Adapt USER-WP-0021 and USER-WP-0023 to published policy-nexus contracts
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m1s

IAM Profile v0.3 and Tenancy Posture v0.1 are now live on
policy.coulomb.social. Close the portal expansion workplan against those
documents, keep the flex-auth live A2 probe waiting, and forward optional
tenant_roles to flex-auth without authorizing from them locally.
This commit is contained in:
tegwick 2026-08-19 09:51:08 +02:00
parent 166788228d
commit f762161d84
13 changed files with 109 additions and 10 deletions

View file

@ -37,6 +37,7 @@ class PlatformAdapterTests(unittest.TestCase):
request = json.loads(call.call_args.args[0].data)
self.assertEqual(request["resource"]["system"], "user-engine")
self.assertEqual(request["context"]["self"], True)
self.assertEqual(request["subject"]["attributes"]["tenant_roles"], ["CUS"])
def test_flex_auth_fails_closed_when_unavailable(self):
with patch("user_engine.adapters.flex_auth.urlopen", side_effect=URLError("down")):
@ -155,7 +156,7 @@ def _request():
actor = Actor(
issuer="https://issuer", subject="subject-1", tenant="tenant-a",
principal_type=PrincipalType.HUMAN, audience=("user-engine",),
roles=("tenant-admin",),
roles=("tenant-admin",), tenant_roles=("CUS",),
)
return AuthorizationRequest(
actor=actor, resource_type="user-engine:user", resource_id="user-1",