feat(doors): role policy and audit for door commands #72
Labels
No labels
blocked
bug
enhancement
high-priority
low-priority
needs-info
needs-triage
ready-for-agent
ready-for-human
referenced
research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
gabogg/hikcentral#72
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
POST /api/doors/{door_index_code}/control(app/controllers/door_controller.py:77) sends a door command to HikCentral throughDoorStateManager.control_door_async(app/services/door_service.py:1418). Commands areunlock,open,close,remain_open,remain_closedandrestore(DoorControlRequest,app/schemas/models.py:287). The route only requiresrequire_auth, so any logged-in operator can hold any door open indefinitely (remain_open). Nothing records who issued a command, and a command that changes nothing, or that HikCentral rejects, leaves no trace:door_hardware_state_transitionsonly records state changes.Door control is expected to grow (follow-up capabilities for opening doors through the system), so the role policy and audit trail should exist before it does.
Settled scope
open,unlock,close,restore): operators and admins.remain_open,remain_closed), which leave a door in that state until someone reverses it: admins only. Operators get 403 with the existingFORBIDDEN_ADMINerror code.door_commandstable recording, for every attempt: timestamp, the user, the door, the command, the outcome (ACCEPTED,REJECTEDby policy,FAILEDupstream) and the error message. Written through the door repository; pruned at 365 days by the existing retention job. Refused and failed attempts are recorded too.CONTEXT.md(one-shot vs persistent), in this issue's PR.Acceptance criteria
FORBIDDEN_ADMINfor operators and succeed for admins (tests for both roles).door_commandsrow with the user and outcome (tests for each outcome, with Artemis mocked).door_commandscreated viaCREATE TABLE IF NOT EXISTS, included in retention pruning.CONTEXT.mddefines Door Command (one-shot vs persistent).node --test).Related: #64.