feat: add subject access logs and appointment references - #1766
Merged
Merged
Conversation
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
…ring schemas Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
One expiry call erases at most 1000 rows, and the worker ran it once a minute, so a registry logging more than 1000 reads a minute accumulated expired rows past their retention promise. Each tick now keeps erasing committed batches until one comes back short, stops after 100 batches, and logs the remaining backlog when it reaches that bound. Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
… access-log entries ACCESS-LOG.md lists these read paths as logged, but the PostgreSQL suites only proved get, list, lookup, and relationship reads. Each path now has a test that reads through the real route and finds its access-log row. Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…ks read its result Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
This was referenced Sep 29, 2026
jeremi
enabled auto-merge
September 29, 2026 23:48
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Sep 30, 2026
The closed catalog now always expected the subject access-log table and expiry function, but only an apply creates them. A database v0.37.0 activated therefore failed `bregctl instance-claim status`, `bregctl verify`, and `breg` startup before any successor could be applied, and reapplying the active package failed because installing the storage changes the fingerprint that package records. A compiled catalog whose registry declares no `accessLog` is now checked without that storage while its table is absent. The next successor apply installs it. The retention worker starts only where the storage exists. Security review note: this relaxes the closed-catalog check only for the two access-log objects, only for a registry that collects no access log, and only while the table is absent. Ownership, ACL, row security, policy, and the recorded fingerprint checks stay exact, so a partial install or a collecting registry without storage is still refused. Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
jeremi
enabled auto-merge
September 30, 2026 00:54
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #1763.
Closes #1764.
BReg can now keep a subject-facing access log for an opted-in entity. Each materialized record read records the requester, time, and purpose under that registry's record identifier. The subject reads it with their own token and current record authority. Retention defaults to 90 days; governed exemptions delay visibility and record their use in the operational audit. Evidence can forward the original verified requester and authorized purpose to explicitly configured sources.
Scheduling's
v1alpha2HTTP contract adds typed, opaqueexternalReferencesto holds, direct bookings, and appointment responses. References survive confirmation, rescheduling, cancellation, and retries. An authenticated caller can list their appointments by an exact product, record type, and identifier tuple.Evidence
postgres_access_log(5),postgres_migration(52),postgres_compiled_schema(6),postgres_read(3), andpostgres_startup(15) passed with--locked --features postgres-test,tooling,schema. Coverage includes owner concealment, trusted attribution, per-hit logging, failure before response release, delayed exemptions, relationship profile collisions, expiry privileges, and upgrading an older catalog before later disabling collection. Three opt-in performance benchmarks were not run.cargo clippy --locked --all-targetspassed for BReg and bregctl with runtime/PostgreSQL features.source_contractstests, authenticated requester attribution, batch paths, reserved-header refusals, clippy, configuration-key checks, source neutrality, and contract reproduction passed. The maintained BReg-to-Evidence composition proof passed its 22 fixture cases and native source update.VERIFIED, plus a tampered-purpose 403. Formatting and diff checks passed.The full cross-product PostgreSQL matrices and TLS/S3 variants were not repeated locally. Focused tests cover the changed boundaries; protected CI supplies the broader matrix.
Notes
DCO
Signed-off-bytrailer.Review follow-up
products/breg/ACCESS-LOG.mdnow names GIS collection items under list reads; no existing claim in it was false.cargo fmt --check;cargo clippy --locked -p registry-breg --all-targets --features postgres-test,tooling,schema -- -D warnings;registry-breglibrary (173) andaccess_log(9) tests without a database;postgres_access_log(7) andpostgres_migration(52) on PostGIS, plus the new attachment and GIS tests;products/identifiers/scripts/check.sh;generate.py --check-references; docsnpm test,npm run check, andcheck:evidence-anchors.Security review notes
exemptionReasonbecomes visible to the subject once the exemption's delay ends. Both are deliberate, documented product choices.breg-evidence-lookup-v2, which changes thebehaviorRevisionof exported sources.