Class MembershipAuthorizer
java.lang.Object
ai.badmonkey.agentspaces.peering.membership.MembershipAuthorizer
- All Implemented Interfaces:
Authorizer
The default
Authorizer (security remediation plan §6): authority is
rooted in the group's admitted membership, with optional explicit grants
narrowing individual operations to named peers. This is the mtls
profile's posture — the group's admission perimeter (founder-rooted INVITE
credentials or the POLICY validator) already decides who belongs, and
privileged operations follow that decision with no external dependency.
Ungranted operations default to any admitted member; an operation
with an explicit grant is permitted to exactly the granted peers (who must
still be admitted members — a revoked or evicted peer loses its grants with
its membership). A fleet that wants only its console issuing directives
grants DIRECTIVE_ISSUER to the console peer and leaves the rest
defaulted.
-
Nested Class Summary
Nested classes/interfaces inherited from interface Authorizer
Authorizer.Granularity, Authorizer.Operation -
Constructor Summary
ConstructorsConstructorDescriptionMembershipAuthorizer(GroupMembership membership, PeerId self) Creates an authorizer over a group's membership with no explicit grants: every admitted member may perform every operation.MembershipAuthorizer(GroupMembership membership, PeerId self, Map<Authorizer.Operation, Set<PeerId>> grants) Creates an authorizer with explicit per-operation grants.MembershipAuthorizer(GroupMembership membership, PeerId self, Map<Authorizer.Operation, Set<PeerId>> grants, Map<Authorizer.Operation, Set<AgentId>> agentGrants) Creates an authorizer with per-peer and per-agent grants (QA4 A4-7 phase 2). -
Method Summary
Modifier and TypeMethodDescriptiongranularity(Authorizer.Operation operation, String scope) The granularity at which this authorizer answers for an operation and scope;Authorizer.Granularity.PEERunless agent-level grants exist.static MembershipAuthorizerparsing(GroupMembership membership, PeerId self, Map<Authorizer.Operation, ? extends Collection<String>> encoded) Parses grant lists that mix bare PeerIds andpeer/localNameAgentIds, as the starter'sagentspaces.security.grants.*do, into an authorizer.booleanpermits(AgentId agent, Authorizer.Operation operation, String scope) Whether an agent may perform an operation in a scope.booleanpermits(PeerId peer, Authorizer.Operation operation, String scope) Decides one authorization question.
-
Constructor Details
-
MembershipAuthorizer
Creates an authorizer over a group's membership with no explicit grants: every admitted member may perform every operation.- Parameters:
membership- the group's membership viewself- this node's own peer id (always permitted; a node's view never contains itself)
-
MembershipAuthorizer
public MembershipAuthorizer(GroupMembership membership, PeerId self, Map<Authorizer.Operation, Set<PeerId>> grants) Creates an authorizer with explicit per-operation grants.- Parameters:
membership- the group's membership viewself- this node's own peer idgrants- operations narrowed to named peers; absent operations default to any admitted member
-
MembershipAuthorizer
public MembershipAuthorizer(GroupMembership membership, PeerId self, Map<Authorizer.Operation, Set<PeerId>> grants, Map<Authorizer.Operation, Set<AgentId>> agentGrants) Creates an authorizer with per-peer and per-agent grants (QA4 A4-7 phase 2). A bare PeerId grant admits every agent on that peer atPEERgranularity; an AgentId grant admits that agent alone and switches the operation toAGENTgranularity, under which an agent must be named to be permitted (its peer, asked at peer level, is permitted because it hosts a granted agent).- Parameters:
membership- the group's membership viewself- the local peer, always admittedgrants- per-operation PeerId grantsagentGrants- per-operation AgentId grants
-
-
Method Details
-
parsing
public static MembershipAuthorizer parsing(GroupMembership membership, PeerId self, Map<Authorizer.Operation, ? extends Collection<String>> encoded) Parses grant lists that mix bare PeerIds andpeer/localNameAgentIds, as the starter'sagentspaces.security.grants.*do, into an authorizer.- Parameters:
membership- the group's membership viewself- the local peerencoded- per-operation lists of PeerId or AgentId strings- Returns:
- the authorizer
- Throws:
IllegalArgumentException- on an entry that is neither
-
permits
Description copied from interface:AuthorizerDecides one authorization question. Implementations must be safe for concurrent use and fast enough to sit on frame-dispatch paths; expensive lookups (token validation, JWKS refresh) belong in caches behind this call, never inline.- Specified by:
permitsin interfaceAuthorizer- Parameters:
peer- the authenticated peer asking to actoperation- the privileged operationscope- the operation's scope: a group id, a space name, or an empty string for fleet-wide operations- Returns:
- whether the peer may perform the operation in that scope
-
permits
Description copied from interface:AuthorizerWhether an agent may perform an operation in a scope. The default delegates to the agent's peer, which is exactly today's behaviour; an implementation that holds agent-level grants overrides it and reportsAuthorizer.Granularity.AGENTfor that operation and scope.- Specified by:
permitsin interfaceAuthorizer- Parameters:
agent- the agent being judgedoperation- the privileged operationscope- the operation's scope- Returns:
- whether the agent is permitted
-
granularity
Description copied from interface:AuthorizerThe granularity at which this authorizer answers for an operation and scope;Authorizer.Granularity.PEERunless agent-level grants exist.- Specified by:
granularityin interfaceAuthorizer- Parameters:
operation- the privileged operationscope- the operation's scope- Returns:
- the granularity
-