A11 (C++ runtime)
Native C++ implementation of the A11 streaming action runtime
Loading...
Searching...
No Matches
authorization.h
Go to the documentation of this file.
1// Copyright 2026 The A11 Authors
2//
3// Licensed under the Apache License, Version 2.0 (the "License");
4// you may not use this file except in compliance with the License.
5// You may obtain a copy of the License at
6//
7// https://www.apache.org/licenses/LICENSE-2.0
8//
9// Unless required by applicable law or agreed to in writing, software
10// distributed under the License is distributed on an "AS IS" BASIS,
11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12// See the License for the specific language governing permissions and
13// limitations under the License.
14
15#ifndef A11_ACTIONS_AUTHORIZATION_H_
16#define A11_ACTIONS_AUTHORIZATION_H_
17
18#include <cstdint>
19#include <functional>
20#include <memory>
21#include <optional>
22#include <string>
23#include <string_view>
24#include <vector>
25
26#include <absl/status/status.h>
27#include <absl/status/statusor.h>
28#include <absl/time/time.h>
29#include <nlohmann/json.hpp>
30
31namespace a11::actions {
32
33class Action;
34class ActionRegistry;
35struct ActionSchema;
36
37inline constexpr std::string_view kAuthorizationHeader = "x-a11-auth";
38inline constexpr std::string_view kAuthorizationReferenceHeader =
39 "x-a11-auth-ref";
40inline constexpr std::string_view kAuthorizationDefaultHeader =
41 "x-a11-auth-default";
42inline constexpr std::string_view kAuthorizationReplaceHeader =
43 "x-a11-auth-replace";
44inline constexpr std::string_view kAuthorizeAction = "__authorize__";
45inline constexpr int kAuthorizationVersion = 1;
46inline constexpr size_t kMaxAuthorizationBytes = 16 * 1024;
47inline constexpr size_t kMaxAuthorizationHops = 8;
48
52 std::vector<std::string> chain;
53
55 const AuthorizationEnvelope&) = default;
56};
57
61 std::string subject;
62 std::string subject_kind;
63 std::vector<std::string> actors;
64 std::vector<std::string> provenance;
65 std::string assurance;
66 std::string audience;
67 absl::Time expires_at = absl::UnixEpoch();
68 nlohmann::json grants = nlohmann::json::array();
69 nlohmann::json restrictions = nlohmann::json::object();
70 std::int64_t authorization_epoch = 0;
71};
72
75 std::string context_id;
76 std::shared_ptr<const VerifiedAuthorization> authorization;
77 bool is_default = false;
78};
79
82 public:
83 struct State;
84
85 explicit AuthorizationContextStore(size_t max_contexts_per_stream = 128);
87
88 absl::StatusOr<AuthorizationContext> Install(
89 const std::shared_ptr<Action>& action,
90 std::shared_ptr<const VerifiedAuthorization> authorization,
91 bool make_default = true,
92 std::optional<std::string> replace = std::nullopt);
93 absl::StatusOr<std::shared_ptr<const VerifiedAuthorization>> Resolve(
94 const std::shared_ptr<Action>& action);
95 absl::Status ClearStream(const Action& action);
96 void ClearSession(std::string_view session_id);
97
98 private:
99 std::unique_ptr<State> state_;
100};
101
103 std::function<absl::StatusOr<VerifiedAuthorization>(std::string_view)>;
104
107
109absl::StatusOr<std::shared_ptr<AuthorizationContextStore>> InstallAuthorizer(
110 const std::shared_ptr<ActionRegistry>& registry,
111 AuthorizationVerifier verifier,
112 std::shared_ptr<AuthorizationContextStore> contexts = nullptr);
113
115absl::StatusOr<std::string> EncodeAuthorization(
116 const AuthorizationEnvelope& envelope);
117
119absl::StatusOr<AuthorizationEnvelope> DecodeAuthorization(
120 std::string_view value);
121
123absl::StatusOr<std::string> AuthorizationToText(
124 const AuthorizationEnvelope& envelope);
125
127absl::StatusOr<std::string> AuthorizationFingerprint(
128 const AuthorizationEnvelope& envelope);
129
131absl::StatusOr<AuthorizationEnvelope> AuthorizationFromText(
132 std::string_view value);
133
135absl::StatusOr<std::optional<AuthorizationEnvelope>> GetAuthorization(
136 const Action& action);
137
139absl::Status SetAuthorization(
140 const std::shared_ptr<Action>& action,
141 const std::optional<AuthorizationEnvelope>& envelope);
142
144absl::StatusOr<std::optional<std::string>> GetAuthorizationReference(
145 const Action& action);
146
148absl::Status SetAuthorizationReference(
149 const std::shared_ptr<Action>& action,
150 const std::optional<std::string>& context_id);
151
152} // namespace a11::actions
153
154#endif // A11_ACTIONS_AUTHORIZATION_H_
std::string session_id
Definition authorization.cc:327
A11's unit of work: a schema-described, asynchronously run operation.
