Skip to content

Authorize snowdeploy actions per token: converge-only tokens cannot deploy or rollback - #4

Merged
SnowballSH merged 2 commits into
mainfrom
snowdeploy-converge-scope
Sep 8, 2026
Merged

SnowballSH merged 2 commits into
mainfrom
snowdeploy-converge-scope

Conversation

@SnowballSH

Copy link
Copy Markdown
Owner

Authorize snowdeploy actions per token: converge-only tokens cannot deploy or rollback

A token hash line may end in a scope=<action>[,<action>] field; a scoped token gets 403 on any route outside its actions, an unscoped token is unchanged. Labels containing spaces keep working. The token file fails closed: a scope-like trailing field that is not exactly the grammar, or an unknown action name, is a configuration error at load, so a mistyped scope can never widen a token. README documents the format.

Motivation: the SnowSys agent-farm design (D040) grants the farm a converge-only bearer on deploy.; D035 requires the application, not the proxy, to authorize the action.

After merge (operator): release v0.1.9; SnowSys installs it through a new snowdeploy-phase11-5-v12 bundle and revision 20261146 (plan Task A11).

Verification: gofmt, go vet, go test ./... (new scope, label and fail-closed tests, proven red first), golangci-lint, go build; per-task Opus review, Fable whole-branch review, one fix wave.

@SnowballSH
SnowballSH merged commit 0773707 into main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant