Add principal-scoped secret access contract - #62
shivanshu-risa wants to merge 3 commits into
Conversation
Review: principal-scoped secret access contractNice, carefully-argued contract — the "principal is never an argument" rule, the not-found/not-authorized conflation in The substantive comments below are mostly "now or never": everything here is frozen the moment 1.0.94 publishes. 1.
|
Review: principal-scoped secret access contract (1/2)Contract-only change and the security shape is the right one. What's good: the principal is not a parameter on any method, so untrusted code can't impersonate one — and the KDoc says why, which is the part that survives future edits. Findings ordered by how expensive they are to fix after release. 1.
|
Review: principal-scoped secret access contract (2/2)5. Open-string enums with no constants
object SecretAccessLevel { const val OWNER = "owner"; const val USE = "use" }
object SecretPrincipalType { const val PLUGIN = "plugin"; const val MCP_TOOL = "mcp_tool" }
6. No tests, against a consistent repo conventionComparable contract additions here all ship one: 7. Missing
|
Review: principal-scoped secret access contractRead the full diff ( Findings below, most consequential first. I could not run 1. The manual version bump to 1.0.94 is probably off by one, and downstream PRs are pinning to it
That failure mode is not soft. A consumer declaring Suggest dropping commit 3 and reading the floor off the actual published tag before the dependent PRs hard-code it. 2.
|
|
Closing this draft to keep the current rollout limited to the AI Gateway and Secret Manager plugins. Principal-scoped secret access will be redesigned and handled in a separate security-hardening round. |
Summary
Verification
Merge order
This is the foundation PR. Merge it first so release v1.0.94 is available to the host, AI Gateway, and Secret Manager PRs.