Skip to content

Require trusted identity for ontology authority - #372

Merged
witbrock merged 2 commits into
mainfrom
agent/jvnautosci-2632-session-identity-hotfix
Aug 13, 2026
Merged

witbrock merged 2 commits into
mainfrom
agent/jvnautosci-2632-session-identity-hotfix

Conversation

@witbrock

@witbrock witbrock commented Aug 13, 2026 •

Copy link
Copy Markdown
Member

What changed

  • Require authenticated Flask session identity for the ontology-authority management blueprint.
  • Resolve actor provenance at the shared access-control seam while retaining legacy identity headers for compatibility reads.
  • Reject header-derived identity at every governed ontology effect boundary, including direct concept/relationship/text HTTP writes.
  • Prevent /von/generate and /von/api/session/set_user_concept from promoting a legacy header into signed session or adaptive-turn authority.
  • Prevent InternalMCP from classifying header-derived ambient identity as trusted workflow/authentication context.
  • Add both-header negative controls and authenticated-session positives across authority, HTTP, session, adaptive, gateway, scope, and stdio paths.

Root cause

PR #371 reused a legacy identity resolver that validates X-User-Concept-ID / X-User-Client-ID as existing people. That was sufficient for historical compatibility reads but not authentication. The new semantic-authority surfaces initially treated that identity as a direct human actor, and two routes could persist it into signed session state.

Impact

A client-supplied identity header can no longer grant, delegate, or exercise semantic ontology authority. Legitimate browser sessions and trusted in-process/workflow/adaptive contexts remain supported.

Validation

  • 87 end-to-end boundary tests passed across authority routes, direct HTTP, session setup, /von/generate, InternalMCP, stdio, and scope changes.
  • 69 role lifecycle, migration, operator-role, vocabulary, and motivating Tier-3 tests passed.
  • Independent bounded audit passed 27/27, 66/66, and 44/44 tranches and found no remaining legacy-header spoof path in this demonstrated class.
  • Ruff F/E9, Python byte-compilation, and git diff --check passed.

Jira: JVNAUTOSCI-2632

@witbrock witbrock changed the title Require session identity for ontology authority Require trusted identity for ontology authority Aug 13, 2026
@witbrock
witbrock marked this pull request as ready for review August 13, 2026 15:44
monkeypatch.setattr(
authority,
"resolve_live_semantic_roles",
lambda actor_id: (role,) if actor_id == "#V#existing_global_admin" else (),
@witbrock
witbrock merged commit b421d8e into main Aug 13, 2026
4 checks passed
@witbrock
witbrock deleted the agent/jvnautosci-2632-session-identity-hotfix branch August 18, 2026 20:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant