All checks were successful
check / gate (push) Successful in 21s
REOPENS the agent path — but only because possession is now actually proven. EPT verification (api/app/ept.py): ES256 against Eternitas's published key set at /.well-known/eternitas-keys. algorithms=['ES256'] makes alg:none and algorithm confusion unrepresentable rather than merely unlikely; issuer and exp are enforced by the library; an unknown kid is refused. Order is deliberate: signature FIRST, trust lookup second. These EPTs live ~365 days and carry rev/tru baked in at issuance, so a year-old 'rev: false' proves nothing — revocation and band still come from a live lookup on every request. Found while building it: real EPTs put the passport in . The old code read /, which no genuine EPT carries — so real agents were never recognised and ONLY forged tokens ever authenticated. The bypass was not just a hole, it was the only thing that worked. Throttle (api/app/throttle.py): BAND_MULTIPLIER and rate_*_per_day were defined and read by nothing. Now enforced on repo.create and grant.create, counted against agent_actions (one source of truth, not a private counter that drifts from the audit log). Fails CLOSED — a limiter that fails open protects you until the moment something is wrong. Untrusted band is 403 read-only, not 429, because 'slow down' would be a lie. Tests: 14 behavioral, signing real ES256 tokens with a locally-generated key so they exercise the crypto path with no network dependency — genuine tokens accepted, and alg:none / foreign key / tampered payload / expired / wrong issuer / unknown kid / missing claims all refused. 74 green. Co-Authored-By: Claude (Fable 5) <noreply@anthropic.com>
51 lines
1.4 KiB
TOML
51 lines
1.4 KiB
TOML
[build-system]
|
|
requires = ["setuptools>=68"]
|
|
build-backend = "setuptools.build_meta"
|
|
|
|
[tool.setuptools.packages.find]
|
|
include = ["api*"]
|
|
|
|
[project]
|
|
name = "windy-git"
|
|
version = "0.1.0"
|
|
description = "Windy Git — the version, permission and provenance plane over Windy Cloud."
|
|
requires-python = ">=3.12"
|
|
dependencies = [
|
|
"fastapi>=0.115",
|
|
"uvicorn[standard]>=0.32",
|
|
"pydantic>=2.9",
|
|
"pydantic-settings>=2.6",
|
|
"sqlalchemy[asyncio]>=2.0",
|
|
"asyncpg>=0.30",
|
|
# Alembic runs synchronously (env.py strips +asyncpg), so the image needs a
|
|
# sync driver too. Without it migrations fail INSIDE the container while
|
|
# passing on a developer machine that happens to have it — the kind of gap
|
|
# that only shows up on a fresh deploy.
|
|
"psycopg2-binary>=2.9",
|
|
"alembic>=1.14",
|
|
"httpx>=0.27",
|
|
"boto3>=1.35",
|
|
# ES256 verification of Eternitas EPTs (G3.2/G9.1). Without crypto extras
|
|
# PyJWT cannot verify EC signatures and silently offers no protection.
|
|
"pyjwt[crypto]>=2.9",
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
dev = ["pytest>=8.3", "pytest-asyncio>=0.24", "ruff>=0.7", "mypy>=1.13"]
|
|
|
|
[tool.ruff]
|
|
line-length = 100
|
|
target-version = "py312"
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "I", "UP", "B", "SIM"]
|
|
ignore = ["E501"]
|
|
|
|
[tool.mypy]
|
|
python_version = "3.12"
|
|
ignore_missing_imports = true
|
|
|
|
[tool.pytest.ini_options]
|
|
testpaths = ["api/tests"]
|
|
asyncio_mode = "auto"
|