feat(webui): read-only workflow policy & guardrail visibility (Closes #646)
Phase 3 child of the Web Console epic #631. Operators can now see the active workflow policy/guardrail configuration from the console instead of reading the repo tree. - webui/policy_inventory.py (new): redacted, machine-readable guardrail inventory. One row per major guardrail (role separation/RBAC, lease rules, worktree binding, merge confirmation, redaction, contamination, allocator policy, audit logging, mutation gating) with source pointers (file/module/doc) and a compact active projection from the existing safe policy accessors. Fail-soft per entry; whole payload run through console_redaction before emit; diff vs documented default where feasible. - webui/policy_views.py (new): HTML cards with source pointers, active config, and the documented-default diff; read-only page copy, no forms. - webui/app.py: register GET /policy and GET /api/v1/policy (additive). - webui/layout.py: add Policy nav item. - tests/test_webui_policy_visibility.py (new): guardrail presence + source pointers (AC1), redaction incl. planted-secret masking and scan_for_secrets (AC2/AC3), read-only page + no-mutation routes (AC4), fail-soft rendering. - docs/webui-local-dev.md: route table + read-only policy-visibility section. Read-only throughout; no policy editing, no gate-weakening toggle, secrets redacted. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
@@ -0,0 +1,104 @@
|
||||
"""HTML views for the workflow policy and guardrail inventory (#646)."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import html
|
||||
import json
|
||||
|
||||
from webui.policy_inventory import PolicyEntry, PolicyInventorySnapshot
|
||||
|
||||
|
||||
def _source_pointer(source) -> str:
|
||||
path = source.path
|
||||
if source.anchor:
|
||||
path = f"{path}#{source.anchor}"
|
||||
return (
|
||||
f"<li>{html.escape(source.label)} — "
|
||||
f"<code>{html.escape(path)}</code> "
|
||||
f"<span class='muted'>({html.escape(source.kind)})</span></li>"
|
||||
)
|
||||
|
||||
|
||||
def _active_block(entry: PolicyEntry) -> str:
|
||||
if entry.error:
|
||||
return (
|
||||
"<p class='muted'><strong>Active value unavailable:</strong> "
|
||||
f"{html.escape(entry.error)}</p>"
|
||||
)
|
||||
if not entry.active:
|
||||
return "<p class='muted'>No live projection for this guardrail.</p>"
|
||||
pretty = json.dumps(entry.active, indent=2, sort_keys=True, default=str)
|
||||
return f"<pre class='prompt-text'>{html.escape(pretty)}</pre>"
|
||||
|
||||
|
||||
def _diff_block(entry: PolicyEntry) -> str:
|
||||
if entry.diff is None:
|
||||
if entry.documented_default is None:
|
||||
return "<p class='muted'>Diff vs documented default: not feasible (no declared default).</p>"
|
||||
return "<p class='muted'>Diff vs documented default: unavailable.</p>"
|
||||
status = entry.diff.get("status", "unknown")
|
||||
badge = "badge-claimed" if status == "matches_documented_default" else "badge-blocked"
|
||||
rows = []
|
||||
for key, cell in (entry.diff.get("checked") or {}).items():
|
||||
marker = "✓" if cell.get("matches") else "✗"
|
||||
rows.append(
|
||||
"<tr>"
|
||||
f"<td><code>{html.escape(str(key))}</code></td>"
|
||||
f"<td><code>{html.escape(str(cell.get('expected')))}</code></td>"
|
||||
f"<td><code>{html.escape(str(cell.get('observed')))}</code></td>"
|
||||
f"<td>{marker}</td>"
|
||||
"</tr>"
|
||||
)
|
||||
table = ""
|
||||
if rows:
|
||||
table = (
|
||||
"<table class='detail'><thead><tr>"
|
||||
"<th>Key</th><th>Documented</th><th>Active</th><th>Match</th>"
|
||||
"</tr></thead><tbody>"
|
||||
f"{''.join(rows)}</tbody></table>"
|
||||
)
|
||||
return (
|
||||
f"<p class='meta'>Diff vs documented default: "
|
||||
f"<span class='badge {badge}'>{html.escape(status)}</span></p>"
|
||||
f"{table}"
|
||||
)
|
||||
|
||||
|
||||
def _entry_card(entry: PolicyEntry) -> str:
|
||||
sources = "".join(_source_pointer(s) for s in entry.sources)
|
||||
return (
|
||||
"<div class='prompt-card'>"
|
||||
f"<h3>{html.escape(entry.title)} "
|
||||
f"<span class='badge'>{html.escape(entry.category)}</span></h3>"
|
||||
f"<p>{html.escape(entry.summary)}</p>"
|
||||
"<p class='meta'><strong>Source pointers</strong></p>"
|
||||
f"<ul>{sources}</ul>"
|
||||
"<p class='meta'><strong>Active configuration</strong></p>"
|
||||
f"{_active_block(entry)}"
|
||||
f"{_diff_block(entry)}"
|
||||
"</div>"
|
||||
)
|
||||
|
||||
|
||||
def render_policy_page(snapshot: PolicyInventorySnapshot) -> str:
|
||||
categories = ", ".join(html.escape(c) for c in snapshot.categories) or "none"
|
||||
cards = "".join(_entry_card(e) for e in snapshot.entries)
|
||||
build_errors = ""
|
||||
if snapshot.build_errors:
|
||||
items = "".join(
|
||||
f"<li>{html.escape(err)}</li>" for err in snapshot.build_errors
|
||||
)
|
||||
build_errors = (
|
||||
"<div class='stub'><p><strong>Some guardrails could not be built:"
|
||||
f"</strong></p><ul>{items}</ul></div>"
|
||||
)
|
||||
return (
|
||||
"<h2>Workflow policy & guardrails</h2>"
|
||||
f"<p class='muted'>{html.escape(snapshot.note)}</p>"
|
||||
f"<p class='meta'>Schema v{snapshot.schema_version} · "
|
||||
f"{len(snapshot.entries)} guardrails · categories: {categories}</p>"
|
||||
f"{build_errors}"
|
||||
f"{cards}"
|
||||
"<p class='muted'>This page is read-only. It reports enforced policy "
|
||||
"and never edits or weakens a gate. Secret values are redacted.</p>"
|
||||
)
|
||||
Reference in New Issue
Block a user