Redact provider connection config for read-only viewers and canonicalize Bedrock ids in setup

The provider read grant now serves usage_viewer the display surface only:
the manager blanks upstream URL, operator-typed header values, identity
header names, and the TLS override for callers holding read without
update. The me/setup model intersection compares declared ids through the
same normalization the proxy's parser applies, so a Bedrock declaration
in region/version form still advertises when its canonical id is
allowlisted. Docs and comments now say account-wide for the logs
exclusion and describe the real group source shared with enforcement.
This commit is contained in:
mlsmaycon
2026-08-27 08:07:20 +00:00
parent 6b38bd9c71
commit c995d89830
7 changed files with 199 additions and 8 deletions
+4 -1
View File
@@ -112,7 +112,10 @@ Two roles delegate Agent Network access without account-admin rights:
- **`usage_viewer`** — the regular User baseline plus read on
`agent_network.usage` (the aggregated usage and cost overview) and read-only
access to the resources the usage filters resolve against: users, groups,
peers, and the provider list. No policies, no request-level access logs.
peers, and the provider list (connection config redacted — no upstream URLs
or operator-supplied header values). No policies, and no account-wide
request-level access logs; like any caller, it still reads its own requests
through the self-scoped endpoints below.
Every authenticated user, regardless of role, can read the caller-scoped
self-service endpoint `GET /api/agent-network/me/setup` (the endpoint, providers,