Skip to content

AuthPolicy compat: auth pipeline phases (auth.metadata/authorization/response/callbacks) + metadata/filter_state #161

Description

@maleck13

Parent: #130

Important
This issue captures the need to map these attributes, but the actual implementation behind what these attributes contain is a much bigger piece than simply mapping existing values. This issue shouldn't / can't be taken on until we have the capability to fetch auth metadata etc.

Map Kuadrant's later auth-pipeline attributes (auth.metadata, auth.authorization, auth.response, auth.callbacks) and the metadata / filter_state roots onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), sections "Auth — other phases" and "Metadata and filter state".

These are mostly Gap / N/A. auth.metadata (external metadata fetch) is the largest functional gap and the case most exposed to the fail-open-under-negation hazard. metadata collides with PPE meta.* (entity metadata — different thing).

Approach: no PPE pipeline phase reaches these today. Reject imported policies that depend on them rather than silently allowing (fail-open is a security hole, not a safe default). Shim metadata to meta.* only where semantics align.

Acceptance (tiered testing — doc "Testing strategy"):

  • Config loader rejects policies reading auth.metadata / authorization / response / callbacks; metadata keyword collision guarded.
  • Tier 1: Authorino reference JSON + expected decision checked in for these attributes, all recorded as expected divergence (Gap / N/A).
  • Tier 2: ppe-pdp-diff fixtures prove a missing mapping cannot flip an Authorino deny into a PPE allow (the central fail-open-under-negation case).
  • Tier 3: n/a — no runtime path reaches external auth metadata today.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions