Skip to content

Latest commit

 

History

History
46 lines (37 loc) · 2.17 KB

File metadata and controls

46 lines (37 loc) · 2.17 KB

SCOPE 2.0 Migration Guide

Summary

SCOPE 2.0 replaces the unsafe total-order approval hierarchy with AuthorizationEnvelope capability partial orders. Cross-family scopes are incomparable. Grant issuance requires a VerifiedDecision from the mandatory verification service.

Breaking changes

  1. Authorization model: scope_rank / total hierarchy comparisons are deprecated for authorization. Use envelope_contains, envelope_intersection, envelope_is_narrower, and envelope_difference.
  2. Grant issuance: GrantEngine.issue accepts only VerifiedDecision. Plain dicts with decision_signature are never grant-eligible.
  3. Identifiers: New artifacts use full UUID4 hex IDs (not 6-character fragments). Short IDs remain readable as legacy aliases only.
  4. Trust root: scope_trust_root_hash is the digest of the complete authorization trust manifest, not only policy + key registry.
  5. Identity: Missing role claim/group mapping fails closed (no default domain_scientist).
  6. REST: Spoofable X-Scope-Tenant-Id / X-Scope-Policy-Dir / X-Scope-Ledger-Path / X-Scope-Caller-Id headers are not authoritative. Public request fields no longer accept arbitrary server filesystem paths.
  7. Ledger: Prefer SQLite transactional ledger (SCOPE_LEDGER_BACKEND=sqlite or *.sqlite path). Local append files are LocalAppendSink, not WORM.
  8. Version: Package version is 2.0.0.

Compatibility bridges

  • Legacy scope names still appear on grants as approved_scope and map into envelopes via envelope_from_legacy_scope.
  • Development mode may accept unsigned decisions as explicit VerifiedDecision with SAL0; production requires cryptographic verification.

Contract vs implementation vs production

Layer Status
Artifact schemas (packet/decision/grant) Stable contract with 2.0 extensions
Core library implementation Beta — expanding toward institutional DoD
Production deployment profile Not claimed ready until Section 14 DoD passes

Do not market WORM, verified remote ledger, multi-tenant isolation, KMS/SAL4, or institutional authorization as complete until acceptance tests pass.