Add the compliance permission and the Compliance Officer roles
ci / fork-checks (pull_request) Successful in 31s
ci / build (pull_request) Successful in 11m31s

Personal-data catalog spec, §7 (settled 2026-09-28).

sysComplianceGet (673) sees the data inventory and compliance
overview: superusers and, for their tenant's slice, tenant
administrators, by default and through the one-time grants on servers
that already have their roles stored.

A Compliance Officer role at server level holds it with reading and
exporting the audit log, placing, widening, releasing and exporting
legal holds, seeing account locks, and reading accounts, lists,
domains, tenants and roles. It changes no server setting, creates or
deletes no account, and can't shorten audit retention.

A tenant's accounts can hold only roles of their own tenant (MT-3), so
the tenant role is one "Compliance Officer" role per tenant, without
holds (LH-13): made once for every tenant a server has, and whenever a
tenant is created. While nobody holds it, it is removed with its tenant
so it doesn't block the delete, and put back if the delete is refused
for another reason. Both roles carry a user's own permissions too,
since roles given to a person replace the default user role, which a
tenant's accounts can't hold anyway.

Every server makes these once, new or existing -- the built-in roles
are only made on a server with none -- and records each under P c, so a
role an administrator deletes stays deleted.

Tested: unit tests (neither role changes a setting beyond a user's
own; holds for the server's officer only; per-place records); a new
compliance system test (one server-level role; an officer reads the
audit log, places and releases a hold, and is refused a setting, an
account and audit retention; a tenant gets its role, whose holder reads
the tenant's audit log and no holds; a tenant with an unused role is
deleted and the role goes with it); the system, audit, legal hold,
account lock and SCIM suites; fork checks. The directory suite needs
its LDAP container and wasn't run here.
This commit is contained in:
2026-09-28 08:50:17 -07:00
parent d107c1b2bb
commit 63adb4e2b8
13 changed files with 548 additions and 5 deletions
+6
View File
@@ -290,6 +290,12 @@ impl Default for DefaultPermissions {
default.superuser.push(permission);
default.tenant.push(permission);
}
// inbuxa: personal-data catalog: the data inventory, the
// server's or, inside a tenant, the tenant's slice
Permission::SysComplianceGet => {
default.superuser.push(permission);
default.tenant.push(permission);
}
// inbuxa: AL-12: tenant administrators lock and delegate
// within their tenant
Permission::SysAccountLockGet
@@ -0,0 +1,267 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The compliance roles (personal-data catalog spec, §7; settled
//! 2026-09-28): a server-level Compliance Officer, and one Compliance
//! Officer role in each tenant. A tenant's accounts can hold only roles of
//! their own tenant (MT-3), so the tenant role is made per tenant: once for
//! each tenant a server already has, and whenever a tenant is created.
//!
//! Each creation is recorded under `P` `c` in the fork's subspace, so a
//! role an administrator deletes stays deleted. A tenant's role, while
//! nobody holds it, is removed with the tenant so it doesn't block the
//! delete.
//!
//! Both read what compliance work needs and change no server setting. The
//! server-level officer also places, widens, releases and exports legal
//! holds: that is the job, and each is audited with its reason. A tenant's
//! role has no holds, which are server-level only (LH-13), and the tenant
//! ceiling keeps it within the tenant. Each role carries a user's own
//! permissions too (signing in, mail), since roles given to a person replace
//! the default user role, and a tenant's accounts can't hold the
//! server-level User role.
use registry::schema::{
enums::Permission,
prelude::ObjectType,
structs::{Role, Tenant},
};
use registry::types::map::Map;
use store::{
RegistryStore, SUBSPACE_INBUXA, Store, ValueKey,
registry::write::{RegistryWrite, RegistryWriteResult},
write::{AnyClass, BatchBuilder, ValueClass},
};
use trc::AddContext;
