Authenticate and validate private lifecycle commands #22
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Ting/Vedanta#22
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Authenticate OpenBao as the sole lifecycle caller and validate the complete signed command before any Kanidm mutation.
Delivery class
agent-unit— implementsrc/private_api.rswith request fixtures derived from the Session OpenSpec.Design
The transport peer must be OpenBao's dedicated service identity. Validate signature, request window, fresh operation ID, action, grant ID/version/digest, principal UUID/name, state, auth and credential generations, requested expiry, and predecessor ownership in order. Caller-supplied grant content is never authority.
Tasks
Specification Delta
Requirement: invalid private commands cannot reach the mutation adapter
Scenario: one command field is substituted
OpenSpec
OpenSpec 20
Structural parent
Vedanta#20