From 45df4d0d9b577fecee798d672695fe24ff57fb1b Mon Sep 17 00:00:00 2001 From: mo khan Date: Tue, 15 Jul 2025 16:37:08 -0600 Subject: feat: migrate from Cedar to SpiceDB authorization system This is a major architectural change that replaces the Cedar policy-based authorization system with SpiceDB's relation-based authorization. Key changes: - Migrate from Rust to Go implementation - Replace Cedar policies with SpiceDB schema and relationships - Switch from envoy `ext_authz` with Cedar to SpiceDB permission checks - Update build system and dependencies for Go ecosystem - Maintain Envoy integration for external authorization This change enables more flexible permission modeling through SpiceDB's Google Zanzibar inspired relation-based system, supporting complex hierarchical permissions that were difficult to express in Cedar. Breaking change: Existing Cedar policies and Rust-based configuration will no longer work and need to be migrated to SpiceDB schema. --- .../src/encrypt_transform.rs | 29 ---------------------- 1 file changed, 29 deletions(-) delete mode 100644 vendor/security-framework-sys/src/encrypt_transform.rs (limited to 'vendor/security-framework-sys/src/encrypt_transform.rs') diff --git a/vendor/security-framework-sys/src/encrypt_transform.rs b/vendor/security-framework-sys/src/encrypt_transform.rs deleted file mode 100644 index 85330527..00000000 --- a/vendor/security-framework-sys/src/encrypt_transform.rs +++ /dev/null @@ -1,29 +0,0 @@ -use core_foundation_sys::error::CFErrorRef; -use core_foundation_sys::string::CFStringRef; - -use crate::base::SecKeyRef; -use crate::transform::SecTransformRef; - -extern "C" { - pub static kSecEncryptionMode: CFStringRef; - pub static kSecEncryptKey: CFStringRef; - pub static kSecIVKey: CFStringRef; - pub static kSecModeCBCKey: CFStringRef; - pub static kSecModeCFBKey: CFStringRef; - pub static kSecModeECBKey: CFStringRef; - pub static kSecModeNoneKey: CFStringRef; - pub static kSecModeOFBKey: CFStringRef; - pub static kSecPaddingKey: CFStringRef; - pub static kSecPaddingNoneKey: CFStringRef; - pub static kSecPaddingOAEPKey: CFStringRef; - pub static kSecPaddingPKCS1Key: CFStringRef; - pub static kSecPaddingPKCS5Key: CFStringRef; - pub static kSecPaddingPKCS7Key: CFStringRef; - - pub fn SecDecryptTransformCreate(keyRef: SecKeyRef, error: *mut CFErrorRef) -> SecTransformRef; - // this symbol is apparently missing in 10.13.3? - // pub fn SecDecryptTransformGetTypeID() -> CFTypeID; - pub fn SecEncryptTransformCreate(keyRef: SecKeyRef, error: *mut CFErrorRef) -> SecTransformRef; -// this symbol is apparently missing in 10.13.3? -// pub fn SecEncryptTransformGetTypeID() -> CFTypeID; -} -- cgit v1.2.3