Skip to content

[CT-802] Enforce receipts at the Edict or Boundary adapter #96

Description

@flyingrobots

ADR-THINK-001 · Delivery plan · Complete issue catalog

Milestone: ADR-THINK-001 P8 — Action bridge and production cutover

Feature: F8.1 — Bounded action authorization

Outcome

The external-action adapter validates a receipt and executes only its named operation and bounded parameters, with no ambient capability or semantic fallback.

User stories

  • As a Think user, I want external effects limited to exactly what I or policy authorized, so that a safe plan cannot expand during transport or execution.
  • As a Edict or Boundary maintainer, I want a narrow versioned adapter contract, so that Think semantics do not leak into the general action runtime.

Deliverables

  • Versioned Think-to-Edict or Think-to-Boundary adapter port.
  • Pre-execution validation for signer, operation, parameters, frontier, expiry, revocation, access, and replay.
  • Execution receipt linking the authorization, exact request, bounded result, and external idempotency key.
  • No-op simulator and deny-by-default adapter for unsupported operations.

Acceptance criteria

  • The executor performs only the operation and parameters explicitly granted by a valid receipt.
  • Unsupported, widened, expired, revoked, replayed, or access-mismatched requests fail before an external effect.
  • Execution produces an immutable receipt whether the bounded operation succeeds or returns a typed failure.
  • The adapter never asks an LLM to reinterpret authorization at execution time.

Test plan

Contract and unit

  • Adapter tests cover every validation axis, idempotency, supported operation, result, and typed failure.

Integration and acceptance

  • The no-op simulator executes an authorized dojo-derived action and records linked authorization/execution receipts.

Failure and recovery

  • Parameter widening, operation substitution, replay, revocation race, timeout, provider ambiguity, and partial external failure fail safely.

Resource and performance

  • Validation, connection pools, retries, concurrency, result size, and provider calls obey receipt and runtime bounds.

Security, privacy, and erasure

  • Signer verification, confused-deputy, tenant/view isolation, payload redaction, and credential handling pass threat fixtures.

Build-time resources

Resource Exclusivity mode Scope
think-edict-adapter-contract exclusive Versioned port and receipt mapping.
external-action-simulator exclusive Deterministic no-op effect boundary.
external-operation-lanes partitioned Disjoint operation type and provider partitions.
action-idempotency-ledger exclusive Replay prevention per authorization.
authorization-history shared Read-only validated receipts and revocations.
  • exclusive: Only one active slice may mutate or lease the named resource.
  • partitioned: Concurrent writes are lawful only in disjoint partitions named by each slice.
  • shared: Concurrent read-only use is lawful; this slice does not mutate the resource.

Dependencies

ADR traceability

  • Implementation gates: None directly
  • Constitutional invariants: I3, I9, I10, I13
  • ADR acceptance criteria: AC33, AC34

Non-goals

  • Do not grant the adapter general access to Think canonical state.
  • Do not treat a provider success response as proof the action was semantically wise.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions