Repository navigation
docs: authorization change evidence design - #96
Open
lakhansamani wants to merge 6 commits into
Open
lakhansamani wants to merge 6 commits into
lakhansamani wants to merge 6 commits into
Conversation
Scoping to internal/service/admin_fga.go covered 4 of 8 FGA tuple mutation sites. SCIM group membership is stored as FGA tuples and writes them directly; purgeFgaTuplesForUser deletes them on user delete. Neither is audited, and scim.Dependencies has no AuditProvider at all. Rescope by claim rather than by file, add the static guard test that prevents a ninth site appearing unaudited, and bring roles/membership in. Infrastructure-config surfaces stay deferred.
Verified empirically: the three new storage subtests fail on couchbase before the fix. Earlier table read its SELECT column list as filter support.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
✅ Deploy Preview for authorizerdev-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Principal is written only by the gRPC interceptor; GraphQL and REST build none, which is why requireSuperAdmin falls back to IsSuperAdmin. Reading Principal.AuthMode would record an empty auth_mode for the dashboard path. Found by the Phase 1 whole-branch review.
lakhansamani
added a commit
to authorizerdev/authorizer
that referenced
this pull request
Oct 6, 2026
Phase 1 plumbing for authorization-change evidence. Adds no new audit records and changes no observable behaviour; consumers arrive in Phase 2. - audit.Provider.LogEventSync(ctx, Event) error for operations where the audit record is part of the contract rather than a side effect. LogEvent keeps its signature and fire-and-forget semantics, so logins and token issuance never gain a synchronous dependency on the audit table. Both share one buildAuditLog so the paths cannot drift on record shape. - token.Provider.AdminAuthMode records HOW a super-admin authenticated (admin_session vs shared_secret). Super-admin is one shared AdminSecret with no per-admin identity, so an audit record can never name a person; the credential mode is the honest substitute. IsSuperAdmin is now a predicate over AdminAuthMode, so the admit decision and the recorded mode cannot disagree. The session handle is never recorded. - scim.Dependencies.AuditProvider plus a nil-safe wrapper. The SCIM package had no audit provider at all, which blocks half of Phase 2's call sites. Reviewed for admit-equivalence branch by branch: neither widened nor narrowed. Interface widening is safe by construction - both interfaces are under internal/, which the compiler enforces as unimportable. Design: authorizerdev/docs#96
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Design for recording before/after state on authorization changes, so an auditor can answer what changed, from what, to what, and on whose authority — not just that something changed.
Why
A verification pass against server
main(891f58fd) found:count=Nonlyresource_idunsetScope
Scoped by the claim it makes true, not by a file. An earlier revision said "FGA only", meaning
internal/service/admin_fga.go— that turned out to cover 4 of 8 FGA tuple mutation sites. SCIM group membership is FGA tuples and writes them directly;purgeFgaTuplesForUserdeletes them on user delete. Neither is audited, andscim.Dependencieshas noAuditProviderat all.Shipping that narrower version would have replaced a known gap with false confidence, which is worse than the gap.
Locked decisions
auth_mode), no new auth modelStatus
Phase 0 is implemented and verified in authorizerdev/authorizer#802. Phases 1–3 await review of this spec.