fix(auth): validate embedded domains before authority

Signed-off-by: Cea Stapleton Cordasco <261786559+cea-block@users.noreply.github.com>
This commit is contained in:
Cea Stapleton Cordasco
2026-08-03 17:03:42 -05:00
parent 4affe89a4d
commit 6db9d336fb
3 changed files with 38 additions and 1 deletions
+16 -1
View File
@@ -14,7 +14,7 @@ use super::{
pub type AuthorityAdapterFuture<'a, T> = Pin<Box<dyn Future<Output = T> + Send + 'a>>;
/// Failure while invoking or validating a federated authority adapter.
#[derive(Debug, PartialEq, Eq)]
#[derive(PartialEq, Eq)]
pub enum AuthorityAdapterError<E> {
/// The storage adapter failed before producing authoritative state.
Adapter(E),
@@ -24,6 +24,21 @@ pub enum AuthorityAdapterError<E> {
PolicyChanged,
}
impl<E> fmt::Debug for AuthorityAdapterError<E> {
fn fmt(&self, formatter: &mut fmt::Formatter<'_>) -> fmt::Result {
let variant = match self {
Self::Adapter(_) => "Adapter",
Self::Contract(_) => "Contract",
Self::PolicyChanged => "PolicyChanged",
};
formatter
.debug_struct("AuthorityAdapterError")
.field("variant", &variant)
.field("detail", &"[redacted]")
.finish()
}
}
impl<E> AuthorityAdapterError<E> {
/// Wrap a storage-adapter failure.
pub const fn adapter(error: E) -> Self {
+10
View File
@@ -193,6 +193,16 @@ impl AuthContextInput {
self.tenant.community()
}
#[allow(dead_code)]
pub(crate) const fn nostr_proof_authorization_domain(&self) -> CommunityId {
self.nostr_proof.authorization_domain()
}
#[allow(dead_code)]
pub(crate) const fn community_access_authorization_domain(&self) -> CommunityId {
self.community_access.authorization_domain()
}
#[allow(dead_code)]
pub(crate) const fn correlation_id(&self) -> Uuid {
self.correlation_id
+12
View File
@@ -766,6 +766,18 @@ fn evidence_value_debug_output_redacts_numeric_values() {
);
}
#[test]
fn authority_adapter_error_debug_output_redacts_storage_detail() {
let error = AuthorityAdapterError::adapter("private-storage-detail");
let rendered = format!("{error:?}");
assert_eq!(
rendered,
"AuthorityAdapterError { variant: \"Adapter\", detail: \"[redacted]\" }"
);
assert!(!rendered.contains("private-storage-detail"));
}
#[test]
fn zero_owner_admission_expiry_is_rejected() {
assert_eq!(