Files
git.stella-ops.org/src/Policy/StellaOps.Policy.Engine
master b55d9fa68d
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Add comprehensive security tests for OWASP A03 (Injection) and A10 (SSRF)
- Implemented InjectionTests.cs to cover various injection vulnerabilities including SQL, NoSQL, Command, LDAP, and XPath injections.
- Created SsrfTests.cs to test for Server-Side Request Forgery (SSRF) vulnerabilities, including internal URL access, cloud metadata access, and URL allowlist bypass attempts.
- Introduced MaliciousPayloads.cs to store a collection of malicious payloads for testing various security vulnerabilities.
- Added SecurityAssertions.cs for common security-specific assertion helpers.
- Established SecurityTestBase.cs as a base class for security tests, providing common infrastructure and mocking utilities.
- Configured the test project StellaOps.Security.Tests.csproj with necessary dependencies for testing.
2025-12-16 13:11:57 +02:00
..
up
2025-11-24 07:52:25 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-12-03 00:10:19 +02:00
up
2025-12-13 09:37:15 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-12-14 15:50:38 +02:00
up
2025-11-27 23:45:09 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-12-13 02:22:15 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-12-01 21:16:22 +02:00
up
2025-12-13 02:22:15 +02:00
up
2025-12-13 09:37:15 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-11-28 00:45:16 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-11-27 23:45:09 +02:00
up
2025-12-12 09:35:37 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-12-14 15:50:38 +02:00
up
2025-12-13 02:22:15 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-12-12 09:35:37 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-12-14 15:50:38 +02:00
up
2025-12-13 09:37:15 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-11-24 07:52:25 +02:00
up
2025-11-28 09:41:08 +02:00
up
2025-12-13 00:20:26 +02:00
up
2025-12-12 09:35:37 +02:00
up
2025-12-14 15:50:38 +02:00
up
2025-12-12 09:35:37 +02:00
up
2025-12-14 23:20:14 +02:00

Policy Engine Host Template

This service hosts the Policy Engine APIs and background workers introduced in Policy Engine v2. The project currently ships a minimal bootstrap that validates configuration, registers Authority clients, and exposes readiness/health endpoints. Future tasks will extend it with compilation, evaluation, and persistence features.

Compliance Checklist

  • Configuration loads from policy-engine.yaml/environment variables and validates on startup.
  • Authority client scaffolding enforces policy:* + effective:write scopes and respects back-channel timeouts.
  • Resource server authentication requires Policy Engine scopes with tenant-aware policies.
  • Health and readiness endpoints exist for platform probes.
  • Deterministic policy evaluation pipeline implemented (POLICY-ENGINE-20-002).
  • PostgreSQL materialisation writers implemented (POLICY-ENGINE-20-004).
  • Observability (metrics/traces/logs) completed (POLICY-ENGINE-20-007).
  • Comprehensive test suites and perf baselines established (POLICY-ENGINE-20-008).