use types::id::Id;
/// The role's name, in the server's roles and in each tenant's.
pub const NAME: &str = "Compliance Officer";
/// Reading who and what records refer to, for both roles.
const READS: &[Permission] = &[
Permission::SysAccountGet,
Permission::SysAccountQuery,
Permission::SysMailingListGet,
Permission::SysMailingListQuery,
Permission::SysDomainGet,
Permission::SysDomainQuery,
Permission::SysTenantGet,
Permission::SysTenantQuery,
Permission::SysRoleGet,
Permission::SysRoleQuery,
];
/// What the server-level officer holds besides [`READS`].
const OFFICER: &[Permission] = &[
Permission::SysComplianceGet,
Permission::SysAuditGet,
Permission::SysAuditExport,
Permission::SysLegalHoldGet,
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
Permission::SysAccountLockGet,
];
/// What a tenant's officer holds besides [`READS`].
const TENANT_OFFICER: &[Permission] = &[
Permission::SysComplianceGet,
Permission::SysAuditGet,
Permission::SysAuditExport,
Permission::SysAccountLockGet,
];
fn role(own: &[Permission], tenant: Option<Id>) -> Role {
let mut permissions = crate::auth::permissions::DefaultPermissions::default().user;
for permission in own.iter().chain(READS) {
if !permissions.contains(permission) {
permissions.push(*permission);
}
}
Role {
description: NAME.into(),
enabled_permissions: Map::new(permissions),
member_tenant_id: tenant,
..Default::default()
}
}
/// The server-level Compliance Officer role.
pub fn officer_role() -> Role {
role(OFFICER, None)
}
/// A tenant's Compliance Officer role.
pub fn tenant_role(tenant: Id) -> Role {
role(TENANT_OFFICER, Some(tenant))
}
/// Where a creation is recorded: the server's role, or a tenant's. The value
/// is the role's id.
fn created_key(tenant: Option<Id>) -> ValueClass {
let mut key = b"Pc".to_vec();
if let Some(tenant) = tenant {
key.extend_from_slice(&tenant.id().to_be_bytes());
}
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
async fn recorded(data: &Store, tenant: Option<Id>) -> trc::Result<Option<Id>> {
Ok(data
.get_value::<u64>(ValueKey::from(created_key(tenant)))
.await
.caused_by(trc::location!())?
.map(Id::from))
}
async fn record(data: &Store, tenant: Option<Id>, role: Option<Id>) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
match role {
Some(role) => batch.set(created_key(tenant), role.id().to_be_bytes().to_vec()),
None => batch.clear(created_key(tenant)),
};
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// Creates a role, unless one was created for this place before, and records
/// it. Returns the new role's id.
async fn create_once(
registry: &RegistryStore,
data: &Store,
tenant: Option<Id>,
role: Role,
) -> trc::Result<Option<Id>> {
if recorded(data, tenant).await?.is_some() {
return Ok(None);
}
match registry.write(RegistryWrite::insert(&role.into())).await? {
RegistryWriteResult::Success(id) => {
record(data, tenant, Some(id)).await?;
Ok(Some(id))
}
err => {
trc::error!(
trc::EventType::Registry(trc::RegistryEvent::ValidationError)
.into_err()
.details(format!("Failed to create the {NAME} role: {err}"))
);
Ok(None)
}
}
}
/// Once per server: the officer role, and one in each tenant it already has.
pub async fn ensure_compliance_roles(registry: &RegistryStore, data: &Store) -> trc::Result<()> {
create_once(registry, data, None, officer_role()).await?;
for tenant in registry.list::<Tenant>().await? {
let tenant = Id::from(tenant.id.id());
create_once(registry, data, Some(tenant), tenant_role(tenant)).await?;
}
Ok(())
}
/// A new tenant gets its Compliance Officer role.
pub async fn tenant_created(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<()> {
create_once(registry, data, Some(tenant), tenant_role(tenant)).await.map(|_| ())
}
/// Before a tenant is deleted: removes its Compliance Officer role if nobody
/// holds it, so the role doesn't block the delete. Returns whether it did,
/// so a delete refused for another reason can put it back.
pub async fn tenant_deleting(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<bool> {
let Some(role) = recorded(data, Some(tenant)).await? else {
return Ok(false);
};
match registry
.write(RegistryWrite::delete(ObjectType::Role.id(role)))
.await?
{
