Compare commits
4
Commits
v1.0.0
..
30a2b9b2a6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
30a2b9b2a6 | ||
|
|
eb7a2a3d18 | ||
|
|
d11cefe3df | ||
|
|
1e6f3bc44f |
@@ -13,26 +13,26 @@ authorization system and the key-document schema; the crypto primitives live in
|
||||
## Install
|
||||
|
||||
```
|
||||
envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.0
|
||||
envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2
|
||||
```
|
||||
|
||||
Direct:
|
||||
|
||||
```bash
|
||||
pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.0"
|
||||
pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2"
|
||||
```
|
||||
|
||||
The base install uses a local JSON file for storage (stdlib only). For shared
|
||||
dev→server storage, install the mongo extra:
|
||||
|
||||
```bash
|
||||
pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.0"
|
||||
pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2"
|
||||
```
|
||||
|
||||
Installing pulls `envelope_crypto` (and `mongo` with the extra). After install,
|
||||
the `authorizer` command is on your PATH; `python -m envelope_authorizer` also works.
|
||||
|
||||
Drop the `@v1.0.0` suffix from the line above to install the latest unpinned.
|
||||
Drop the `@v1.0.2` suffix from the line above to install the latest unpinned.
|
||||
|
||||
## Trust model (read this)
|
||||
|
||||
|
||||
+3
-3
@@ -4,18 +4,18 @@ build-backend = "hatchling.build"
|
||||
|
||||
[project]
|
||||
name = "envelope_authorizer"
|
||||
version = "1.0.0"
|
||||
version = "1.1.0"
|
||||
description = "CLI key-authorization manager for envelope_crypto"
|
||||
requires-python = ">=3.10"
|
||||
dependencies = [
|
||||
"envelope_crypto @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_crypto.git",
|
||||
"envelope_crypto @ git+https://git.rethinkstudios.io/rethink-public/envelope_crypto.git@v1.0.0",
|
||||
"cryptography>=42.0",
|
||||
"tomli>=2.0; python_version<'3.11'",
|
||||
]
|
||||
|
||||
[project.optional-dependencies]
|
||||
mongo = [
|
||||
"mongo @ git+ssh://git@git.rethinkstudios.io/rethink-public/mongo.git@v0.1.0",
|
||||
"mongo @ git+https://git.rethinkstudios.io/rethink-public/mongo.git@v1.0.0",
|
||||
]
|
||||
|
||||
[project.scripts]
|
||||
|
||||
@@ -5,16 +5,31 @@ CAN_AUTHORIZE (`?` if unreadable here). prints only fingerprint/metadata - never
|
||||
the wrapped key or DEK.
|
||||
"""
|
||||
|
||||
import logging
|
||||
from datetime import datetime, timezone
|
||||
|
||||
from cryptography.exceptions import InvalidTag
|
||||
|
||||
from . import boot_local, doc_meta, read_flag
|
||||
|
||||
log = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def _can_authorize(crypto, doc) -> str:
|
||||
"""decrypted authority of a doc as Yes/No, or `?` if unreadable here"""
|
||||
"""decrypted authority of a doc as Yes/No, or `?` if unreadable here
|
||||
|
||||
a malformed/foreign flag degrades to `?` for display continuity. a GCM auth-tag
|
||||
failure is logged first (WARNING): it is either a foreign key this host can't
|
||||
decrypt or a tampered authz record, and this layer can't tell them apart, so the
|
||||
security signal must stay visible rather than render identically to a `?`.
|
||||
"""
|
||||
try:
|
||||
return "Yes" if read_flag(crypto, doc["meta"]["authorizer"]) else "No"
|
||||
except Exception:
|
||||
except (KeyError, TypeError, ValueError):
|
||||
return "?"
|
||||
except InvalidTag:
|
||||
friendly = doc_meta(doc).get("friendly", doc.get("_id", "?"))
|
||||
log.warning("auth-tag verification failed for flag %s - foreign key or tampered record", friendly)
|
||||
return "?"
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user