches neither the full request nor the request with the claim
removed. Raised with both teams; recorded here so a future change to it is
visible rather than silent.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M65ovP3eiiPHubibvWs9mD
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 393550@bnt-lap001
Assistant-Session: 4bb359f9-1f12-4410-9e76-079cf23c82e4
142 lines
4.6 KiB
JSON
142 lines
4.6 KiB
JSON
{
|
|
"id": "decision:395efe37c5066e8a",
|
|
"contract_version": "flex-auth.decision-record.v1",
|
|
"request_id": "check:secrets-engine-destroy",
|
|
"effect": "allow",
|
|
"reason": "catalog_lane_policy_matched",
|
|
"matched_policy_version": "v1",
|
|
"matched_rule": "catalog_lane_policy_matched",
|
|
"resource": {
|
|
"id": "lane:glas-primary",
|
|
"type": "secret-catalog-lane",
|
|
"system": "secrets-engine",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"auth_targets": [],
|
|
"fields": [],
|
|
"policy_targets": [],
|
|
"stage": "prod"
|
|
}
|
|
},
|
|
"subject": {
|
|
"id": "secrets-engine",
|
|
"type": "service",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"description": "secrets-engine's own service identity, the single calling identity for the twelve gated catalog-lane actions it sends to POST /v1/check. Because it is the only subject, the package has no action_not_granted branch (FLEX-WP-0021-T02); registering a second identity is the revisit trigger.",
|
|
"display_name": "secrets-engine service principal",
|
|
"groups": [
|
|
"group:secrets-engine-lane-operators"
|
|
],
|
|
"organization_relation": "ServiceProvider",
|
|
"roles": [
|
|
"Operator"
|
|
]
|
|
}
|
|
},
|
|
"binding": {
|
|
"tenant": "tenant:platform",
|
|
"subject": {
|
|
"id": "secrets-engine",
|
|
"type": "service",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"description": "secrets-engine's own service identity, the single calling identity for the twelve gated catalog-lane actions it sends to POST /v1/check. Because it is the only subject, the package has no action_not_granted branch (FLEX-WP-0021-T02); registering a second identity is the revisit trigger.",
|
|
"display_name": "secrets-engine service principal",
|
|
"groups": [
|
|
"group:secrets-engine-lane-operators"
|
|
],
|
|
"organization_relation": "ServiceProvider",
|
|
"roles": [
|
|
"Operator"
|
|
]
|
|
}
|
|
},
|
|
"action": "destroy",
|
|
"resource": {
|
|
"id": "lane:glas-primary",
|
|
"type": "secret-catalog-lane",
|
|
"system": "secrets-engine",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"auth_targets": [],
|
|
"fields": [],
|
|
"policy_targets": [],
|
|
"stage": "prod"
|
|
}
|
|
},
|
|
"context": {
|
|
"approval": {
|
|
"approval_id": "3d1c0a8e-6b7f-4c21-9a0e-1f2b3c4d5e6f",
|
|
"binding": {
|
|
"action": "secrets.kv.destroy",
|
|
"actor": "agt-secrets-engine",
|
|
"digest": "sha256:3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f3f",
|
|
"pdp_digest": "sha256:570d112890586d3cbf00c0e81c85ae7806f40f00afa1a2c0a23fd5e077a27f56",
|
|
"principal": "bernd",
|
|
"purpose": "rotate-exposed-key",
|
|
"target": {
|
|
"id": "lane-openbao-root",
|
|
"stage": "prod"
|
|
}
|
|
},
|
|
"consumed": false,
|
|
"freshness": {
|
|
"not_after": "2026-09-06T12:00:30+00:00",
|
|
"observed_at": "2026-09-06T12:00:00+00:00",
|
|
"ttl_seconds": 30
|
|
},
|
|
"issuer": "approval-engine",
|
|
"kind": "approval-claim",
|
|
"reason_code": "ok",
|
|
"schema_version": "0.1",
|
|
"state": "valid",
|
|
"valid_now": true,
|
|
"validity": {
|
|
"expires_at": "2026-09-06T15:00:00+00:00",
|
|
"not_before": "2026-09-06T11:00:00+00:00"
|
|
}
|
|
}
|
|
},
|
|
"request_digest": "sha256:fc155dba88f8ab18b3032ed086ba2f455158c6981106e7829d520ab7b036bdf3"
|
|
},
|
|
"lifetime": {
|
|
"kind": "ttl",
|
|
"ttl": "15m",
|
|
"not_before": "2026-09-06T12:18:21Z",
|
|
"expires_at": "2026-09-06T12:33:21Z"
|
|
},
|
|
"diagnostics": {
|
|
"action": "destroy",
|
|
"matched_relationship": "",
|
|
"policy_package": "secrets-engine.catalog-lane.lifecycle",
|
|
"policy_status": "ready",
|
|
"registry_resource": false,
|
|
"registry_subject": true
|
|
},
|
|
"provenance": {
|
|
"evaluator": "flex-auth/local",
|
|
"mode": "standalone",
|
|
"policy_package": "secrets-engine.catalog-lane.lifecycle",
|
|
"policy_version": "v1",
|
|
"policy_package_digest": "sha256:fe0070b79f66442ae6c218697a49c470c6c8f670aa57a30c078a5284d097bd8c",
|
|
"registry_snapshot_digest": "sha256:f5a309bc0b36721fd6d9ad7f53eb21222162bc2eac62a0ab0802a9a1d51340bb",
|
|
"input_claim_digests": {
|
|
"context": "sha256:b0d2203cd2b43a9ba573c21c038154c131afba4255e313affd7ecf810e2cc221"
|
|
},
|
|
"decision_time": "2026-09-06T12:18:21Z"
|
|
},
|
|
"caring": {
|
|
"profile": "caring-0.4.0-rc2",
|
|
"conformance_findings": [
|
|
{
|
|
"code": "CARING-DESCRIPTOR-MISSING",
|
|
"severity": "warning",
|
|
"message": "no CARING descriptor matched the request",
|
|
"fields": [
|
|
"caring_context"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|