Implement Control Plane backend: rights enforcement + audit log (WP-0009-T03)
migrations/0006_control_plane.sql: control_plane_audit_log (append-only, no UPDATE/DELETE for trf_app) and control_plane_proposed_entries (the Contributor tier's "propose, don't append" workflow from concept §2) - review decisions go through a review_proposed_entry() SECURITY DEFINER function, same governance-action pattern as set_extension_status/revoke_credential, not a direct UPDATE. src/target_revenue/control_plane.py is the enforcement layer concept §2 called for: register_phase/append_development_credit require Operator+; propose_ledger_entry requires Contributor+ and stores a pending proposal without touching the real Ledger; approve_proposed_entry (Operator+) appends it under the *reviewer's own* credential/attribution (not the original proposer's - the reviewer is who's authorizing it into the real Ledger, while the proposer stays on record in the proposal row and audit log); reject_proposed_entry (Operator+) discards it. issue_/ revoke_user_credential (Admin+) wrap registry.py's T02 functions with the same rights check and audit logging. Every action funnels through record_audit_event, independent of the Trust Service's own signed records. tests/test_control_plane.py (12 tests): rights enforcement at each tier boundary, the full propose -> approve -> appended-under-reviewer flow, propose -> reject -> nothing appended, double-review rejection, audit log content/attribution, DB-level UPDATE rejection on both new tables. Full suite: 84 offline (unchanged), 53 with Docker (up from 41); no stray containers left running.
This commit is contained in:
parent
d29447fcff
commit
885da0a1cb
6 changed files with 756 additions and 2 deletions
|
|
@ -122,6 +122,15 @@ Licensor token (§2). This log is the answer to "who actually clicked the
|
|||
button," which matters operationally even though it's not part of the
|
||||
Trust Service's own cryptographic guarantees.
|
||||
|
||||
**Implemented 2026-07-30** (`workplans/TREV-WP-0009-target-revenue-control-plane.md`
|
||||
T03, `src/target_revenue/control_plane.py`): `control_plane_audit_log`
|
||||
(append-only) records every action; the Contributor tier's "propose, not
|
||||
append" workflow (§2's rights table) is backed by
|
||||
`control_plane_proposed_entries`, with Operator/Admin review going
|
||||
through a governance-gated database function rather than a plain
|
||||
UPDATE — the same pattern already established for extension
|
||||
canonicalization and credential revocation.
|
||||
|
||||
## 6. Explicit non-goals
|
||||
|
||||
- Replacing `scripts/trf_onboard.py` — the CLI remains valid for
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue