You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[CT-802] Enforce receipts at the Edict or Boundary adapter #96
Milestone: ADR-THINK-001 P8 — Action bridge and production cutover
Feature: F8.1 — Bounded action authorization
Outcome
The external-action adapter validates a receipt and executes only its named operation and bounded parameters, with no ambient capability or semantic fallback.
User stories
As a Think user, I want external effects limited to exactly what I or policy authorized, so that a safe plan cannot expand during transport or execution.
As a Edict or Boundary maintainer, I want a narrow versioned adapter contract, so that Think semantics do not leak into the general action runtime.
Deliverables
Versioned Think-to-Edict or Think-to-Boundary adapter port.
Pre-execution validation for signer, operation, parameters, frontier, expiry, revocation, access, and replay.
Execution receipt linking the authorization, exact request, bounded result, and external idempotency key.
No-op simulator and deny-by-default adapter for unsupported operations.
Acceptance criteria
The executor performs only the operation and parameters explicitly granted by a valid receipt.
Unsupported, widened, expired, revoked, replayed, or access-mismatched requests fail before an external effect.
Execution produces an immutable receipt whether the bounded operation succeeds or returns a typed failure.
The adapter never asks an LLM to reinterpret authorization at execution time.
Test plan
Contract and unit
Adapter tests cover every validation axis, idempotency, supported operation, result, and typed failure.
Integration and acceptance
The no-op simulator executes an authorized dojo-derived action and records linked authorization/execution receipts.
ADR-THINK-001 · Delivery plan · Complete issue catalog
Milestone: ADR-THINK-001 P8 — Action bridge and production cutover
Feature: F8.1 — Bounded action authorization
Outcome
The external-action adapter validates a receipt and executes only its named operation and bounded parameters, with no ambient capability or semantic fallback.
User stories
Deliverables
Acceptance criteria
Test plan
Contract and unit
Integration and acceptance
Failure and recovery
Resource and performance
Security, privacy, and erasure
Build-time resources
think-edict-adapter-contractexternal-action-simulatorexternal-operation-lanesaction-idempotency-ledgerauthorization-historyDependencies
ADR traceability
I3,I9,I10,I13AC33,AC34Non-goals