Skip to content

feat(iam): enforce the effective action set on the fast path - #133

Closed
pyropy wants to merge 1 commit into
srdjan/feat/iam-permission-setfrom
srdjan/feat/iam-enforce-actions
Closed

pyropy wants to merge 1 commit into
srdjan/feat/iam-permission-setfrom
srdjan/feat/iam-enforce-actions

Conversation

@pyropy

@pyropy pyropy commented Sep 10, 2026 •

Copy link
Copy Markdown

Description

The fast path enforces the effective action set. A key granted only s3:PutObject could read, list and abort multipart uploads on the same bucket, because that permission's command set covers those actions and the fast path decided on a chain probe alone. The authorize response's permissions is now cached per bucket and an action outside it is refused with AccessDenied; no cached set means Hilt decides. Part of the Forge S3 tenant IAM work (RFC).

Change log

  • authorizeLocal returns a denial alongside the existing ok result; set cached on the Hilt path
  • TestPutOnlyKeyIsDeniedOnReads pins the defect; no set, empty set, action outside set
  • Diagrams updated

🤖 Generated with Claude Code

@pyropy
pyropy added this pull request to stack #135 September 10, 2026 16:21
A key granted only s3:PutObject could read and abort on the same bucket:
s3perm maps that permission to a command set containing every command
s3:GetObject, s3:ListBucket and s3:AbortMultipartUpload need, and the
fast path decided on a chain probe alone.

The authorize response's effective action set is now cached under the
bucket hilt named, with the same expiry as the derived keys and the
tenant. authorizeLocal reports authorized, denied or undecided: it
refuses an action the cached set excludes with AccessDenied, and defers
to hilt whenever no set is cached or the operation maps to no Forge
command.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@pyropy
pyropy force-pushed the srdjan/feat/iam-enforce-actions branch from c756269 to a2a886d Compare September 11, 2026 12:42
@pyropy

pyropy commented Sep 15, 2026

Copy link
Copy Markdown
Author

Superseded by the per-key marker design in fil-one/RFC#30 (f61f474): no principal invalidation record; markers are revoked through the existing /ucan/revoke. Branch kept.

@pyropy pyropy closed this Sep 15, 2026
@pyropy
pyropy removed this pull request from stack #135 September 15, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant