Skip to content

Define auth RBAC verifier contract#12

Merged
andrei-hasna merged 1 commit into
mainfrom
missing-core/foundation-auth-rbac
Jul 6, 2026
Merged

Define auth RBAC verifier contract#12
andrei-hasna merged 1 commit into
mainfrom
missing-core/foundation-auth-rbac

Conversation

@andrei-hasna

Copy link
Copy Markdown
Contributor

Summary

  • add a shared Auth and RBAC Verifier Contract for API, MCP, CLI-token, dashboard, worker, sync/export, and provider webhook surfaces
  • define auth context, token types, scope/role model, tenant/workspace/entity boundaries, negative-test matrix, provider webhook rules, and audit requirements
  • link the contract from the @hasna/contracts README

Validation

  • bun install --frozen-lockfile
  • bun run typecheck
  • bun test
  • bun run build
  • marker scan for patch markers
  • negative matrix term scan
  • staged secrets scan: todos redaction scan --file /tmp/open-contracts-auth-rbac-staged.diff

Task: 74220f07-c9e0-487a-ac32-d6bbe91fdf1a

@andrei-hasna
andrei-hasna merged commit 1d383d7 into main Jul 6, 2026
1 check passed
@andrei-hasna
andrei-hasna deleted the missing-core/foundation-auth-rbac branch July 6, 2026 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant