Add GitHub self‑governance/workflow gates, agent manifests, docs, CODEOWNERS, and trust‑authority tests - #17
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eb0ff11c05
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (req.method === "POST" && url.pathname === "/re/authorize") { | ||
| const body = await parseBody(req) as AuthorizeRequest | ||
| const { decision, reason, context } = decide(body, protectedPaths) |
There was a problem hiding this comment.
Enforce bearer auth before processing authorization requests
The /re/authorize handler processes and signs decisions without checking the Authorization header, so any caller that can reach this service can obtain valid receipts (including PERMIT for non-critical actions) and pollute the receipt chain. This is a security boundary issue because the workflows already assume token-gated access via RUNTIME_AUTH_TOKEN, but the service currently ignores that trust boundary entirely.
Useful? React with 👍 / 👎.
| if (!(prior.decision === "STEP_UP" || prior.decision === "ESCALATE")) { | ||
| return { decision: "DENY", reason: "prior_decision_not_reauthorizable", context } | ||
| } | ||
| if (!req.approval?.approved || !req.approval.approvedBy) { | ||
| return { decision: "DENY", reason: "step_up_approval_missing", context } |
There was a problem hiding this comment.
Validate reauth targets match the prior receipt context
Reauthorization only checks that the prior receipt exists and had STEP_UP/ESCALATE, then permits on generic approval/freshness checks; it never verifies that the new request matches the prior receipt’s repo/resource/commit/action scope. This allows reusing a step-up receipt from one change to authorize a different change, which breaks the intended step-up security model.
Useful? React with 👍 / 👎.
| } | ||
|
|
||
| if (req.method === "POST" && url.pathname === "/re/authorize") { | ||
| const body = await parseBody(req) as AuthorizeRequest |
There was a problem hiding this comment.
Handle JSON parse failures in /re/authorize requests
The route awaits parseBody(req) without a try/catch, but parseBody rejects on malformed JSON; in that case the request never gets a structured error response and can surface as an unhandled rejection. A single malformed client payload can therefore cause request hangs and potentially destabilize the process depending on runtime unhandled-rejection settings.
Useful? React with 👍 / 👎.
Motivation
POST /re/authorize) and requiring auditable receipts.CODEOWNERSand related repo access guidance.Description
CODEOWNERS, two workflow skeletons (.github/workflows/ttp-protected-gate.yml,.github/workflows/ttp-governed-pr-action.yml) and a CI job (.github/workflows/ci.yml) that builds and tests the trust‑authority reference.docs/,policy/,spec/extensions/,receipts/schemas/and new README/CONTRIBUTING/SECURITY updates to document self‑governance, operator guides, open‑source boundary, and public‑readiness.agents/(multiplemanifest.jsonandrole-agents.yaml) to model workload identities and allowed actions for AI role‑agents.services/authority/) that implementsPOST /re/authorize, receipt signing/chain hashing, policy loader, and example decision logic and schemas.src/aggregation.test.ts),jestconfig,package.jsondev deps,tsconfigadjustments, API extensionGET /v1/admin/agents, in‑memory store helpers (listAgents,getAgentReceiptsAcrossDomains), and multiple small crypto/sha512 sync fixes.ttp-languagedocs to match repository semantics.Testing
reference-implementations/trust-authority/src/aggregation.test.tswhich exerciseaggregateTrustScorebehavior (windowing, issuer weight cap, metadata outputs).CI(.github/workflows/ci.yml) to runnpm install,npm run build, andnpm testinreference-implementations/trust-authority; the job is wired to run onpush/pull_request.npm test/jest) as part of validation and passed (aggregation behavior and cap logic succeeded).Codex Task