4 Commits

Author SHA1 Message Date
ed7c1b0a0f fix(openbao-session): always pass -ttl so session tokens stay short-lived
Without an explicit -ttl the role path could mint ~32-day session tokens.
Pass SESSION_TTL in both role and policy modes. Bump 0.1.3.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:37:00 +07:00
0f77ad534e fix(openbao-session): use a token role for entity-alias minting
entity-alias only works with -role; add OPENBAO_SESSION_ROLE so session tokens
can carry the user entity (and read humans/self) via the openbao-session role.
Bump 0.1.2.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:28:38 +07:00
6877bc7202 feat(openbao-session): tie session token to the user entity
Mint the session token with -entity-alias from OPENBAO_SESSION_ENTITY so
{{identity.entity.id}} resolves and the session can read humans/self (read-only)
in addition to shared/*. Document the claude-session policy with humans/self.
Bump 0.1.1.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 11:19:00 +07:00
5166f12775 feat: add openbao-session plugin for interactive agents
SessionStart hook that provisions a short-lived, policy-scoped OpenBao token
for each agent session. For Claude Code it writes export lines into
$CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it
writes a mode-600 session env file and points the agent to it via context.
Failure degrades to a benign JSON so sessions still start. Registered in both
Claude and Codex marketplace manifests.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 02:16:01 +07:00