Skip to content

feat: add claims and audit - #430

Merged
cowan-macady merged 1 commit into
masterfrom
claims-audit
Oct 1, 2026
Merged

cowan-macady merged 1 commit into
masterfrom
claims-audit

Conversation

@cowan-macady

@cowan-macady cowan-macady commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

implement ENG-9616

Checklist

  • pipenv run pytest passes
  • tests are included for new or changed behavior
  • pre-commit run --all-files passes
  • documentation (README, docstrings, examples) is changed or added

Affected client(s)

Description of change

add claims and audit

Copilot AI balanced review requested due to automatic review settings September 30, 2026 14:16
@cowan-macady
cowan-macady requested review from a team as code owners September 30, 2026 14:16
@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpylint@​4.0.8 ⏵ 4.1.19210010010070
Updatedruff@​0.16.8 ⏵ 0.16.9100 +1100100100100

View full report

@deepsource-io

deepsource-io Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 3abac28...a0a17d7 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Secrets Sep 30, 2026 2:33p.m. Review ↗
Python Sep 30, 2026 2:33p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The export omits older checkpoints, and several prerequisites and token constraints are documented inconsistently.

Review effort: Balanced
Findings: 1 Medium severity · 3 Low severity

Open (4)
What changed in this PR

Adds delegated-token claim support to AuthZEN/CIQ and introduces synchronous and asynchronous Audit Log clients.

Changes:

  • Adds X-IK-Token forwarding for policy claims.
  • Adds paginated audit logs, manifests, checkpoints, and JWKS APIs.
  • Adds tests, documentation, examples, permissions, and exports.
File Description
tests/​unit/​test_parity.py Adds Audit client parity checks.
tests/​unit/​ciq/​test_ciq.py Tests delegated-token forwarding.
tests/​unit/​authzen/​test_authzen.py Tests delegated-token behavior.
tests/​unit/​audit/​test_audit.py Tests Audit client operations.
tests/​unit/​audit/​__init__.py Defines the audit test package.
tests/​integration/​test_audit.py Adds live Audit API tests.
tests/​integration/​conftest.py Adds the Audit client fixture.
README.md Documents claims and audit usage.
Pipfile.lock Updates development dependencies.
indykite_sdk/​config/​models/​core.py Adds the Audit permission type.
indykite_sdk/​config/​client.py Documents Audit agent permissions.
indykite_sdk/​ciq/​client.py Adds synchronous delegated tokens.
indykite_sdk/​ciq/​aio.py Adds asynchronous delegated tokens.
indykite_sdk/​authzen/​models.py Documents reserved claim parameters.
indykite_sdk/​authzen/​client.py Adds synchronous delegated tokens.
indykite_sdk/​authzen/​aio.py Adds asynchronous delegated tokens.
indykite_sdk/​authzen/​_ops.py Builds delegated-token headers.
indykite_sdk/​audit/​models.py Defines Audit response models.
indykite_sdk/​audit/​client.py Implements the synchronous client.
indykite_sdk/​audit/​aio.py Implements the asynchronous client.
indykite_sdk/​audit/​_ops.py Builds Audit requests and pagination.
indykite_sdk/​audit/​__init__.py Exports the Audit API package.
indykite_sdk/​_core/​ops.py Adds X-IK-Token header support.
indykite_sdk/​_core/​errors_map.py Improves permission error guidance.
indykite_sdk/​__init__.py Exports both Audit clients.
examples/​audit_logs.py Adds an audit export example.
.github/​workflows/​docs.yaml Publishes Audit API documentation.
.github/​PULL_REQUEST_TEMPLATE.md Lists AuditClient as affected client.
.github/​ISSUE_TEMPLATE/​bug-report.md Adds AuditClient to bug reports.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread examples/audit_logs.py Outdated
Comment thread indykite_sdk/authzen/client.py Outdated
Comment thread indykite_sdk/ciq/client.py Outdated
Comment thread tests/integration/conftest.py Outdated
implement [ENG-9616]
Copilot AI balanced review requested due to automatic review settings September 30, 2026 14:29

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementations are consistent across sync and async clients and include comprehensive tests and documentation.

Review effort: Balanced
Findings: None

Resolved since last review (4)

@cowan-macady
cowan-macady merged commit fac2a3d into master Oct 1, 2026
15 checks passed
@cowan-macady
cowan-macady deleted the claims-audit branch October 1, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants