PermDock
CLI

arazzo

Resolve every step of an Arazzo workflow to an operation's x-permdock-permissions and report steps that call undocumented operations.

permdock arazzo check is the workflow counterpart of permdock openapi --check. It runs the resolution half of permdock.simulate({ arazzo, openapi }) and never evaluates a subject. See Arazzo workflows and Arazzo.

permdock arazzo check --doc workflows/publish-post.arazzo.json --openapi openapi.json
permdock arazzo check --doc workflows/publish-post.arazzo.json --openapi openapi.json --workflow publishPost --from src/permissions.ts

Flags

FlagValuesDefaultPurpose
--doc <path>file pathrequiredThe Arazzo 1.0.x or 1.1.x document
--openapi <path>file pathrequiredThe applied OpenAPI description (Overlay already merged). Several sources: pass one document, or a JSON object keyed by source name
--workflow <id>workflow idfirst workflowWhich workflowId to expand
--from <module>definition modulepermissions in configCatalog used to reject unknown permission keys

--cwd, --config and --json are shared (CLI). Exit codes: 0 every step documented, 1 findings, 2 usage (missing flags, unreadable JSON).

What it reports

A finding is one of:

ReasonWhen
validationThe document is not a valid Arazzo 1.0.x / 1.1.x document (missing info, source descriptions, workflows, steps, a step target or a parameter value), the workflowId is missing, or a workflowId step cycles
undocumentedThe operationId / operationPath does not resolve, names an unknown source, matches operations in several sources without a $sourceDescriptions qualifier, or the operation has no x-permdock-permissions
unsupportedThe step is an AsyncAPI operation or channelPath, or calls a workflow in another Arazzo document
unknown-key--from (or config permissions) is set and a key is not in the catalog

The command does not call decide, does not load a policy, and does not accept a subject. Pre-flighting grants is permdock.simulate({ arazzo, openapi }) on an instance.

--json prints { "$schema": "permdock-arazzo-check", findings }.

Last updated on

On this page