feat: scaffold encryption capability boundaries
This commit is contained in:
@@ -0,0 +1,142 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from govoplan_core.core.modules import (
|
||||
DocumentationTopic,
|
||||
ModuleInterfaceProvider,
|
||||
ModuleManifest,
|
||||
PermissionDefinition,
|
||||
RoleTemplate,
|
||||
)
|
||||
|
||||
|
||||
MODULE_ID = "encryption"
|
||||
MODULE_NAME = "Encryption"
|
||||
MODULE_VERSION = "0.1.14"
|
||||
|
||||
USE_SCOPE = "encryption:vault:use"
|
||||
ADMIN_SCOPE = "encryption:vault:admin"
|
||||
RECOVERY_SCOPE = "encryption:recovery:approve"
|
||||
|
||||
OPTIONAL_DEPENDENCIES = (
|
||||
"access",
|
||||
"audit",
|
||||
"policy",
|
||||
"notifications",
|
||||
"files",
|
||||
"postbox",
|
||||
"campaigns",
|
||||
"workflow",
|
||||
)
|
||||
|
||||
|
||||
def _permission(
|
||||
scope: str,
|
||||
label: str,
|
||||
description: str,
|
||||
) -> PermissionDefinition:
|
||||
module_id, resource, action = scope.split(":", 2)
|
||||
return PermissionDefinition(
|
||||
scope=scope,
|
||||
label=label,
|
||||
description=description,
|
||||
category="Encryption",
|
||||
level="tenant",
|
||||
module_id=module_id,
|
||||
resource=resource,
|
||||
action=action,
|
||||
)
|
||||
|
||||
|
||||
PERMISSIONS = (
|
||||
_permission(
|
||||
USE_SCOPE,
|
||||
"Use encryption profiles",
|
||||
"Protect and decrypt authorized content through an available profile.",
|
||||
),
|
||||
_permission(
|
||||
ADMIN_SCOPE,
|
||||
"Administer encryption",
|
||||
"Manage vaults, protection profiles, key rotation, and provider policy.",
|
||||
),
|
||||
_permission(
|
||||
RECOVERY_SCOPE,
|
||||
"Approve key recovery",
|
||||
"Participate in an auditable recovery ceremony without gaining content ownership.",
|
||||
),
|
||||
)
|
||||
|
||||
ROLE_TEMPLATES = (
|
||||
RoleTemplate(
|
||||
slug="encryption_user",
|
||||
name="Encryption user",
|
||||
description="Use configured content-protection profiles.",
|
||||
permissions=(USE_SCOPE,),
|
||||
),
|
||||
RoleTemplate(
|
||||
slug="encryption_custodian",
|
||||
name="Encryption custodian",
|
||||
description="Administer encryption and participate in key recovery.",
|
||||
permissions=(USE_SCOPE, ADMIN_SCOPE, RECOVERY_SCOPE),
|
||||
),
|
||||
)
|
||||
|
||||
manifest = ModuleManifest(
|
||||
id=MODULE_ID,
|
||||
name=MODULE_NAME,
|
||||
version=MODULE_VERSION,
|
||||
optional_dependencies=OPTIONAL_DEPENDENCIES,
|
||||
provides_interfaces=(
|
||||
ModuleInterfaceProvider(name="encryption.key_vault", version="1.0.0"),
|
||||
ModuleInterfaceProvider(
|
||||
name="encryption.content_protection",
|
||||
version="1.0.0",
|
||||
),
|
||||
ModuleInterfaceProvider(
|
||||
name="encryption.recovery_ceremony",
|
||||
version="1.0.0",
|
||||
),
|
||||
ModuleInterfaceProvider(
|
||||
name="encryption.disable_preflight",
|
||||
version="1.0.0",
|
||||
),
|
||||
),
|
||||
permissions=PERMISSIONS,
|
||||
role_templates=ROLE_TEMPLATES,
|
||||
documentation=(
|
||||
DocumentationTopic(
|
||||
id="encryption.boundary",
|
||||
title="Encryption and key-custody boundary",
|
||||
summary=(
|
||||
"Optional vault, content-protection, rotation, recovery, and "
|
||||
"disable-assurance capabilities."
|
||||
),
|
||||
body=(
|
||||
"Encryption protects feature-owned content without taking over "
|
||||
"its business ownership. Resource ownership recovery never "
|
||||
"implicitly grants cryptographic keys. Disabling the module is "
|
||||
"blocked until protected objects are decrypted, rewrapped, "
|
||||
"explicitly exported, or cryptographically deleted."
|
||||
),
|
||||
layer="available",
|
||||
documentation_types=("admin",),
|
||||
audience=("administrator", "security_officer", "product_owner"),
|
||||
related_modules=OPTIONAL_DEPENDENCIES,
|
||||
order=100,
|
||||
),
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def get_manifest() -> ModuleManifest:
|
||||
return manifest
|
||||
|
||||
|
||||
__all__ = [
|
||||
"ADMIN_SCOPE",
|
||||
"MODULE_ID",
|
||||
"MODULE_VERSION",
|
||||
"RECOVERY_SCOPE",
|
||||
"USE_SCOPE",
|
||||
"get_manifest",
|
||||
"manifest",
|
||||
]
|
||||
Reference in New Issue
Block a user