Parent: #130
Important
This issue captures the need to map these attributes, but the actual implementation behind what these attributes contain is a much bigger piece than simply mapping existing values. This issue shouldn't / can't be taken on until we have the capability to fetch auth metadata etc.
Map Kuadrant's later auth-pipeline attributes (auth.metadata, auth.authorization, auth.response, auth.callbacks) and the metadata / filter_state roots onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), sections "Auth — other phases" and "Metadata and filter state".
These are mostly Gap / N/A. auth.metadata (external metadata fetch) is the largest functional gap and the case most exposed to the fail-open-under-negation hazard. metadata collides with PPE meta.* (entity metadata — different thing).
Approach: no PPE pipeline phase reaches these today. Reject imported policies that depend on them rather than silently allowing (fail-open is a security hole, not a safe default). Shim metadata to meta.* only where semantics align.
Acceptance (tiered testing — doc "Testing strategy"):
Parent: #130
Important
This issue captures the need to map these attributes, but the actual implementation behind what these attributes contain is a much bigger piece than simply mapping existing values. This issue shouldn't / can't be taken on until we have the capability to fetch auth metadata etc.
Map Kuadrant's later auth-pipeline attributes (
auth.metadata,auth.authorization,auth.response,auth.callbacks) and themetadata/filter_stateroots onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), sections "Auth — other phases" and "Metadata and filter state".These are mostly Gap / N/A.
auth.metadata(external metadata fetch) is the largest functional gap and the case most exposed to the fail-open-under-negation hazard.metadatacollides with PPEmeta.*(entity metadata — different thing).Approach: no PPE pipeline phase reaches these today. Reject imported policies that depend on them rather than silently allowing (fail-open is a security hole, not a safe default). Shim
metadatatometa.*only where semantics align.Acceptance (tiered testing — doc "Testing strategy"):
auth.metadata/authorization/response/callbacks;metadatakeyword collision guarded.ppe-pdp-difffixtures prove a missing mapping cannot flip an Authorino deny into a PPE allow (the central fail-open-under-negation case).