com.l1fe.forge:forge-auth
Kotlin/JVM forge-auth module.
Kotlin/JVM forge-auth module.
Package contract
| Field | Value |
|---|---|
| Language | kotlin |
| Source version | 0.1.0 |
| Manifest | forge-kt/forge-auth/build.gradle.kts |
| Source files | 4 |
| Evidence | Source reference; registry publication and runtime conformance are separate checks |
Import boundary
import com.l1fe.forge.auth.*Use a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.
Source reference
Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.
com/l1fe/forge/auth/AuthError.kt
Read declaration text · 19 declaration entries
public sealed class ForgeAuthError(
message: String,
cause: Throwable?;
public class TokenExpired(
public val actId: String,
public val expiredAt: String,
) : ForgeAuthError(
"Arsenal ACT '$actId' expired at $expiredAt"
)
/**
* The agent does not have sufficient scope in its ACT.
*
* @property agentDid The agent's DID.
* @property actId The ACT identifier.
* @property requiredScope The scope that was required.
* @property availableScopes The scopes available in the ACT.
*/
public class InsufficientScope(
public val agentDid: String,
public val actId: String,
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public val actId: String,
public val expiredAt: String,
) : ForgeAuthError(
"Arsenal ACT '$actId' expired at $expiredAt"
)
/**
* The agent does not have sufficient scope in its ACT.
*
* @property agentDid The agent's DID.
* @property actId The ACT identifier.
* @property requiredScope The scope that was required.
* @property availableScopes The scopes available in the ACT.
*/
public class InsufficientScope(
public val agentDid: String,
public val actId: String,
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public val expiredAt: String,
) : ForgeAuthError(
"Arsenal ACT '$actId' expired at $expiredAt"
)
/**
* The agent does not have sufficient scope in its ACT.
*
* @property agentDid The agent's DID.
* @property actId The ACT identifier.
* @property requiredScope The scope that was required.
* @property availableScopes The scopes available in the ACT.
*/
public class InsufficientScope(
public val agentDid: String,
public val actId: String,
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public class InsufficientScope(
public val agentDid: String,
public val actId: String,
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public val agentDid: String,
public val actId: String,
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public val actId: String,
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public val requiredScope: String,
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public val availableScopes: List<String>,
) : ForgeAuthError(
"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; " +
public class CapabilityEscalation(
public val parentDid: String,
public val actId: String,
public val requestedScope: String,
public val parentScopes: List<String>,
) : ForgeAuthError(
"capability escalation denied: child requested scope '$requestedScope' but " +
"parent $parentDid ACT '$actId' only grants: " +
parentScopes.joinToString(", ").ifEmpty
public val parentDid: String,
public val actId: String,
public val requestedScope: String,
public val parentScopes: List<String>,
) : ForgeAuthError(
"capability escalation denied: child requested scope '$requestedScope' but " +
"parent $parentDid ACT '$actId' only grants: " +
parentScopes.joinToString(", ").ifEmpty
public val actId: String,
public val requestedScope: String,
public val parentScopes: List<String>,
) : ForgeAuthError(
"capability escalation denied: child requested scope '$requestedScope' but " +
"parent $parentDid ACT '$actId' only grants: " +
parentScopes.joinToString(", ").ifEmpty
public val requestedScope: String,
public val parentScopes: List<String>,
) : ForgeAuthError(
"capability escalation denied: child requested scope '$requestedScope' but " +
"parent $parentDid ACT '$actId' only grants: " +
parentScopes.joinToString(", ").ifEmpty
public val parentScopes: List<String>,
) : ForgeAuthError(
"capability escalation denied: child requested scope '$requestedScope' but " +
"parent $parentDid ACT '$actId' only grants: " +
parentScopes.joinToString(", ").ifEmpty
public class DelegationDenied(
public val reason: String,
) : ForgeAuthError("delegation denied: $reason")
/**
* An ACT is structurally invalid.
*
* @property actId The ACT identifier.
* @property reason The validation failure reason.
*/
public class InvalidAct(
public val actId: String,
public val reason: String,
) : ForgeAuthError("Arsenal ACT '$actId' is invalid: $reason")
}
public val reason: String,
) : ForgeAuthError("delegation denied: $reason")
/**
* An ACT is structurally invalid.
*
* @property actId The ACT identifier.
* @property reason The validation failure reason.
*/
public class InvalidAct(
public val actId: String,
public val reason: String,
) : ForgeAuthError("Arsenal ACT '$actId' is invalid: $reason")
}
public class InvalidAct(
public val actId: String,
public val reason: String,
) : ForgeAuthError("Arsenal ACT '$actId' is invalid: $reason")
}
public val actId: String,
public val reason: String,
) : ForgeAuthError("Arsenal ACT '$actId' is invalid: $reason")
}
public val reason: String,
) : ForgeAuthError("Arsenal ACT '$actId' is invalid: $reason")
}com/l1fe/forge/auth/Capability.kt
Read declaration text · 6 declaration entries
public data class DelegationConstraints(
@SerialName("allow_delegation")
val allowDelegation: Boolean;
public data class AgentCapabilityToken(
val id: String,
@SerialName("agent_did")
val agentDid: String,
@SerialName("issuer_did")
val issuerDid: String,
val scopes: List<String>,
@SerialName("issued_at")
val issuedAt: Timestamp,
@SerialName("expires_at")
val expiresAt: Timestamp,
@SerialName("delegation_constraints")
val delegationConstraints: DelegationConstraints;
public fun verifyAct(act: AgentCapabilityToken)
public fun extractScopes(act: AgentCapabilityToken): List<String>;
public fun actAllowsScope(act: AgentCapabilityToken, requiredScope: String): Boolean
public fun scopeImplies(granted: String, required: String): Booleancom/l1fe/forge/auth/Delegation.kt
Read declaration text · 3 declaration entries
public data class DelegationRequest(
@SerialName("parent_act")
val parentAct: AgentCapabilityToken,
@SerialName("child_did")
val childDid: String,
@SerialName("requested_scopes")
val requestedScopes: List<String>,
)
/**
* The result of a delegation operation.
*
* @property childAct The delegated ACT for the child agent.
* @property narrowedScopes The scopes that were actually granted (may be a subset of requested).
*/
@Serializable
public data class DelegationResult(
@SerialName("child_act")
val childAct: AgentCapabilityToken,
@SerialName("narrowed_scopes")
val narrowedScopes: List<String>,
)
/**
* Delegate capabilities from a parent to a child agent.
*
public data class DelegationResult(
@SerialName("child_act")
val childAct: AgentCapabilityToken,
@SerialName("narrowed_scopes")
val narrowedScopes: List<String>,
)
/**
* Delegate capabilities from a parent to a child agent.
*
* Enforces the ANVIL rule that child capabilities must be a strict
* subset of parent capabilities. The child's TTL is reduced by
* the delegation constraints.
*
* ANVIL Spec Section 11.2
*
* @param request The delegation request.
* @return The delegation result with the child's ACT.
* @throws ForgeAuthError.DelegationDenied if delegation is not allowed.
* @throws ForgeAuthError.CapabilityEscalation if requested scopes exceed parent's.
* @throws ForgeAuthError.TokenExpired if the parent's ACT has expired.
*/
public fun delegateCapabilities(request: DelegationRequest): DelegationResult
public fun delegateCapabilities(request: DelegationRequest): DelegationResultcom/l1fe/forge/auth/ToolAuth.kt
Read declaration text · 7 declaration entries
public data class ToolAuthorizationRequest(
@SerialName("tool_name")
val toolName: String,
@SerialName("tool_tier")
val toolTier: ToolTier,
@SerialName("agent_did")
val agentDid: String?;
public sealed class ToolAuthorizationDecision
public data class Allowed(val scope: String) : ToolAuthorizationDecision()
/**
* The tool invocation is denied.
*
* @property reason The denial reason.
*/
@Serializable
@SerialName("denied")
public data class Denied(val reason: String) : ToolAuthorizationDecision()
/**
* The tool invocation is in legacy mode (no identity/auth configured).
*
* Legacy mode allows all tools but logs a warning.
*/
@Serializable
@SerialName("legacy_mode")
public data object LegacyMode : ToolAuthorizationDecision()
}
/**
* Authorize a tool invocation against an Arsenal ACT.
*
* Authorization rules per ANVIL 3-tier model:
* - **Platform (Tier 1)**: Always allowed, no ACT check needed.
public data class Denied(val reason: String) : ToolAuthorizationDecision()
/**
* The tool invocation is in legacy mode (no identity/auth configured).
*
* Legacy mode allows all tools but logs a warning.
*/
@Serializable
@SerialName("legacy_mode")
public data object LegacyMode : ToolAuthorizationDecision()
}
/**
* Authorize a tool invocation against an Arsenal ACT.
*
* Authorization rules per ANVIL 3-tier model:
* - **Platform (Tier 1)**: Always allowed, no ACT check needed.
* - **External (Tier 2)**: Requires ACT with matching scope.
* - **Embedded (Tier 3)**: Always allowed (module-scoped).
*
* If no ACT is provided, returns [ToolAuthorizationDecision.LegacyMode].
*
* ANVIL Spec Section 8.7
*
* @param request The authorization request.
* @return The authorization decision.
public data object LegacyMode : ToolAuthorizationDecision()
}
/**
* Authorize a tool invocation against an Arsenal ACT.
*
* Authorization rules per ANVIL 3-tier model:
* - **Platform (Tier 1)**: Always allowed, no ACT check needed.
* - **External (Tier 2)**: Requires ACT with matching scope.
* - **Embedded (Tier 3)**: Always allowed (module-scoped).
*
* If no ACT is provided, returns [ToolAuthorizationDecision.LegacyMode].
*
* ANVIL Spec Section 8.7
*
* @param request The authorization request.
* @return The authorization decision.
*/
public fun authorizeToolInvocation(request: ToolAuthorizationRequest): ToolAuthorizationDecision
public fun authorizeToolInvocation(request: ToolAuthorizationRequest): ToolAuthorizationDecision
public fun buildToolScope(toolName: String): String;