Class MembershipAuthorizer

java.lang.Object
ai.badmonkey.agentspaces.peering.membership.MembershipAuthorizer
All Implemented Interfaces:
Authorizer

public final class MembershipAuthorizer extends Object implements Authorizer
The default Authorizer (security remediation plan §6): authority is rooted in the group's admitted membership, with optional explicit grants narrowing individual operations to named peers. This is the mtls profile's posture — the group's admission perimeter (founder-rooted INVITE credentials or the POLICY validator) already decides who belongs, and privileged operations follow that decision with no external dependency.

Ungranted operations default to any admitted member; an operation with an explicit grant is permitted to exactly the granted peers (who must still be admitted members — a revoked or evicted peer loses its grants with its membership). A fleet that wants only its console issuing directives grants DIRECTIVE_ISSUER to the console peer and leaves the rest defaulted.

  • Constructor Details

    • MembershipAuthorizer

      public MembershipAuthorizer(GroupMembership membership, PeerId self)
      Creates an authorizer over a group's membership with no explicit grants: every admitted member may perform every operation.
      Parameters:
      membership - the group's membership view
      self - this node's own peer id (always permitted; a node's view never contains itself)
    • MembershipAuthorizer

      public MembershipAuthorizer(GroupMembership membership, PeerId self, Map<Authorizer.Operation, Set<PeerId>> grants)
      Creates an authorizer with explicit per-operation grants.
      Parameters:
      membership - the group's membership view
      self - this node's own peer id
      grants - operations narrowed to named peers; absent operations default to any admitted member
    • MembershipAuthorizer

      public MembershipAuthorizer(GroupMembership membership, PeerId self, Map<Authorizer.Operation, Set<PeerId>> grants, Map<Authorizer.Operation, Set<AgentId>> agentGrants)
      Creates an authorizer with per-peer and per-agent grants (QA4 A4-7 phase 2). A bare PeerId grant admits every agent on that peer at PEER granularity; an AgentId grant admits that agent alone and switches the operation to AGENT granularity, under which an agent must be named to be permitted (its peer, asked at peer level, is permitted because it hosts a granted agent).
      Parameters:
      membership - the group's membership view
      self - the local peer, always admitted
      grants - per-operation PeerId grants
      agentGrants - per-operation AgentId grants
  • Method Details

    • parsing

      public static MembershipAuthorizer parsing(GroupMembership membership, PeerId self, Map<Authorizer.Operation, ? extends Collection<String>> encoded)
      Parses grant lists that mix bare PeerIds and peer/localName AgentIds, as the starter's agentspaces.security.grants.* do, into an authorizer.
      Parameters:
      membership - the group's membership view
      self - the local peer
      encoded - per-operation lists of PeerId or AgentId strings
      Returns:
      the authorizer
      Throws:
      IllegalArgumentException - on an entry that is neither
    • permits

      public boolean permits(PeerId peer, Authorizer.Operation operation, String scope)
      Description copied from interface: Authorizer
      Decides one authorization question. Implementations must be safe for concurrent use and fast enough to sit on frame-dispatch paths; expensive lookups (token validation, JWKS refresh) belong in caches behind this call, never inline.
      Specified by:
      permits in interface Authorizer
      Parameters:
      peer - the authenticated peer asking to act
      operation - the privileged operation
      scope - the operation's scope: a group id, a space name, or an empty string for fleet-wide operations
      Returns:
      whether the peer may perform the operation in that scope
    • permits

      public boolean permits(AgentId agent, Authorizer.Operation operation, String scope)
      Description copied from interface: Authorizer
      Whether an agent may perform an operation in a scope. The default delegates to the agent's peer, which is exactly today's behaviour; an implementation that holds agent-level grants overrides it and reports Authorizer.Granularity.AGENT for that operation and scope.
      Specified by:
      permits in interface Authorizer
      Parameters:
      agent - the agent being judged
      operation - the privileged operation
      scope - the operation's scope
      Returns:
      whether the agent is permitted
    • granularity

      public Authorizer.Granularity granularity(Authorizer.Operation operation, String scope)
      Description copied from interface: Authorizer
      The granularity at which this authorizer answers for an operation and scope; Authorizer.Granularity.PEER unless agent-level grants exist.
      Specified by:
      granularity in interface Authorizer
      Parameters:
      operation - the privileged operation
      scope - the operation's scope
      Returns:
      the granularity