Definition action.h:136
Bounded verified contexts scoped to the receiving Session and stream.
Definition authorization.h:81
absl::StatusOr< AuthorizationContext > Install(const std::shared_ptr< Action > &action, std::shared_ptr< const VerifiedAuthorization > authorization, bool make_default=true, std::optional< std::string > replace=std::nullopt)
Definition authorization.cc:377
absl::StatusOr< std::shared_ptr< const VerifiedAuthorization > > Resolve(const std::shared_ptr< Action > &action)
Definition authorization.cc:444
absl::Status ClearStream(const Action &action)
Definition authorization.cc:499
void ClearSession(std::string_view session_id)
Definition authorization.cc:513
std::string value
Definition discover.cc:114
Definition action.cc:63
constexpr std::string_view kAuthorizationDefaultHeader
Definition authorization.h:40
absl::StatusOr< std::shared_ptr< AuthorizationContextStore > > InstallAuthorizer(const std::shared_ptr< ActionRegistry > &registry, AuthorizationVerifier verifier, std::shared_ptr< AuthorizationContextStore > contexts)
Register __authorize__ for a native verifier and context store.
Definition authorization.cc:546
absl::StatusOr< std::string > AuthorizationFingerprint(const AuthorizationEnvelope &envelope)
Return an unpadded base64url SHA-256 identifier for the exact envelope.
Definition authorization.cc:206
ActionSchema AuthorizationActionSchema()
Schema of the transport-independent connection authorizing action.
Definition authorization.cc:518
absl::StatusOr< std::optional< std::string > > GetAuthorizationReference(const Action &action)
Read the receiver-issued raw 128-bit context reference, when present.
Definition authorization.cc:271
constexpr std::string_view kAuthorizeAction
Definition authorization.h:44
constexpr size_t kMaxAuthorizationHops
Definition authorization.h:47
constexpr size_t kMaxAuthorizationBytes
Definition authorization.h:46
absl::Status SetAuthorization(const std::shared_ptr< Action > &action, const std::optional< AuthorizationEnvelope > &envelope)
Set or remove a complete authorization and clear any context reference.
Definition authorization.cc:256
absl::Status SetAuthorizationReference(const std::shared_ptr< Action > &action, const std::optional< std::string > &context_id)
Set or remove a raw 128-bit context reference and clear any full proof.
Definition authorization.cc:282
constexpr std::string_view kAuthorizationReferenceHeader
Definition authorization.h:38
constexpr int kAuthorizationVersion
Definition authorization.h:45
std::function< absl::StatusOr< VerifiedAuthorization >(std::string_view)> AuthorizationVerifier
Definition authorization.h:103
absl::StatusOr< std::string > EncodeAuthorization(const AuthorizationEnvelope &envelope)
Validate and canonically encode an authorization envelope as MessagePack.
Definition authorization.cc:146
absl::StatusOr< AuthorizationEnvelope > AuthorizationFromText(std::string_view value)
Convert an ASCII physical HTTP header to the native envelope.
Definition authorization.cc:216
absl::StatusOr< std::optional< AuthorizationEnvelope > > GetAuthorization(const Action &action)
Decode the complete authorization on an action, when present.
Definition authorization.cc:238
absl::StatusOr< AuthorizationEnvelope > DecodeAuthorization(std::string_view value)
Decode a canonical, bounded native authorization value.
Definition authorization.cc:162
constexpr std::string_view kAuthorizationReplaceHeader
Definition authorization.h:42
absl::StatusOr< std::string > AuthorizationToText(const AuthorizationEnvelope &envelope)
Convert a native value to an ASCII physical HTTP header.
Definition authorization.cc:199
constexpr std::string_view kAuthorizationHeader
Definition authorization.h:37
The full typed interface of an action.
Definition schema.h:138
Definition authorization.cc:300
Result of installing a verified connection context.
Definition authorization.h:74
std::shared_ptr< const VerifiedAuthorization > authorization
Definition authorization.h:76
bool is_default
Definition authorization.h:77
std::string context_id
Definition authorization.h:75
A versioned ordered sequence of compact signed delegation statements.
Definition authorization.h:50
friend bool operator==(const AuthorizationEnvelope &, const AuthorizationEnvelope &)=default
std::vector< std::string > chain
Definition authorization.h:52
int version
Definition authorization.h:51
Identity and effective authority returned by an application verifier.
Definition authorization.h:59
std::string assurance
Definition authorization.h:65
std::int64_t authorization_epoch
Definition authorization.h:70
nlohmann::json restrictions
Definition authorization.h:69
nlohmann::json grants
Definition authorization.h:68
AuthorizationEnvelope envelope
Definition authorization.h:60
std::vector< std::string > actors
Definition authorization.h:63
std::string subject
Definition authorization.h:61
std::string subject_kind
Definition authorization.h:62
std::vector< std::string > provenance
Definition authorization.h:64
absl::Time expires_at
Definition authorization.h:67
std::string audience
Definition authorization.h:66