Skip to content

ogar-rbac: OgarRbac as the RBAC hot-plug authority + ogar-auth identity adapter - #324

Merged
AdaWorldAPI merged 2 commits into
mainfrom
ccr-0455e606-wmtsor
Oct 8, 2026
Merged

AdaWorldAPI merged 2 commits into
mainfrom
ccr-0455e606-wmtsor

Conversation

@AdaWorldAPI

@AdaWorldAPI AdaWorldAPI commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

OgarRbac becomes the authority for the RBAC hot-plug socket from AdaWorldAPI/lance-graph#1404 (contract::rbac_plug, merged). An ogar-auth user can now be authorized through a plugged binding. This is the authorization twin of OgarAuthority for capabilities: a consumer declares one RbacPlug const and binds it here, with no copy of the policy of its own.

Changes

The authority: impl<S: GrantSource> RbacAuthority for OgarRbac<S>. The bind checks, in order:

  • every plugged classid is minted in ogar-vocab (UnknownClassid);
  • the resolved names agree with the contract's wire mirror (MirrorDrift);
  • every plugged role is one the source defines (UnknownRole).

The RbacBinding it returns carries the grants and field masks of exactly the plugged roles on the plugged classids.

GrantSource gains two defaulted methods. defines_role defaults to "has at least one grant". field_mask_of defaults to None, meaning no column restriction. Existing sources are unchanged.

The identity adapter:

  • IdentityActors::new(&AuthenticatedUser, &RbacBinding): an ogar-auth user as the ActorSource of a binding.
    • The user's roles are matched against the binding's declared roles. Any other role is dropped and reported by unplugged_roles(); it grants nothing.
    • Every membership is bound to the user's tenant.
    • It answers only for its own subject.
  • authorize_identity(binding, identity, class, op): the decision through authorize_membership, which is the existing kernel. The result is always scoped to the user's tenant and never unrestricted.

Tests and disable runs

  • Results: ogar-rbac passes 15 tests, 7 of them new:

    • bind and permit;
    • refusal of unminted classids and undefined roles;
    • field masks carried through;
    • tenant-scoped decisions;
    • unplugged roles dropped and reported;
    • the subject check;
    • a user with no plugged role is denied.

    clippy -D warnings and fmt are clean. All of this ran against lance-graph main, which now contains #1404.

  • Disable runs: each of these failed the test aimed at it:

    • skipping the minted check;
    • skipping the role check;
    • dropping field masks;
    • keeping unplugged roles;
    • answering for any actor;
    • dropping the tenant scope.

Next

The consumer plugs for MedCare-rs and a2ui-rs follow as their own PRs. They depend on this one being on OGAR main.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg

impl RbacAuthority for OgarRbac<S>: binds a consumer's RbacPlug to the
source's grants. Plugged classids must be minted in ogar-vocab and agree
with the contract mirror; plugged roles must be defined by the source.
GrantSource gains defaulted defines_role and field_mask_of.

Pairs with AdaWorldAPI/lance-graph#1404 (contract::rbac_plug).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 0be9c290-97d4-44c6-be67-c0f7a8bd055a
📥 Commits

Reviewing files that changed from the base of the PR and between fca2380 and e49875c.

📒 Files selected for processing (1)
  • crates/ogar-rbac/src/lib.rs
 _________________________________________________
< SNAFU: Situation Normal, All Faults Understood. >
 -------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Owner Author

The red cargo clippy -D warnings here is the expected pairing gap with AdaWorldAPI/lance-graph#1404, not a defect in this PR. The same goes for cargo check + test if it fails.

ogar-rbac builds against lance-graph's main branch, which doesn't have lance_graph_contract::rbac_plug yet. The single error is an E0432 unresolved import of that module.

Against the #1404 branch, ogar-rbac builds, clippy is clean and all 11 tests pass. I checked that locally through a --config patch; nothing is committed for it.

Merge #1404 first. Once it is on main, a re-run here should go green with no change to this PR.


Generated by Claude Code

An ogar-auth AuthenticatedUser as the ActorSource of a plugged binding:
roles are matched against the binding's declared roles (others dropped
and reported), memberships are bound to the user's tenant, and
authorize_identity decides through authorize_memberships.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@AdaWorldAPI AdaWorldAPI changed the title ogar-rbac: OgarRbac as the RBAC hot-plug authority ogar-rbac: OgarRbac as the RBAC hot-plug authority + ogar-auth identity adapter Oct 8, 2026
@AdaWorldAPI
AdaWorldAPI marked this pull request as ready for review October 8, 2026 17:36
@AdaWorldAPI
AdaWorldAPI merged commit d17963c into main Oct 8, 2026
4 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T17:36:55.086590Z e49875c Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants