feat: add claims and audit - #430
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Secrets | Sep 30, 2026 2:33p.m. | Review ↗ | |
| Python | Sep 30, 2026 2:33p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The export omits older checkpoints, and several prerequisites and token constraints are documented inconsistently.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Adds delegated-token claim support to AuthZEN/CIQ and introduces synchronous and asynchronous Audit Log clients.
Changes:
- Adds
X-IK-Tokenforwarding for policy claims. - Adds paginated audit logs, manifests, checkpoints, and JWKS APIs.
- Adds tests, documentation, examples, permissions, and exports.
| File | Description |
|---|---|
tests/unit/test_parity.py |
Adds Audit client parity checks. |
tests/unit/ciq/test_ciq.py |
Tests delegated-token forwarding. |
tests/unit/authzen/test_authzen.py |
Tests delegated-token behavior. |
tests/unit/audit/test_audit.py |
Tests Audit client operations. |
tests/unit/audit/__init__.py |
Defines the audit test package. |
tests/integration/test_audit.py |
Adds live Audit API tests. |
tests/integration/conftest.py |
Adds the Audit client fixture. |
README.md |
Documents claims and audit usage. |
Pipfile.lock |
Updates development dependencies. |
indykite_sdk/config/models/core.py |
Adds the Audit permission type. |
indykite_sdk/config/client.py |
Documents Audit agent permissions. |
indykite_sdk/ciq/client.py |
Adds synchronous delegated tokens. |
indykite_sdk/ciq/aio.py |
Adds asynchronous delegated tokens. |
indykite_sdk/authzen/models.py |
Documents reserved claim parameters. |
indykite_sdk/authzen/client.py |
Adds synchronous delegated tokens. |
indykite_sdk/authzen/aio.py |
Adds asynchronous delegated tokens. |
indykite_sdk/authzen/_ops.py |
Builds delegated-token headers. |
indykite_sdk/audit/models.py |
Defines Audit response models. |
indykite_sdk/audit/client.py |
Implements the synchronous client. |
indykite_sdk/audit/aio.py |
Implements the asynchronous client. |
indykite_sdk/audit/_ops.py |
Builds Audit requests and pagination. |
indykite_sdk/audit/__init__.py |
Exports the Audit API package. |
indykite_sdk/_core/ops.py |
Adds X-IK-Token header support. |
indykite_sdk/_core/errors_map.py |
Improves permission error guidance. |
indykite_sdk/__init__.py |
Exports both Audit clients. |
examples/audit_logs.py |
Adds an audit export example. |
.github/workflows/docs.yaml |
Publishes Audit API documentation. |
.github/PULL_REQUEST_TEMPLATE.md |
Lists AuditClient as affected client. |
.github/ISSUE_TEMPLATE/bug-report.md |
Adds AuditClient to bug reports. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
implement [ENG-9616]
077f0ad to
a0a17d7
Compare


implement ENG-9616
Checklist
pipenv run pytestpassespre-commit run --all-filespassesAffected client(s)
Description of change
add claims and audit