mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-08-14 06:47:28 +00:00
New @logicsrc/plugin-credential-sharing: a provider-neutral secret-sync engine with env/.env, Doppler, Railway, and GitHub Secrets adapters behind one CredentialProvider contract. - engine: inspect -> diff -> plan -> approve -> sync -> rollback -> audit/export - dry-run is the default for sync; --approve writes; destructive changes gated - fingerprint-based diffs (salted SHA-256); raw values never printed or stored in plans/runs/audit; rollback pre-image kept in a 0600 .logicsrc vault (gitignored) - github-secrets is write-only for values (sealed-box via libsodium), so it cannot be a sync source or value-restoring rollback target - CLI: real `logicsrc credentials <providers|inspect|diff|plan|approve|sync| rollback|audit|export>` (replaces the prior stub) - 4 JSON schemas registered in @logicsrc/validators - flip logicsrc.com/credential-sharing band from coming-soon to available - 37 tests pass; full env->env lifecycle verified; artifacts schema-validate Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
32 lines
1.3 KiB
JSON
32 lines
1.3 KiB
JSON
{
|
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
"$id": "https://schemas.logicsrc.com/logicsrc-credential-audit-event.schema.json",
|
|
"title": "LogicSRC Credential Audit Event",
|
|
"type": "object",
|
|
"required": ["type", "id", "provider", "action", "key", "target", "principal", "decision", "dryRun", "createdAt"],
|
|
"additionalProperties": false,
|
|
"properties": {
|
|
"type": { "const": "logicsrc.credential_audit_event" },
|
|
"id": { "type": "string", "minLength": 1 },
|
|
"runId": { "type": "string", "minLength": 1 },
|
|
"planId": { "type": "string", "minLength": 1 },
|
|
"provider": { "type": "string", "pattern": "^[a-z][a-z0-9-]*$" },
|
|
"action": { "type": "string", "pattern": "^[a-z][a-z0-9_-]*(:[a-z][a-z0-9_-]*)+$" },
|
|
"key": { "type": "string", "minLength": 1 },
|
|
"target": { "type": "string", "minLength": 1 },
|
|
"fingerprint": { "type": "string" },
|
|
"principal": {
|
|
"type": "object",
|
|
"required": ["type", "id"],
|
|
"additionalProperties": false,
|
|
"properties": {
|
|
"type": { "enum": ["user", "agent", "workflow", "plugin"] },
|
|
"id": { "type": "string", "minLength": 1 },
|
|
"trusted": { "type": "boolean" }
|
|
}
|
|
},
|
|
"decision": { "enum": ["allow", "approval_required", "deny"] },
|
|
"dryRun": { "type": "boolean" },
|
|
"createdAt": { "type": "string", "format": "date-time" }
|
|
}
|
|
}
|