Skip to content

GRAPHOS-IDENTITY-R009.2.2: OIDC ID-token claim checks with typed refusal - #231

Merged
43 commits merged into
mainfrom
deliver-identity-r009-2-2
Oct 10, 2026
Merged

43 commits merged into
mainfrom
deliver-identity-r009-2-2

Conversation

@Knucklessg1

Copy link
Copy Markdown
Member

Adds check_id_token_claims and OidcTokenRefused/OidcRefusalReason in graph_os/identity/oidc.py (issuer, audience, expiry, nonce over decoded claims). Based on land/train-1010d.

🤖 Generated with Claude Code

Knucklessg1 and others added 30 commits October 10, 2026 15:20
… resolver

_probe_protocol_families called _harvest_resource_bodies directly twice; both now
go through _resolve_via_local_catalog_or_harvest so admitted children resolve from
the resident catalog with no wire read.

Spec: GRAPHOS-FLEET-R006.3.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Only ingest sync has a real registry operation; every other analyze/ingest
legacy action is a gap, so each row is split into add-operation children
plus an approve-mappings child.

Spec: none (refactor)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… ports

build_identity_ports builds the concrete runtime once and returns it typed as
CredentialAuthority/SessionAuthority; fails closed with IdentityUnavailable.

Spec: GRAPHOS-OPS-R032.2.1
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Add expires_at and effective_scopes(): intersect with owner scopes at use time, deny revoked/expired keys, never yield approver scopes.

Spec: GRAPHOS-IDENTITY-R008.2
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Spec: none (refactor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Injection needs run_web_ui and mcp_server.composition startup wiring that cannot be tested in isolation; split into compose_web_application (.1) and run_web_ui/supervisor threading (.2).

Spec: none (refactor)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Adds the approved mapping and a bound test that the operation id exists in the ingest registry.

Spec: GRAPHOS-HOST-R005.2.3.1
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ring (.2)

The R022/PA-12 publish step is not built in graph-os, so there is no entry point to wire. R003 becomes a rollup with two bite-sized children.

Spec: none (refactor)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
admit_tool_subset already refuses closed; add a negative test across
varied graph refs and budgets proving no trimmed admission is returned.

Spec: GRAPHOS-A2A-002-R005
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Split R020.3.1 into .1 (ingest.packs.list) and .2 (ingest.jobs.status) and
deliver .1 through the typed ingest runner port with the ingest:read scope.

Spec: GRAPHOS-OPS-R020.3.1.1
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Spec: none (refactor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Typed IngestJobRecord and runner port method get_job_status; read op under ingest:read, fails closed with UNAVAILABLE when no runner is composed.

Spec: GRAPHOS-OPS-R020.3.1.2
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Adds PublicationRefusedError and require_reconciled_for_swap(), which raises
the typed refusal for any reingestion-unreconciled gate result.

Spec: GRAPHOS-MCP-RESOURCES-R003.1
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
ingest.operations() gained ingest.packs.list; both functions are still the
per-domain declarative OpSpec registries the entry describes.

Spec: none (refactor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Spec: none (refactor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…server

No production identity runtime exists (build_identity_ports has only test
callers), so the supervisor start call cannot supply real ports yet. Split
.2.3.2 into .2.3.2.1 (run_web_ui accepts/binds ports, lands with .2.3.1) and
.2.3.2.2 (supply from mcp_server composition, depends on R032.2.2).

Spec: none (refactor)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…o children

Split R010.2 into .2.1-.2.4 and deliver .2.1: map_groups_to_roles with DN
normalization, refusing when no group maps to a role.

Spec: GRAPHOS-IDENTITY-R010.2.1
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Split R009.2 into children .2.1-.2.4; deliver pure select_mapping_rule.

Spec: GRAPHOS-IDENTITY-R009.2.1
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ser model

R011.2 becomes a rollup of .2.1-.2.4; .2.1 delivers ScimUser with validation/refusal tests.

Spec: GRAPHOS-IDENTITY-R011.2.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Knucklessg1 and others added 13 commits October 10, 2026 16:15
Split R012.2 into .2.1-.2.4; deliver .2.1: ParsedSamlAssertion plus pure
audience/recipient/validity-window checks with typed refusal reasons.

Spec: GRAPHOS-IDENTITY-R012.2.1
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Split R021.2 into .1 retrieval.search and .2 retrieval.freshness; deliver
.1 through a typed retriever port that truncates hits to the context budget
and fails closed with UNAVAILABLE.

Spec: GRAPHOS-OPS-R021.2.1
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Add docs-consistency tests asserting docs/status.md and docs/fleet.md cite
exactly the reingestion-unreconciled code the gate returns.

Spec: GRAPHOS-MCP-RESOURCES-R004
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
….jobs.status

Spec: none (refactor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…223-#229

Spec: none (refactor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Adds check_id_token_claims (issuer, audience, expiry, nonce over decoded claims) raising OidcTokenRefused with an OidcRefusalReason; no signature handling.

Spec: GRAPHOS-IDENTITY-R009.2.2
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Knucklessg1 added a commit that referenced this pull request Oct 10, 2026
@Knucklessg1 Knucklessg1 closed this pull request by merging all changes into main in 6f4153f Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant