Intercept and authorize wasi:http calls - #10
Merged
Merged
Conversation
Closed
Access control for wasi:http, split between gates and latches, modeled on componentized/sockets. A gate wraps wasi:http/client or wasi:http/handler and consults a latch before each request, a latch decides whether the request may proceed. A latch defers or denies, a request proceeds unless a latch denies it. Gates: * gate-client: gates wasi:http/client * gate-handler: gates wasi:http/handler * gate: a union of both The componentized:http/latch interface separates deciding from acting on a decision. `authorize` decides without side effects, then the gate reports the final decision to `observe-decision`, where a latch updates any state it keeps. A denied request fails with the latch's reason and is logged as a warning, a latch error or failed observation fails the request with internal-error and is logged as an error. Latches: * latch-defer-all, latch-deny-all: blanket decisions * latch-method, latch-scheme: decide by the request method or scheme, configured with wasi:config/store * latch-method-readonly, latch-scheme-httpsonly: preconfigured, allow only reading methods or only https * latch-deny-random: randomly denies a fraction of requests, reproducible with a seed, for fault injection * latch-n2 to latch-n5: aggregate latches, any latch can deny, every latch observes the final decision * latch-delegate-client, latch-delegate-handler: apply a wrapped latch to only client or handler requests * latch-dry-run: logs what a wrapped latch would deny without enforcing it, to roll out a policy * latch-trace: logs the decisions of a wrapped latch Shared crates: * http-latch: bindings, logging, config loading and display helpers for latches. An invalid config is logged as critical and fails every request with invalid-config, so a typo is noticed rather than ignored * http-latch-n: aggregation for the latch-n components * http-utils: macros to format and parse wasi:http error codes, methods and schemes, expanded for each component's generated types. Tested against wit-bindgen types from the repository's own wit The test harness drives gates with requests created by the host, scripts a host latch, provides wasi:config/store, and composes latch components into the gate, aggregating several with latch-n. Signed-off-by: Scott Andrews <scott@andrews.me> Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Scott Andrews <scott@andrews.me>
Signed-off-by: Scott Andrews <scott@andrews.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The gate components virtualize the wasi:http interfaces allowing http client and handler calls to be intercepted and authorized before the call precedes. A latch interface is imported containing the authorization logic. Multiple latches can be combined using the latch-n components.
The latch-method component authorizes requests based on the HTTP request's method and a wasi:config object. The latch-method-readonly component is a configuration of latch-method that denies all methods except for those generally known not to cause side effects on a remote server.