Repository navigation
ogar-rbac: OgarRbac as the RBAC hot-plug authority + ogar-auth identity adapter - #324
Conversation
impl RbacAuthority for OgarRbac<S>: binds a consumer's RbacPlug to the source's grants. Plugged classids must be minted in ogar-vocab and agree with the contract mirror; plugged roles must be defined by the source. GrantSource gains defaulted defines_role and field_mask_of. Pairs with AdaWorldAPI/lance-graph#1404 (contract::rbac_plug). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
✨ Finishing Touches📝 Generate docstrings
Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Comment |
|
The red
Against the #1404 branch, Merge #1404 first. Once it is on Generated by Claude Code |
An ogar-auth AuthenticatedUser as the ActorSource of a plugged binding: roles are matched against the binding's declared roles (others dropped and reported), memberships are bound to the user's tenant, and authorize_identity decides through authorize_memberships. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
OgarRbacbecomes the authority for the RBAC hot-plug socket from AdaWorldAPI/lance-graph#1404 (contract::rbac_plug, merged). Anogar-authuser can now be authorized through a plugged binding. This is the authorization twin ofOgarAuthorityfor capabilities: a consumer declares oneRbacPlugconst and binds it here, with no copy of the policy of its own.Changes
The authority:
impl<S: GrantSource> RbacAuthority for OgarRbac<S>. The bind checks, in order:ogar-vocab(UnknownClassid);MirrorDrift);UnknownRole).The
RbacBindingit returns carries the grants and field masks of exactly the plugged roles on the plugged classids.GrantSourcegains two defaulted methods.defines_roledefaults to "has at least one grant".field_mask_ofdefaults toNone, meaning no column restriction. Existing sources are unchanged.The identity adapter:
IdentityActors::new(&AuthenticatedUser, &RbacBinding): anogar-authuser as theActorSourceof a binding.unplugged_roles(); it grants nothing.authorize_identity(binding, identity, class, op): the decision throughauthorize_membership, which is the existing kernel. The result is always scoped to the user's tenant and never unrestricted.Tests and disable runs
Results:
ogar-rbacpasses 15 tests, 7 of them new:clippy
-D warningsand fmt are clean. All of this ran against lance-graphmain, which now contains #1404.Disable runs: each of these failed the test aimed at it:
Next
The consumer plugs for MedCare-rs and a2ui-rs follow as their own PRs. They depend on this one being on OGAR
main.🤖 Generated with Claude Code
https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg