Skip to content

feat: register provider_keys.manage permission for the gateway's /v1 proxy - #79

Merged
man4ish merged 1 commit into
mainfrom
feature/m15-provider-keys-registry-entry
Oct 4, 2026
Merged

man4ish merged 1 commit into
mainfrom
feature/m15-provider-keys-registry-entry

Conversation

@man4ish

@man4ish man4ish commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

Small, registry-only addition supporting the paired omnibioai-api-gateway PR that exposes M14's BYOK provider-key storage through the public /v1/provider-keys/{provider} surface.

  • Registers provider_keys.manage -- "reserved, not yet enforced by any route," the exact same posture usage.read already has (its own "first real consumer" was the gateway's GET /v1/usage proxy at M1).
  • The real authorization decision stays manage_org, enforced live by routes_organization_config.py's own require_org_permission_or_platform_admin dependency -- not this registry entry, and not any JWT permissions claim, since org-scoped permissions are never embedded in a token (they're resolved fresh per request against the caller's live membership).

Test plan

  • pytest tests/test_permission_registry.py tests/test_platform_permissions_api.py -- 65 passed, including the updated exact-registry-size assertions (32 -> 33) and by-scope totals (both: 17 -> 18)
  • Full repo suite -- 1487 passed, 2 skipped, 1 pre-existing flaky MFA concurrency-timing test (confirmed unrelated in the last two milestones)

🤖 Generated with Claude Code

…proxy

Reserved -- not yet enforced by any route, the same posture usage.read
already has: the real authorization decision for provider-key
management is manage_org, checked live by
routes_organization_config.py's own require_org_permission_or_
platform_admin dependency, not this registry entry or any JWT
permissions claim (org-scoped permissions are never embedded in a
token). This just gives omnibioai-api-gateway's new /v1/provider-keys
proxy a real, registered name to send as policy-engine context.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@man4ish
man4ish merged commit 86039f2 into main Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant