Approving one action must not approve its twin #15
theoadam2506-rgb
announced in
Articles
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Authority’s first evidence-backed article examines a narrow authorization failure:
In the reproduced scenario:
AUTHORIZED.REQUIRES_APPROVAL.Removing the
action_idcomparison incorrectly allows A2 to reuse P1. The mutation causes three regression tests to fail.The result is intentionally limited. It demonstrates action-instance approval binding in Authority V0. It does not establish cryptographic identity, exactly-once execution or protection against every form of replay. It also does not mean that every fingerprint-scoped authority query must distinguish A1 from A2:
AVAILABLE,INVOKEDandRECORDEDanswer different questions.Article:
https://authority-graph.com/articles/approval-binding-action-instance
French version:
https://authority-graph.com/fr/articles/approval-binding-action-instance
Implementation evidence:
46e1321
Questions for discussion:
AVAILABLE,INVOKEDandRECORDEDauthority expose a missing case or an incorrect assumption?Corrections, questions and reproducible counterexamples are welcome. Please report exploitable vulnerabilities privately through GitHub Private Vulnerability Reporting or
security@authority-graph.comrather than posting them here.This article and discussion were prepared with material AI assistance. The cited implementation, tests and claims were reviewed and approved by Théo Adam.
All reactions