Recipe 3
Encrypt bytes and authorize one bounded use
from pathlib import Path
import importlib.util, hashlib, time
ROOT = Path.cwd()
def load_source(path, name):
spec=importlib.util.spec_from_file_location(name, ROOT/path)
mod=importlib.util.module_from_spec(spec); spec.loader.exec_module(mod); return mod
identity_mod=load_source("src/01_Core_Runtime/identity/canonical_identity.py","entity_identity")
vault_mod=load_source("src/08_Data_Vaults/canonical_encrypted_vault.py","entity_vault")
privacy_mod=load_source("src/35_Global_Infrastructure/privacy_provenance.py","entity_privacy")
STATE=ROOT/".recipe-state"/"vault"
identity=identity_mod.EntityIdentityVault(STATE)
owner=identity.create("Owner","organization")
reader=identity.create("Reader","person")
vault=vault_mod.EncryptedDataVault(STATE)
item=vault.put_bytes(owner["entity_id"], b"confidential payload", media_type="text/plain", classification="PRIVATE")
assert vault.read_bytes(owner["entity_id"], item["vault_object_id"]) == b"confidential payload"
access=privacy_mod.PurposeBoundAccessRegistry(STATE, identity)
grant=access.grant(
owner["entity_id"], reader["entity_id"], item["vault_object_id"],
purposes=["RESEARCH"], actions=["READ"],
expires_at_ms=int(time.time()*1000)+60000, max_uses=1,
)
use_hash=hashlib.sha256(b"read-session-evidence").hexdigest()
use=access.authorize_use(grant["grant_id"], reader["entity_id"], "RESEARCH", "READ", use_hash)
assert use["authorized"] is True
assert use["remaining_uses"] == 0
try:
access.authorize_use(grant["grant_id"], reader["entity_id"], "RESEARCH", "READ", use_hash)
raise AssertionError("second use should fail")
except PermissionError:
passThis recipe proves encrypted content storage and purpose/action/use-cap authorization are separate controls.