15#ifndef A11_ACTIONS_AUTHORIZATION_H_
16#define A11_ACTIONS_AUTHORIZATION_H_
26#include <absl/status/status.h>
27#include <absl/status/statusor.h>
28#include <absl/time/time.h>
29#include <nlohmann/json.hpp>
68 nlohmann::json
grants = nlohmann::json::array();
88 absl::StatusOr<AuthorizationContext>
Install(
89 const std::shared_ptr<Action>& action,
90 std::shared_ptr<const VerifiedAuthorization> authorization,
91 bool make_default =
true,
92 std::optional<std::string> replace = std::nullopt);
93 absl::StatusOr<std::shared_ptr<const VerifiedAuthorization>>
Resolve(
94 const std::shared_ptr<Action>& action);
99 std::unique_ptr<State> state_;
103 std::function<absl::StatusOr<VerifiedAuthorization>(std::string_view)>;
110 const std::shared_ptr<ActionRegistry>& registry,
112 std::shared_ptr<AuthorizationContextStore> contexts =
nullptr);
120 std::string_view
value);
132 std::string_view
value);
140 const std::shared_ptr<Action>& action,
141 const std::optional<AuthorizationEnvelope>& envelope);
149 const std::shared_ptr<Action>& action,
150 const std::optional<std::string>& context_id);
std::string session_id
Definition authorization.cc:327
A11's unit of work: a schema-described, asynchronously run operation.
Definition action.h:136
Bounded verified contexts scoped to the receiving Session and stream.
Definition authorization.h:81
absl::StatusOr< AuthorizationContext > Install(const std::shared_ptr< Action > &action, std::shared_ptr< const VerifiedAuthorization > authorization, bool make_default=true, std::optional< std::string > replace=std::nullopt)
Definition authorization.cc:377
~AuthorizationContextStore()
absl::StatusOr< std::shared_ptr< const VerifiedAuthorization > > Resolve(const std::shared_ptr< Action > &action)
Definition authorization.cc:444
absl::Status ClearStream(const Action &action)
Definition authorization.cc:499
void ClearSession(std::string_view session_id)
Definition authorization.cc:513
std::string value
Definition discover.cc:114
constexpr std::string_view kAuthorizationDefaultHeader
Definition authorization.h:40
absl::StatusOr< std::shared_ptr< AuthorizationContextStore > > InstallAuthorizer(const std::shared_ptr< ActionRegistry > ®istry, AuthorizationVerifier verifier, std::shared_ptr< AuthorizationContextStore > contexts)
Register __authorize__ for a native verifier and context store.
Definition authorization.cc:546
absl::StatusOr< std::string > AuthorizationFingerprint(const AuthorizationEnvelope &envelope)
Return an unpadded base64url SHA-256 identifier for the exact envelope.
Definition authorization.cc:206
ActionSchema AuthorizationActionSchema()
Schema of the transport-independent connection authorizing action.
Definition authorization.cc:518
absl::StatusOr< std::optional< std::string > > GetAuthorizationReference(const Action &action)
Read the receiver-issued raw 128-bit context reference, when present.
Definition authorization.cc:271
constexpr std::string_view kAuthorizeAction
Definition authorization.h:44
constexpr size_t kMaxAuthorizationHops
Definition authorization.h:47
constexpr size_t kMaxAuthorizationBytes
Definition authorization.h:46
absl::Status SetAuthorization(const std::shared_ptr< Action > &action, const std::optional< AuthorizationEnvelope > &envelope)
Set or remove a complete authorization and clear any context reference.
Definition authorization.cc:256
absl::Status SetAuthorizationReference(const std::shared_ptr< Action > &action, const std::optional< std::string > &context_id)
Set or remove a raw 128-bit context reference and clear any full proof.
Definition authorization.cc:282
constexpr std::string_view kAuthorizationReferenceHeader
Definition authorization.h:38
constexpr int kAuthorizationVersion
Definition authorization.h:45
std::function< absl::StatusOr< VerifiedAuthorization >(std::string_view)> AuthorizationVerifier
Definition authorization.h:103
absl::StatusOr< std::string > EncodeAuthorization(const AuthorizationEnvelope &envelope)
Validate and canonically encode an authorization envelope as MessagePack.
Definition authorization.cc:146
absl::StatusOr< AuthorizationEnvelope > AuthorizationFromText(std::string_view value)
Convert an ASCII physical HTTP header to the native envelope.
Definition authorization.cc:216
absl::StatusOr< std::optional< AuthorizationEnvelope > > GetAuthorization(const Action &action)
Decode the complete authorization on an action, when present.
Definition authorization.cc:238
absl::StatusOr< AuthorizationEnvelope > DecodeAuthorization(std::string_view value)
Decode a canonical, bounded native authorization value.
Definition authorization.cc:162
constexpr std::string_view kAuthorizationReplaceHeader
Definition authorization.h:42
absl::StatusOr< std::string > AuthorizationToText(const AuthorizationEnvelope &envelope)
Convert a native value to an ASCII physical HTTP header.
Definition authorization.cc:199
constexpr std::string_view kAuthorizationHeader
Definition authorization.h:37
The full typed interface of an action.
Definition schema.h:138
Definition authorization.cc:300
Result of installing a verified connection context.
Definition authorization.h:74
std::shared_ptr< const VerifiedAuthorization > authorization
Definition authorization.h:76
bool is_default
Definition authorization.h:77
std::string context_id
Definition authorization.h:75
A versioned ordered sequence of compact signed delegation statements.
Definition authorization.h:50
friend bool operator==(const AuthorizationEnvelope &, const AuthorizationEnvelope &)=default
std::vector< std::string > chain
Definition authorization.h:52
int version
Definition authorization.h:51
Identity and effective authority returned by an application verifier.
Definition authorization.h:59
std::string assurance
Definition authorization.h:65
std::int64_t authorization_epoch
Definition authorization.h:70
nlohmann::json restrictions
Definition authorization.h:69
nlohmann::json grants
Definition authorization.h:68
AuthorizationEnvelope envelope
Definition authorization.h:60
std::vector< std::string > actors
Definition authorization.h:63
std::string subject
Definition authorization.h:61
std::string subject_kind
Definition authorization.h:62
std::vector< std::string > provenance
Definition authorization.h:64
absl::Time expires_at
Definition authorization.h:67
std::string audience
Definition authorization.h:66