Repository navigation
feat(delegation): resolve company authority from eVault history and bind grants to record id and time - #1194
Conversation
…ind grants to record id and time
|
@codex review |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0139a5d7dd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…re revocation, scope cycle detection to the lookup path
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5622b8c62d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… document per-verification sources
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 56ffd183b8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Description of change
PR 3 of 5 for company signing delegation (replaces #1193). The eVault stays a plain store; verifiers decide authority from signatures and the eVault's version history (
metaEnvelopeHistory).recordIdandsignedAt: a grant copied onto another record fails, and an older signed state can be told apart from a newer one. Writers pick the record id before signing (the eVault already allows creating under a chosen id). Stillw3ds-grant/v1; nothing has shipped with it.resolveBoard: directors over time from the Company record's history (the vault's manifest). First board signed by one of its own directors; later changes only by a sitting director. Unsigned, forged or outsider versions are skipped.historyChainSource: each Role/Delegation resolves to its latest version that is validly signed for its id, not older than the previous valid one, keeps its immutable fields, and was signed by someone entitled when stored:Revocation is final. Grants outlive a director's later removal. Vandalism or deletion doesn't change the result.
evaluateFromHistory: board, then the existingevaluateDelegation;checkDelegatedSignatureis reused unchanged.Next: PR 4 wires this into
packages/auth(verifyDelegatedSignaturereading the company eVault over GraphQL) plus sign-request helpers.Issue Number
Type of change
How the change has been tested
53 vitest cases (16 new in
history.spec.ts, in-memory history + fake verifier): board bootstrap and director-signed change; outsider and unsigned boards ignored; first board not signed by a member refused; delegation and narrowing re-delegation accepted end to end withcheckDelegatedSignature; non-director grant and wrong re-delegator ignored; copied grant fails on id; older state written back ignored; forged revoke ignored, valid revoke final even after a later signed re-activation; delegate can't revoke; grants survive the grantor leaving the board, later ones don't; revoked role fails children; vandalism and deletion survived; immutable field change ignored; re-delegation cycle terminates; no board → nothing. Grant payload tests cover id andsignedAtbinding.tscclean.Change checklist