RegistryWriteResult::Success(_) | RegistryWriteResult::NotFound { .. } => {
record(data, Some(tenant), None).await?;
Ok(true)
}
// Held by someone: the tenant's delete is refused for that anyway
_ => Ok(false),
}
}
/// A tenant's delete was refused after its role went: the role comes back.
pub async fn tenant_kept(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<()> {
tenant_created(registry, data, tenant).await
}
#[cfg(test)]
mod tests {
use super::*;
use registry::types::EnumImpl;
fn permissions(role: &Role) -> Vec<Permission> {
role.enabled_permissions.iter().copied().collect()
}
#[test]
fn neither_role_changes_a_setting() {
let user = crate::auth::permissions::DefaultPermissions::default().user;
for role in [officer_role(), tenant_role(Id::from(7u64))] {
let all = permissions(&role);
for permission in user.iter() {
assert!(all.contains(permission), "a user's own {permission:?}");
}
// Beyond what any user holds for their own account
for permission in all.into_iter().filter(|p| !user.contains(p)) {
let name = permission.as_str();
let holds = name.starts_with("sysLegalHold");
assert!(
!(name.ends_with("Update") && !holds)
&& !(name.ends_with("Create") && !holds)
&& !name.ends_with("Destroy")
&& permission != Permission::Impersonate
&& permission != Permission::FetchAnyBlob,
"{} holds {name}",
role.description
);
}
}
}
#[test]
fn the_officer_places_and_releases_holds_a_tenants_does_not() {
let officer = permissions(&officer_role());
let tenant = tenant_role(Id::from(7u64));
assert_eq!(tenant.member_tenant_id, Some(Id::from(7u64)));
let tenant = permissions(&tenant);
for hold in [
Permission::SysLegalHoldGet,
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
] {
assert!(officer.contains(&hold));
assert!(!tenant.contains(&hold));
}
for both in [Permission::SysComplianceGet, Permission::SysAuditGet, Permission::SysAccountGet] {
assert!(officer.contains(&both) && tenant.contains(&both));
}
assert!(!officer.contains(&Permission::SysAuditSettingsUpdate));
}
#[test]
fn records_are_per_place() {
let ValueClass::Any(server) = created_key(None) else { panic!() };
let ValueClass::Any(a) = created_key(Some(Id::from(1u64))) else { panic!() };
let ValueClass::Any(b) = created_key(Some(Id::from(2u64))) else { panic!() };
assert_eq!(server.key, b"Pc");
assert_ne!(a.key, b.key);
assert!(a.key.starts_with(b"Pc"));
}
}
+2
View File
@@ -482,6 +482,8 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
// inbuxa: administrator roles stored before a permission existed get it once
super::granted_permissions::grant_new_admin_permissions(bp).await?;
// inbuxa: personal-data catalog: the compliance roles, once per server
super::compliance_roles::ensure_compliance_roles(&bp.registry, &bp.data_store).await?;
if bp
.registry
@@ -30,7 +30,8 @@ use types::id::Id;
/// Granted to the default administrator roles: "Explain this"
/// (ai-explain spec, EX-4: superuser by default), the audit log, account
/// locks and legal holds (audit-hold-lock spec, AU-9, AL-12, LH-13).
/// locks and legal holds (audit-hold-lock spec, AU-9, AL-12, LH-13), and
/// the data inventory (personal-data catalog spec).
const ADMIN_GRANTS: &[Permission] = &[
Permission::SysAiExplain,
Permission::SysAuditGet,
@@ -44,11 +45,12 @@ const ADMIN_GRANTS: &[Permission] = &[
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
Permission::SysComplianceGet,
];
/// Granted to the default tenant administrator roles: reading and exporting
/// the tenant's audit log (AU-9), and locking and delegating its accounts
/// (AL-12).
/// the tenant's audit log (AU-9), locking and delegating its accounts
/// (AL-12), and the tenant's slice of the data inventory.
const TENANT_GRANTS: &[Permission] = &[
Permission::SysAuditGet,
Permission::SysAuditExport,
@@ -56,6 +58,7 @@ const TENANT_GRANTS: &[Permission] = &[
Permission::SysAccountLockCreate,
Permission::SysAccountLockUpdate,
Permission::SysAccountLockDestroy,
Permission::SysComplianceGet,
];
#[derive(Clone, Copy, PartialEq, Eq)]
+1
View File
@@ -18,6 +18,7 @@ use utils::HttpLimitResponse;
pub mod application;
pub mod backup;
pub mod boot;
pub mod compliance_roles; // inbuxa: personal-data catalog, the compliance roles
pub mod console;
pub mod defaults;
pub mod first_party;