arazzo
Resolve every step of an Arazzo workflow to an operation's x-permdock-permissions and report steps that call undocumented operations.
permdock arazzo check is the workflow counterpart of permdock openapi --check. It runs the resolution half of permdock.simulate({ arazzo, openapi }) and never evaluates a subject. See Arazzo workflows and Arazzo.
permdock arazzo check --doc workflows/publish-post.arazzo.json --openapi openapi.json
permdock arazzo check --doc workflows/publish-post.arazzo.json --openapi openapi.json --workflow publishPost --from src/permissions.tsFlags
| Flag | Values | Default | Purpose |
|---|---|---|---|
--doc <path> | file path | required | The Arazzo 1.0.x or 1.1.x document |
--openapi <path> | file path | required | The applied OpenAPI description (Overlay already merged). Several sources: pass one document, or a JSON object keyed by source name |
--workflow <id> | workflow id | first workflow | Which workflowId to expand |
--from <module> | definition module | permissions in config | Catalog used to reject unknown permission keys |
--cwd, --config and --json are shared (CLI). Exit codes: 0 every step documented, 1 findings, 2 usage (missing flags, unreadable JSON).
What it reports
A finding is one of:
| Reason | When |
|---|---|
validation | The document is not a valid Arazzo 1.0.x / 1.1.x document (missing info, source descriptions, workflows, steps, a step target or a parameter value), the workflowId is missing, or a workflowId step cycles |
undocumented | The operationId / operationPath does not resolve, names an unknown source, matches operations in several sources without a $sourceDescriptions qualifier, or the operation has no x-permdock-permissions |
unsupported | The step is an AsyncAPI operation or channelPath, or calls a workflow in another Arazzo document |
unknown-key | --from (or config permissions) is set and a key is not in the catalog |
The command does not call decide, does not load a policy, and does not accept a subject. Pre-flighting grants is permdock.simulate({ arazzo, openapi }) on an instance.
--json prints { "$schema": "permdock-arazzo-check", findings }.
Last updated on
openapi
Emit security and securitySchemes into an existing OpenAPI document (or as an Overlay) from the permission catalog, or import a document into a generated definition.
rls
Generate Postgres row-level security policies from a PermDock policy, import existing policies into a generated definition, and verify that both agree.