NAME

Airlock::Policy - Decide which factors an Airlock approval needs

VERSION

version 0.001

SYNOPSIS

my $policy = Airlock::Policy->new(
  always       => ['upstream'],
  step_up      => { admin => ['totp'] },
  max_auth_age => 300,
);

DESCRIPTION

Maps a request and the approving subject to the names of the factors that have to verify before the approval counts. Declarative for the usual case, a coderef for everything else.

always

Factor names required for every approval.

step_up

Hash of scope to factor names. A request asking for that scope needs those factors.

max_auth_age

Optional. Seconds since the subject's auth_time after which no approval is accepted at all. A subject without auth_time then counts as too old.

decide

Optional. Coderef called with the request view, the subject and the list the declarative rules produced; returns the list to use.

clock_skew

Seconds an auth_time may lie in the future before it is taken for wrong rather than for clock drift. 60.

required

my $names = $policy->required( $view, $subject );

The factor names this approval needs, without duplicates, in a stable order.

fresh

$policy->fresh( $subject, time ) or return;

True when the subject's authentication is recent enough to approve anything.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-airlock/issues.

IRC

Join #kubernetes on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <getty@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.