Add GitHub self-governance: runtime authority, protected PR gates, docs, agents and TA updates - #18
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3f9faba4ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "workflowRunId": "${{ github.run_id }}", | ||
| "attestationRef": "att-pr-${{ github.run_id }}-reauth", | ||
| "authorityGrantRef": "grant-pr-${{ github.run_id }}", | ||
| "priorReceiptId": "${{ needs.protected-action-gate.outputs.receipt_id }}", | ||
| "approval": { |
There was a problem hiding this comment.
Include freshnessSeconds in reauthorization request
The reauthorization payload never sets freshnessSeconds, but .github/scripts/ttp-local-authorize.mjs defaults missing freshness to 9999 and returns ESCALATE for merge request reauthorize when freshness is over 900. In protected-path PRs this means step-up-approval can succeed but reauthorize-after-step-up still cannot produce PERMIT, so merge-authority consistently blocks merges.
Useful? React with 👍 / 👎.
| if (req.method === "POST" && url.pathname === "/re/authorize") { | ||
| const body = await parseBody(req) as AuthorizeRequest |
There was a problem hiding this comment.
Catch JSON parse errors on /re/authorize
parseBody(req) is awaited without a try/catch, so malformed JSON causes a rejected promise inside the HTTP request handler instead of a controlled 4xx response. In Node HTTP servers this can leave the request unresolved and surface as an unhandled rejection, which is an availability issue for a public authorization endpoint.
Useful? React with 👍 / 👎.
| } | ||
|
|
||
| function decide(req: AuthorizeRequest, protectedPaths: string[]): { decision: Decision; reason: string; context: DecisionContext } { | ||
| const protectedAction = req.pathsTouched.some(p => isProtectedPath(p, protectedPaths)) |
There was a problem hiding this comment.
Validate pathsTouched before using .some()
The decision path calls req.pathsTouched.some(...) before any runtime validation of request shape. A syntactically valid request with pathsTouched omitted or non-array will throw TypeError, bypassing policy evaluation and returning no proper authorization decision, which can crash or destabilize this handler under malformed input.
Useful? React with 👍 / 👎.
Motivation
Description
services/authority/*, includingreceiptSigner,policyLoader,schemas, and an HTTPPOST /re/authorizeimplementation that emits signedExecutionReceipts../.github/scripts/ttp-local-authorize.mjsand GitHub Actions workflow skeletonsttp-protected-gate.ymlandttp-governed-pr-action.ymlwhich call the local authority and enforce decisions (PERMIT|STEP_UP|ESCALATE|DENY).policy/*.yaml,agents/*manifests andagents/manifests/role-agents.yamlto declare role-agents, protected paths, thresholds, and escalation rules.docs/(self-governance architecture, operator guide, getting-started, protected-action model, repo access control, public-readiness, roadmap, ecosystem integrations) and README/CONTRIBUTING/SECURITY updates to reflect repository self-governance and release controls.aggregation.test.ts, enhancements tostore.tsandroutes.ts(adminGET /v1/admin/agents, metrics), crypto fixes for@noble/hashesusage,jestconfig,package.jsondeps, and TS config tweaks.receipts/schemasandspec/extensionsand example/supporting files (runtime/api/re-authorize.contract.md,rfcs/0001-*).CODEOWNERSentries for maintainers and protocol/security owners and an examples/acceptance test doc for protected workflow edits.Testing
reference-implementations/trust-authority/src/aggregation.test.tsexercisingaggregateTrustScoreand rannpm testinreference-implementations/trust-authority, and the test suite completed successfully./.github/workflows/ci.ymlis provided to runnpm install,npm run build, andnpm testfor the Trust Authority package on PRs and pushes.node .github/scripts/ttp-local-authorize.mjsfrom workflow steps in the repository examples (used in the protected gate and governed PR action steps).Codex Task