Skip to content

[Access] Scoped Authorization Grant - #48

Merged
ericnordelo merged 12 commits into
mainfrom
feat/scoped-authorization-grant
Sep 30, 2026
Merged

ericnordelo merged 12 commits into
mainfrom
feat/scoped-authorization-grant

Conversation

@ericnordelo

@ericnordelo ericnordelo commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Adds ScopedAuthorizationGrantV1 as a reusable access-control component. Applications can issue revocable, time-bounded grants and validate the caller, authority, and resource scope before executing protected choices. Includes optional contract-ID binding, structured errors, and usage events.

Includes licensing and treasury integration examples, isolated tests, and integration documentation. The treasury example demonstrates role-based access control built on the generic grant model. Removes the old AccessControl and Ownable experiments.

@pepebndc pepebndc left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

An independent two-model review (Claude and Codex) of this PR at a49fd3f. Neither reviewer found a critical, high, or medium defect. The guard enforces authority, grantee, scope, revocation, ledger-time bounds, and contract-ID binding, and both examples use it correctly.

The inline comments cover the three low findings and the missing tests. #50 targets this branch and applies those, plus nine info-level documentation fixes, one commit per finding.

Comment thread packages/access/scoped-authorization-grant-v1/README.md
Comment thread packages/access/scoped-authorization-grant-v1/README.md Outdated
Comment thread packages/access/scoped-authorization-grant-v1/README.md Outdated
Comment thread test/scoped-authorization-grant-v1-test/README.md Outdated

@igingu igingu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@ericnordelo nicely done, I like the simplicity! I left three ideas.

@ericnordelo
ericnordelo requested a review from igingu September 28, 2026 15:50

@pepebndc pepebndc left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@0xNeshi 0xNeshi left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good job

Asked for #48 (comment), but approving in advance

@ericnordelo
ericnordelo requested a review from igingu September 29, 2026 22:31

@igingu igingu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the great work!

@ericnordelo
ericnordelo merged commit aeca01d into main Sep 30, 2026
9 checks passed
@ericnordelo
ericnordelo deleted the feat/scoped-authorization-grant branch September 30, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[M2] Library — Roles Based Access Control

4 participants