Denegación de la policy de una ruta o de un recurso (401/403/404 sin oráculo).
packages/api-contracts/src/bus/security-audit.tsPágina generada desde
packages/api-contracts/src/bus/security-audit.ts + packages/api-contracts/src/bus/routes.ts. No se edita a mano:bun run docs:genla regenera ybun run docs:checkfalla si difiere.
evt.security.policyDenied · v1
Denegación de la policy de una ruta o de un recurso (401/403/404 sin oráculo). La publican
catalog-svc y playback-svc; identity-svc la persiste en audit.events (dec-0118 §9).
| Campo | Valor |
|---|---|
| Familia | evt |
| Versión | 1 |
| Tope del payload | 2048 bytes |
| Contrato | SecurityPolicyDenied en packages/api-contracts/src/bus/security-audit.ts |
BUS_ROUTES)Deny-by-default: un emisor fuera de la allowlist se deniega y se audita (dec-0119 §4).
| Atiende | Transporte | Emisores admitidos | Rate (por emisor) |
|---|---|---|---|
identity-svc | nats | catalog-svc, playback-svc | 100/s, ráfaga 200 |
{
"type": "object",
"required": [
"severity",
"outcome",
"count"
],
"properties": {
"severity": {
"anyOf": [
{
"type": "string",
"const": "info"
},
{
"type": "string",
"const": "warn"
},
{
"type": "string",
"const": "high"
}
]
},
"outcome": {
"anyOf": [
{
"type": "string",
"const": "success"
},
{
"type": "string",
"const": "failure"
},
{
"type": "string",
"const": "denied"
}
]
},
"actorId": {
"type": "string",
"minLength": 1,
"maxLength": 128,
"pattern": "^[\\x21-\\x7e]+$"
},
"sessionId": {
"type": "string",
"minLength": 1,
"maxLength": 128,
"pattern": "^[\\x21-\\x7e]+$"
},
"ip": {
"type": "string",
"minLength": 1,
"maxLength": 64,
"pattern": "^[\\x21-\\x7e]+$"
},
"reason": {
"type": "string",
"minLength": 1,
"maxLength": 160,
"pattern": "^[\\x21-\\x7e]+$"
},
"count": {
"type": "integer",
"minimum": 1,
"maximum": 2147483647
},
"windowStart": {
"type": "integer",
"minimum": 0
}
}
}