Compare commits
3
Commits
v1.0.1
...
30a2b9b2a6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
30a2b9b2a6 | ||
|
|
eb7a2a3d18 | ||
|
|
d11cefe3df |
@@ -13,26 +13,26 @@ authorization system and the key-document schema; the crypto primitives live in
|
|||||||
## Install
|
## Install
|
||||||
|
|
||||||
```
|
```
|
||||||
envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.1
|
envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2
|
||||||
```
|
```
|
||||||
|
|
||||||
Direct:
|
Direct:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.1"
|
pip install "envelope_authorizer @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2"
|
||||||
```
|
```
|
||||||
|
|
||||||
The base install uses a local JSON file for storage (stdlib only). For shared
|
The base install uses a local JSON file for storage (stdlib only). For shared
|
||||||
dev→server storage, install the mongo extra:
|
dev→server storage, install the mongo extra:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.1"
|
pip install "envelope_authorizer[mongo] @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_authorizer.git@v1.0.2"
|
||||||
```
|
```
|
||||||
|
|
||||||
Installing pulls `envelope_crypto` (and `mongo` with the extra). After install,
|
Installing pulls `envelope_crypto` (and `mongo` with the extra). After install,
|
||||||
the `authorizer` command is on your PATH; `python -m envelope_authorizer` also works.
|
the `authorizer` command is on your PATH; `python -m envelope_authorizer` also works.
|
||||||
|
|
||||||
Drop the `@v1.0.1` suffix from the line above to install the latest unpinned.
|
Drop the `@v1.0.2` suffix from the line above to install the latest unpinned.
|
||||||
|
|
||||||
## Trust model (read this)
|
## Trust model (read this)
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -4,18 +4,18 @@ build-backend = "hatchling.build"
|
|||||||
|
|
||||||
[project]
|
[project]
|
||||||
name = "envelope_authorizer"
|
name = "envelope_authorizer"
|
||||||
version = "1.0.1"
|
version = "1.1.0"
|
||||||
description = "CLI key-authorization manager for envelope_crypto"
|
description = "CLI key-authorization manager for envelope_crypto"
|
||||||
requires-python = ">=3.10"
|
requires-python = ">=3.10"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"envelope_crypto @ git+ssh://git@git.rethinkstudios.io/rethink-public/envelope_crypto.git@v1.0.0",
|
"envelope_crypto @ git+https://git.rethinkstudios.io/rethink-public/envelope_crypto.git@v1.0.0",
|
||||||
"cryptography>=42.0",
|
"cryptography>=42.0",
|
||||||
"tomli>=2.0; python_version<'3.11'",
|
"tomli>=2.0; python_version<'3.11'",
|
||||||
]
|
]
|
||||||
|
|
||||||
[project.optional-dependencies]
|
[project.optional-dependencies]
|
||||||
mongo = [
|
mongo = [
|
||||||
"mongo @ git+ssh://git@git.rethinkstudios.io/rethink-public/mongo.git@v1.0.0",
|
"mongo @ git+https://git.rethinkstudios.io/rethink-public/mongo.git@v1.0.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
[project.scripts]
|
[project.scripts]
|
||||||
|
|||||||
@@ -5,16 +5,31 @@ CAN_AUTHORIZE (`?` if unreadable here). prints only fingerprint/metadata - never
|
|||||||
the wrapped key or DEK.
|
the wrapped key or DEK.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
import logging
|
||||||
from datetime import datetime, timezone
|
from datetime import datetime, timezone
|
||||||
|
|
||||||
|
from cryptography.exceptions import InvalidTag
|
||||||
|
|
||||||
from . import boot_local, doc_meta, read_flag
|
from . import boot_local, doc_meta, read_flag
|
||||||
|
|
||||||
|
log = logging.getLogger(__name__)
|
||||||
|
|
||||||
|
|
||||||
def _can_authorize(crypto, doc) -> str:
|
def _can_authorize(crypto, doc) -> str:
|
||||||
"""decrypted authority of a doc as Yes/No, or `?` if unreadable here"""
|
"""decrypted authority of a doc as Yes/No, or `?` if unreadable here
|
||||||
|
|
||||||
|
a malformed/foreign flag degrades to `?` for display continuity. a GCM auth-tag
|
||||||
|
failure is logged first (WARNING): it is either a foreign key this host can't
|
||||||
|
decrypt or a tampered authz record, and this layer can't tell them apart, so the
|
||||||
|
security signal must stay visible rather than render identically to a `?`.
|
||||||
|
"""
|
||||||
try:
|
try:
|
||||||
return "Yes" if read_flag(crypto, doc["meta"]["authorizer"]) else "No"
|
return "Yes" if read_flag(crypto, doc["meta"]["authorizer"]) else "No"
|
||||||
except Exception:
|
except (KeyError, TypeError, ValueError):
|
||||||
|
return "?"
|
||||||
|
except InvalidTag:
|
||||||
|
friendly = doc_meta(doc).get("friendly", doc.get("_id", "?"))
|
||||||
|
log.warning("auth-tag verification failed for flag %s - foreign key or tampered record", friendly)
|
||||||
return "?"
|
return "?"
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user