1 Commits
Author SHA1 Message Date
dsql 1bb4979b8c release: 1.0.0
first stable release. pre-1.0.0 verification complete: all surviving MED regressions and
gaps resolved and independently re-fired, tree audited clean across the suite.

Signed-off-by: disqualifier <dev@disqualifier.me>
2026-07-06 21:21:00 -04:00
3 changed files with 9 additions and 24 deletions
+4 -4
View File
@@ -13,26 +13,26 @@ authorization system and the key-document schema; the crypto primitives live in
## Install ## Install
``` ```
envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2 envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.7
``` ```
Direct: Direct:
```bash ```bash
pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2" pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.7"
``` ```
The base install uses a local JSON file for storage (stdlib only). For shared The base install uses a local JSON file for storage (stdlib only). For shared
dev→server storage, install the mongo extra: dev→server storage, install the mongo extra:
```bash ```bash
pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2" pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v0.1.7"
``` ```
Installing pulls `envelope_crypto` (and `mongo` with the extra). After install, Installing pulls `envelope_crypto` (and `mongo` with the extra). After install,
the `authorizer` command is on your PATH; `python -m envelope_authorizer` also works. the `authorizer` command is on your PATH; `python -m envelope_authorizer` also works.
Drop the `@v1.0.2` suffix from the line above to install the latest unpinned. Drop the `@v0.1.7` suffix from the line above to install the latest unpinned.
## Trust model (read this) ## Trust model (read this)
+3 -3
View File
@@ -4,18 +4,18 @@ build-backend = "hatchling.build"
[project] [project]
name = "envelope_authorizer" name = "envelope_authorizer"
version = "1.1.0" version = "1.0.0"
description = "CLI key-authorization manager for envelope_crypto" description = "CLI key-authorization manager for envelope_crypto"
requires-python = ">=3.10" requires-python = ">=3.10"
dependencies = [ dependencies = [
"envelope_crypto @ git+https://git.rethinkstudios.io/rethink-public/envelope_crypto.git@v1.0.0", "envelope_crypto @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_crypto.git",
"cryptography>=42.0", "cryptography>=42.0",
"tomli>=2.0; python_version<'3.11'", "tomli>=2.0; python_version<'3.11'",
] ]
[project.optional-dependencies] [project.optional-dependencies]
mongo = [ mongo = [
"mongo @ git+https://git.rethinkstudios.io/rethink-public/mongo.git@v1.0.0", "mongo @ git+ssh://git@git.rethinkstudios.io/rethink-public/mongo.git@v0.1.0",
] ]
[project.scripts] [project.scripts]
+2 -17
View File
@@ -5,31 +5,16 @@ CAN_AUTHORIZE (`?` if unreadable here). prints only fingerprint/metadata - never
the wrapped key or DEK. the wrapped key or DEK.
""" """
import logging
from datetime import datetime, timezone from datetime import datetime, timezone
from cryptography.exceptions import InvalidTag
from . import boot_local, doc_meta, read_flag from . import boot_local, doc_meta, read_flag
log = logging.getLogger(__name__)
def _can_authorize(crypto, doc) -> str: def _can_authorize(crypto, doc) -> str:
"""decrypted authority of a doc as Yes/No, or `?` if unreadable here """decrypted authority of a doc as Yes/No, or `?` if unreadable here"""
a malformed/foreign flag degrades to `?` for display continuity. a GCM auth-tag
failure is logged first (WARNING): it is either a foreign key this host can't
decrypt or a tampered authz record, and this layer can't tell them apart, so the
security signal must stay visible rather than render identically to a `?`.
"""
try: try:
return "Yes" if read_flag(crypto, doc["meta"]["authorizer"]) else "No" return "Yes" if read_flag(crypto, doc["meta"]["authorizer"]) else "No"
except (KeyError, TypeError, ValueError): except Exception:
return "?"
except InvalidTag:
friendly = doc_meta(doc).get("friendly", doc.get("_id", "?"))
log.warning("auth-tag verification failed for flag %s - foreign key or tampered record", friendly)
return "?" return "?"