feat(hierarchy): M4-1b-ii hierarchy command family, grant evaluation, visibility
ci/woodpecker/pr/ci Pipeline was successful
ci/woodpecker/pr/ci Pipeline was successful
Implements the ratified hierarchy command surface per contract 1 (hierarchy-schema.md) and contract 2 (rbac-grant-model.md), brief M4-1B-II: - HierarchyRepository: the closed command family (company/estate/ platform-project create/rename/transfer/delete, grant create/change/ revoke, directory + granted-companies reads). Every mutation runs in one transaction through the M4-1b-i audit machinery (event + outbox, idempotency-key replay, causation-linked composite operations). - HierarchyGrantEvaluationService: live deny-by-default evaluation — effective role is the max over ancestor-chain user grants, fail-closed, team subjects suspended (§1.4), platform admin confers no tenant access (§1.1). - companies.visibility column (private default, directory carve-out) with migration 0020, admin-only audited visibility_change (§5.5), closed-field directory listing (§2.8), no-existence-oracle refusals (§6.7). - hierarchy_grants role CHECK pinned to the ratified vocabulary; namespaced serialized roles (hierarchy:*, §4.5). - §1.1 bypass retirement: role-derived MCP scope elevation and hasScope admin shortcuts removed; specs updated to the granted-scope path. - Witnesses: schema-level (role CHECK, visibility class/default), §6.3 closed route inventory, §6.4 per-mutation-class commit+rollback legs, §6.5 authorization, §6.7 oracle indistinguishability, §6.9 visibility, grant-evaluation semantics (chain inheritance, max-role, live revocation).
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
ALTER TABLE "hierarchy_audit_events" DROP CONSTRAINT "hierarchy_audit_events_verb_check";--> statement-breakpoint
|
||||
ALTER TABLE "companies" ADD COLUMN "visibility" text DEFAULT 'private' NOT NULL;--> statement-breakpoint
|
||||
ALTER TABLE "companies" ADD CONSTRAINT "companies_visibility_check" CHECK (visibility IN ('private', 'directory'));--> statement-breakpoint
|
||||
ALTER TABLE "hierarchy_audit_events" ADD CONSTRAINT "hierarchy_audit_events_verb_check" CHECK (verb IN ('create', 'rename', 'transfer', 'visibility_change', 'delete', 'grant_create', 'grant_change', 'grant_revoke'));--> statement-breakpoint
|
||||
ALTER TABLE "hierarchy_grants" ADD CONSTRAINT "hierarchy_grants_role_check" CHECK (role IN ('viewer', 'member', 'owner'));
|
||||
File diff suppressed because it is too large
Load Diff
@@ -141,6 +141,13 @@
|
||||
"when": 1787880918208,
|
||||
"tag": "0019_volatile_killraven",
|
||||
"breakpoints": true
|
||||
},
|
||||
{
|
||||
"idx": 20,
|
||||
"version": "7",
|
||||
"when": 1787963521142,
|
||||
"tag": "0020_special_betty_brant",
|
||||
"breakpoints": true
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user