Skip to content

feat: add an Enterprise execution and receipt conformance adapter #48

Description

@AjnasNB

Goal

Define the adapter that lets Maqam Enterprise authorize a Cockroach Browser action/session, receive durable outcome evidence, and revoke future work without turning the Browser package into a hosted control plane.

Scope

  • Versioned tenant/project/session/action authority envelope.
  • Bind tool, origin, effects, budgets, artifact hashes, policy revision, approval ID, expiry, nonce, and revocation epoch.
  • Signed/replay-protected outcome webhook or pull receipt contract.
  • Connector health and compatibility snapshot for Enterprise Administration.
  • Cross-platform offline conformance fixtures.

Relationship to existing work

Compose #16, #15, #11, and #9 rather than duplicating them.

Acceptance criteria

  • Wrong tenant, altered action, expired approval, replay, and revoked session deny by default.
  • Evidence distinguishes proposed, dispatched, completed, denied, timed out, and indeterminate outcomes.
  • No cookies, profile secrets, or browser credentials enter the Enterprise receipt.
  • Schemas, TypeScript contracts, exports, docs, and clean-consumer tests agree.
  • Current Browser capabilities and existing actions remain intact.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions