mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
fix(security): active guard enforcement, CEO A2A target check, notification expiry (#595)
* fix(security): guard goes active; CEO A2A respects no-comms roles; ack notifications expire ROBOCO_GUARD_PASSIVE_MODE defaults to false in both compose files — the deferred post-calibration flip; fail_secure stays off and the env override remains the rollback. can_a2a_direct no longer short-circuits the CEO past the no-comms set (auditor/pr_reviewer/prompter/secretary), now canonical in foundation.policy.communications.NO_COMMS_ROLES and shared with the content-actions gate; the A2A service refuses at conversation creation instead of silently suppressing the wake. Ack-required notifications get expires_at stamped from ROBOCO_NOTIFICATION_ACK_TTL_HOURS (default 48, 0 disables), so the re-escalation sweeper's expires_at query matches rows for the first time. * refactor(notification): extract _ack_and_expiry — xenon rank back under B The expires_at stamping pushed _create_notification_with_session to rank C; the requires_ack + expiry derivation moves into a helper with the same semantics and comments. * test(conftest): dispose the global DB engine after every test Production code reaching get_db_context()/get_engine() lazily creates the process-global engine bound to the current event loop; with per-test function-scoped loops, any later test touching the global path inherits a dead-loop engine and dies with 'Future attached to a different loop' — the order-dependent class that has been wandering the suite (cloud_auth login, metrics, tasks-routes, full-lifecycle) whenever collection order shifts. An autouse fixture now close_db()s after every test, keeping the global path loop-local; no-op when untouched. --------- Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
@@ -35,9 +35,11 @@
|
||||
# stays conservative; the build compose arms most of them ON for the
|
||||
# personal NAS deploy. ROBOCO_ROUTING_STRICT and the fastapi-guard trio
|
||||
# (ROBOCO_GUARD_ENABLED/_PASSIVE_MODE/_FAIL_SECURE) are the exception:
|
||||
# both are still mid-calibration on the personal deploy, so they're
|
||||
# omitted entirely here rather than carried — their config defaults
|
||||
# (graceful-degrade routing, guard off) are already the safe posture.
|
||||
# ROUTING_STRICT is still mid-calibration, and guard is now ACTIVE
|
||||
# enforcement on the personal deploy (passive calibration reviewed clean).
|
||||
# Both stay omitted here rather than carried — a third-party deployer
|
||||
# hasn't run that calibration against their own traffic, so their config
|
||||
# defaults (graceful-degrade routing, guard off) are the safer posture.
|
||||
# - Host path defaults differ (/opt/roboco vs /volume1/roboco, ${HOME}
|
||||
# instead of a hardcoded /home/renzof) — registry targets a generic host.
|
||||
# - MinIO (object storage for rendered videos) is intentionally omitted —
|
||||
|
||||
Reference in New Issue
Block a user