feat(iios): wire the three-proof gate into the request path (§1b)
Applies the context-attestation verifier at the request boundary via a guard, so a stolen/forged/replayed attestation is rejected before IIOS acts — while staying safe to roll out. - ContextAttestationGuard: if an X-Context-Attestation header is present, verify it (its app_id must match the actor token's app_id) → 403 on any failure; if absent, allow only when IIOS_REQUIRE_ATTESTATION != 1 (dev/zero-trust), else 403. The flag is read per-request and defaults OFF, so existing callers keep working until AppShell/ be-crm start forwarding attestations. - AttestationModule (@Global): provides the verifier + Prisma stores + guard, and dev-seeds the crm-support-widget client so locally minted attestations verify. - Guard applied to ThreadsController + SupportController. - Tests (5 pass, no DB): not-required-allows, required-rejects, valid, forged, replayed. Workload/mTLS (proof #2) stays a mesh concern. Next: SDK header passthrough + demote be-crm IiosClient to forward an attestation, then flip the flag to prove end-to-end. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -9,13 +9,16 @@ import {
|
||||
Param,
|
||||
Post,
|
||||
Query,
|
||||
UseGuards,
|
||||
} from '@nestjs/common';
|
||||
import { ThreadsService } from './threads.service';
|
||||
import { MessageService } from '../messaging/message.service';
|
||||
import { SessionVerifier } from '../platform/session.verifier';
|
||||
import { ContextAttestationGuard } from '../platform/context-attestation.guard';
|
||||
import { SendMessageDto } from './send-message.dto';
|
||||
|
||||
@Controller('v1/threads')
|
||||
@UseGuards(ContextAttestationGuard)
|
||||
export class ThreadsController {
|
||||
constructor(
|
||||
private readonly threads: ThreadsService,
|
||||
|
||||
Reference in New Issue
Block a user