Today: network grants are keyed as net:{host} only (approval_cache.rs:~81-125, parse_host :~390). Scheme and port are dropped, so an approval for one port or protocol covers every other one on that host. NetworkSessionCache is a third, separate store, and its approve and deny methods have no production callers.
Change
-
Parse the full target. parse_net_target returns a NetKey:
- host: lowercase, normalized to IDNA
- protocol: http, https, ws or wss
- port: the explicit port, or the scheme default
The grouping key becomes net:{proto}://{host}:{port}. An unparseable URL gets its own digest.
-
One store. Conversation-scope grants and denies go into A1's GrantStore. Delete NetworkSessionCache and its unused methods. NetworkPolicyDecider::evaluate checks GrantStore first; a deny still wins.
-
Repo scope and "Don't allow this host". Persist these as existing-schema rules: ToolAskRule{tool:"network", command:"https://host:443", workspace, action}. Older binaries parse them and treat them as inert. Relax the Deny bail in persist_rules_from_approval for tool=="network" only.
-
Card choices. Use the four §19 choices. "Don't allow" offers two versions: this time, or always for this host in this repo.
Tests
net_grant_keyed_by_protocol_and_port
network_repo_deny_beats_conversation_allow
network_rule_toml_parses_with_old_schema
- a compile-time guard that
NetworkSessionCache is removed
- oauth tests moved onto
GrantStore
Size: M. Blocked by: A1. Spec: codewhale-ops approvals/specs/A-grants-authority-0.11.md (A3).
Today: network grants are keyed as
net:{host}only (approval_cache.rs:~81-125,parse_host:~390). Scheme and port are dropped, so an approval for one port or protocol covers every other one on that host.NetworkSessionCacheis a third, separate store, and its approve and deny methods have no production callers.Change
Parse the full target.
parse_net_targetreturns aNetKey:The grouping key becomes
net:{proto}://{host}:{port}. An unparseable URL gets its own digest.One store. Conversation-scope grants and denies go into A1's
GrantStore. DeleteNetworkSessionCacheand its unused methods.NetworkPolicyDecider::evaluatechecksGrantStorefirst; a deny still wins.Repo scope and "Don't allow this host". Persist these as existing-schema rules:
ToolAskRule{tool:"network", command:"https://host:443", workspace, action}. Older binaries parse them and treat them as inert. Relax the Deny bail inpersist_rules_from_approvalfortool=="network"only.Card choices. Use the four §19 choices. "Don't allow" offers two versions: this time, or always for this host in this repo.
Tests
net_grant_keyed_by_protocol_and_portnetwork_repo_deny_beats_conversation_allownetwork_rule_toml_parses_with_old_schemaNetworkSessionCacheis removedGrantStoreSize: M. Blocked by: A1. Spec: codewhale-ops
approvals/specs/A-grants-authority-0.11.md(A3).