G3.2/G3.4: real EPT verification + wire the throttle, reopening agent auth
All checks were successful
check / gate (push) Successful in 21s
All checks were successful
check / gate (push) Successful in 21s
REOPENS the agent path — but only because possession is now actually proven. EPT verification (api/app/ept.py): ES256 against Eternitas's published key set at /.well-known/eternitas-keys. algorithms=['ES256'] makes alg:none and algorithm confusion unrepresentable rather than merely unlikely; issuer and exp are enforced by the library; an unknown kid is refused. Order is deliberate: signature FIRST, trust lookup second. These EPTs live ~365 days and carry rev/tru baked in at issuance, so a year-old 'rev: false' proves nothing — revocation and band still come from a live lookup on every request. Found while building it: real EPTs put the passport in . The old code read /, which no genuine EPT carries — so real agents were never recognised and ONLY forged tokens ever authenticated. The bypass was not just a hole, it was the only thing that worked. Throttle (api/app/throttle.py): BAND_MULTIPLIER and rate_*_per_day were defined and read by nothing. Now enforced on repo.create and grant.create, counted against agent_actions (one source of truth, not a private counter that drifts from the audit log). Fails CLOSED — a limiter that fails open protects you until the moment something is wrong. Untrusted band is 403 read-only, not 429, because 'slow down' would be a lie. Tests: 14 behavioral, signing real ES256 tokens with a locally-generated key so they exercise the crypto path with no network dependency — genuine tokens accepted, and alg:none / foreign key / tampered payload / expired / wrong issuer / unknown kid / missing claims all refused. 74 green. Co-Authored-By: Claude (Fable 5) <noreply@anthropic.com>
This commit is contained in:
@@ -26,6 +26,7 @@ from pydantic import BaseModel, Field, field_validator
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy.ext.asyncio import AsyncSession, async_sessionmaker
|
||||
|
||||
from api.app import throttle
|
||||
from api.app.auth import ActorType, Caller, get_caller
|
||||
from api.app.errors import RepairPointer
|
||||
from api.app.models.core import (
|
||||
@@ -208,6 +209,11 @@ async def create_repo(
|
||||
remediation_tool=None,
|
||||
)
|
||||
|
||||
# Throttle before any side effect. Checking after would let a rate-limited
|
||||
# agent still create the Gitea repo and only then be told no.
|
||||
async with _sessionmaker(request)() as session:
|
||||
await throttle.enforce(session, settings, caller, "repo.create")
|
||||
|
||||
gitea = GiteaClient(settings)
|
||||
owner = _owner_login(caller)
|
||||
await gitea.ensure_user(owner, f"{owner}@windygit.com")
|
||||
@@ -234,6 +240,8 @@ async def create_repo(
|
||||
),
|
||||
)
|
||||
session.add(repo)
|
||||
await session.flush()
|
||||
await throttle.record(session, caller, "repo.create", repo_id=repo.id)
|
||||
await session.commit()
|
||||
await session.refresh(repo)
|
||||
|
||||
@@ -337,6 +345,7 @@ async def create_grant(
|
||||
"""
|
||||
settings = request.app.state.settings
|
||||
async with _sessionmaker(request)() as session:
|
||||
await throttle.enforce(session, settings, caller, "grant.create")
|
||||
repo = await _load_repo(session, repo_id, caller)
|
||||
is_owner = (caller.identity_id and repo.identity_id == caller.identity_id) or (
|
||||
caller.passport and repo.passport == caller.passport
|
||||
@@ -364,6 +373,8 @@ async def create_grant(
|
||||
expires_at=expires,
|
||||
)
|
||||
session.add(grant)
|
||||
await session.flush()
|
||||
await throttle.record(session, caller, "grant.create", repo_id=repo.id)
|
||||
await session.commit()
|
||||
await session.refresh(grant)
|
||||
grant_id, role = grant.id, grant.role
|
||||
|
||||
Reference in New Issue
Block a user