Repository navigation
[Access] Scoped Authorization Grant - #48
Conversation
pepebndc
left a comment
There was a problem hiding this comment.
An independent two-model review (Claude and Codex) of this PR at a49fd3f. Neither reviewer found a critical, high, or medium defect. The guard enforces authority, grantee, scope, revocation, ledger-time bounds, and contract-ID binding, and both examples use it correctly.
The inline comments cover the three low findings and the missing tests. #50 targets this branch and applies those, plus nine info-level documentation fixes, one commit per finding.
igingu
left a comment
There was a problem hiding this comment.
@ericnordelo nicely done, I like the simplicity! I left three ideas.
…feat/scoped-authorization-grant
There was a problem hiding this comment.
Good job
Asked for #48 (comment), but approving in advance
igingu
left a comment
There was a problem hiding this comment.
Thanks for the great work!
Adds ScopedAuthorizationGrantV1 as a reusable access-control component. Applications can issue revocable, time-bounded grants and validate the caller, authority, and resource scope before executing protected choices. Includes optional contract-ID binding, structured errors, and usage events.
Includes licensing and treasury integration examples, isolated tests, and integration documentation. The treasury example demonstrates role-based access control built on the generic grant model. Removes the old AccessControl and Ownable experiments.