feat: enforce the administrative-only runtime API trust boundary - #1394
Merged
Merged
Conversation
Collaborator
Author
|
Ground Control delivery — this pull request delivers issue #1359; Phase E runs on merge. |
9 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Enforces the accepted host-mediated, administrative-only P2 exposure model (#1356). Every served route declares exactly one method-bound transport authority. Construction fails on any undeclared, duplicate, double-authority, public-mutation, or method-mismatched route. The served app then refuses startup and every request if its routes, middleware, exception handlers, or dependency overrides change after construction. Every response carries
Cache-Control: no-store. Transport refusals return stableunauthorized/forbiddenbodies, with the specific reason audit-only. Malformed bodies are admitted before they get a 422, and a forbidden resolution looks the same as an unknown operation. Configured principals, trust flags, limits, and credentials are validated at startup. HTTP-boundary tests pin the route matrix and every rejection path, and a new public guide documents deployment and host duties.Requirement UIDs
API-404Related Issues
Refs #1359
ADR Impact
Changes
ControlPlaneRouteAuthoritywith one role table and one HTTP-method table incontrol_plane_security.py. Public probe and administrative read are GET-only; mutation and operator resolution are POST/PUT/PATCH/DELETE only._ControlPlaneApiAuth.admit()is the single admission seam.create_control_plane_app()validates the route inventory, exposes it asapp.state.control_plane_route_authority, and seals the app composition._ControlPlaneFastAPI.build_middleware_stackandAppCompositionSealMiddlewarerefuse startup and every request when routes, middleware, exception handlers, or dependency overrides differ from the sealed set.NoStoreResponseMiddlewarewraps every response. The redacted 500 and sealed-app refusals setno-storedirectly.unauthorized, and transport 403 is alwaysforbidden. Admission runs before a request-validation 422. A resolution the operator may not perform returns the same 404 as an unknown operation.bool, and limits must be positiveint.mcp[crypto]) upgraded 2.13.0 → 2.15.1 to clear ten published advisories flagged by the OSV supply-chain gate; the hash-complete smoke closures were regenerated from the lock.docs/public/guides/control-plane.md. The Define control-plane and participant-access trust boundaries #1356 preflight names the renamed dependencies.Test Plan
Targeted: the 41 test files that build the HTTP adapter or security config (1,060 passed), the MCP-consuming test files after the PyJWT upgrade (329 passed), the three evidence modules including their integration lane (223 passed), both evidence checker CLIs, the OSV scan, the tooling artifact policy, fast-feedback (hygiene, policy, lint, changed pytest modules), repo policy, and the offline docs build (Vale, Sphinx, public inventory).
Ground Control Checks
Traceability
Checklist
Documentation
Updated: see diff.