Skip to content

feat: bind active metadata authorization to dispatch evidence - #30

Open
zhouning wants to merge 1 commit into
feat/ar1-metadata-fabric-active-metadata-consumerfrom
feat/ar1-metadata-fabric-active-metadata-authorization
Open

feat: bind active metadata authorization to dispatch evidence#30
zhouning wants to merge 1 commit into
feat/ar1-metadata-fabric-active-metadata-consumerfrom
feat/ar1-metadata-fabric-active-metadata-authorization

Conversation

@zhouning

Copy link
Copy Markdown
Owner

Summary

  • add content-bound MetadataActivationAuthorization and an append-only tenant-scoped authorization ledger
  • atomically bind exact request, ResourceVersion, DefinitionVersion, accepted Run, execution plan, PolicyDecision, Approval, independent authorizer, and one pending dispatch
  • reject ordinary metadata projection dispatch, enforce FORCE RLS, function-only authorization insertion, deferred command FK, and database dispatch guard
  • use a path-free Chongqing cultural-district Shapefile inventory as acceptance input and ResourceVersion content identity without committing source data
  • add checked evidence, CI gates, Platform Truth registration, ADR-062, roadmap, and system-of-record updates

Validation

  • platform-required: 821 passed
  • focused evidence/catalog regression: 23 passed
  • PostgreSQL authorization integration: 1 passed
  • migration catalog, PlatformGateway, Platform Truth, and M3-14/M3-15/M3-16 evidence validators: valid
  • Ruff: all new Python files passed
  • git diff --check: passed

Scope boundary

Real data is acceptance evidence, not authorization or production authority. Scheduler submission/read-back, provider apply/mutation/ingestion, protected workload identity, deployment, and production readiness remain false.

This is a stacked PR based on feat/ar1-metadata-fabric-active-metadata-consumer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant