Skip to content

P1: Workspace tenancy + signed-token authn (no header trust) #7

Description

@gnanirahulnutakki

Phase 1. Implement the Workspace tenancy anchor and signed-token authn — authorization derives from signed token claims only, never request headers.

Tasks

  • Workspace + Membership (roles: reader/operator/approver/admin) data model
  • Session/token verification; tenant + role from memberships[workspace] claim
  • Strip/ignore any inbound x-*-role/x-*-tenant headers
  • App-layer tenant scoping on every workspace-scoped model (hard-fail on mismatch)

Acceptance

  • A header-injected role has no effect; identity/tenant come only from the signed token.

Refs: ADR-0003, THREAT-MODEL §7.

Metadata

Metadata

Assignees

No one assigned

    Labels

    governancePDP / audit / decision-ledger / tenancyphase-1Phase 1: read-only federationsecuritySecurity hardening / isolation

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions