Skip to content

feat(cloudserver): authorize explicit prompt source attestations - #1548

Merged
dnlrsls merged 1 commit into
Gentleman-Programming:feat/prompt-inbox-foundation-trackerfrom
dnlrsls:feat/prompt-source-attestation-api
Sep 29, 2026
Merged

dnlrsls merged 1 commit into
Gentleman-Programming:feat/prompt-inbox-foundation-trackerfrom
dnlrsls:feat/prompt-source-attestation-api

Conversation

@dnlrsls

@dnlrsls dnlrsls commented Sep 29, 2026

Copy link
Copy Markdown
Member

🔗 Linked Issue

Closes #1458

Third bounded child for explicit source reauthorization, based on open tracker #1464 at aee38de0, not main.

🏷️ PR Type

  • type:feature — New feature

📝 Summary

  • Add human-principal-only POST /sync/prompt-source-attestations, with strict bounded request, actor bound to the authenticated principal, and current grants on both asserted owner and prompt projects before accessing a global session identity.
  • For an old source with no cloud binding, register asserted owner, claim exact pair, then append an audit attestation. Conflict/transport/storage failures report no success; local confirmation and deletes are not enabled.
  • Document that the explicit assertion is neither proof of historical creation nor a delete grant.

📂 Changes

File Change
internal/cloud/cloudserver/cloudserver.go Route behind withAuth.
internal/cloud/cloudserver/prompt_source_attestation.go Auth, dual-grant, exact source binding and fail-closed error handling.
internal/cloud/cloudserver/prompt_source_attestation_test.go Grant/error/malformed cases plus real bearer-boundary test for human, missing, revoked, disabled, legacy and service credentials.
docs/codebase/prompt-inbox-provenance.md Distinguish explicit assertion from local creation and delete authorization.

257 additions, 2 deletions. Partial remote registration/claim may persist if later audit insert fails; client sees failure and MUST NOT record local confirmation. Retry is idempotent for the binding and appends audit only on success.

🧪 Test Plan

  • Test-first RED: focused test failed with 404 before route mount; GREEN after handler implementation (writer report). Bearer regression initially expected 403 for disabled principal but actual withAuth returned 401, expectation corrected before commit.
  • Focused: go test ./internal/cloud/cloudserver -run '^TestPromptSourceAttestation(BearerBoundary|Admission)$' -count=1 — PASS (independent verifier).
  • Affected package: go test ./internal/cloud/cloudserver -count=1 — PASS (independent verifier).
  • Additional: go vet ./internal/cloud/cloudserver, gofmt listing for new files, git diff --cached --check — PASS. Storage-only exact-binding/append-only tests passed against disposable Postgres in preceding feat(cloudstore): record explicit prompt source attestations #1547; HTTP-to-Postgres path not yet verified. Native review review-59f121b5698420cc approved/acknowledged; nonblocking reliability advisory on fake-store identity assertions to revisit in integration tests.
  • GitHub unit/E2E/plugin/lint/Windows/policy checks — pending at creation.

🤖 Automated Checks

CI pending. All required checks must pass before normal merge.

✅ Contributor Checklist

💬 Notes for Reviewers

A confirmed human assertion plus current grants can authorize a cloud binding even for a formerly unregistered imported source; it never proves local creation. This route does not itself authorize autosync or any remote delete. Subsequent children need a local confirmed marker, one-source CLI with preview/confirmation, gated autosync, separate verified-delete policy and integrated validation before #1464 can be queued.

@dnlrsls dnlrsls added the type:feature New feature label Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d773cf03-b5d5-4241-a446-2b80e0dabda3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dnlrsls
dnlrsls merged commit bd126db into Gentleman-Programming:feat/prompt-inbox-foundation-tracker Sep 29, 2026
15 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:feature New feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant