Metadata-Version: 2.4
Name: gdp-rs
Version: 0.1.0
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: 3.14
Classifier: Programming Language :: Rust
Classifier: Programming Language :: Python :: Implementation :: CPython
Classifier: Topic :: Software Development :: Libraries :: Python Modules
Classifier: Topic :: Security
Requires-Dist: pytest>=8,<10 ; extra == 'test'
Requires-Dist: ruff>=0.11,<1 ; extra == 'test'
Requires-Dist: mypy>=1.15,<2 ; extra == 'test'
Requires-Dist: pyrefly>=1.3.1,<2 ; extra == 'test'
Requires-Dist: fastapi>=0.141.1,<1 ; extra == 'test'
Requires-Dist: httpx2>=2.13.1,<3 ; extra == 'test'
Provides-Extra: test
License-File: LICENSE
Summary: Rust-backed proof contracts for Python authorization boundaries
Keywords: authorization,proof-contracts,rust,gdp
Author: CloudThinker AI
License-Expression: MIT
Requires-Python: >=3.11
Description-Content-Type: text/markdown; charset=UTF-8; variant=GFM
Project-URL: Documentation, https://github.com/cloudthinker-ai/proofbound/blob/main/docs/python.md
Project-URL: Homepage, https://github.com/cloudthinker-ai/proofbound
Project-URL: Issues, https://github.com/cloudthinker-ai/proofbound/issues
Project-URL: Security, https://github.com/cloudthinker-ai/proofbound/blob/main/SECURITY.md
Project-URL: Source, https://github.com/cloudthinker-ai/proofbound

# Proofbound for Python

Rust-backed authorization contracts. The extension creates opaque names and proofs;
the Python decorator checks them before a sensitive function runs.

Proofbound is an early project with an evolving API. The Python distribution is
`gdp-rs`, the import package is `gdp`, and the linter command is `gdp-lint`.

## Install

```bash
pip install gdp-rs==0.1.0
```

CPython 3.11–3.14 is tested. Release wheels support Linux x64/ARM64 (glibc 2.17+),
macOS ARM64 (11+) and Windows x64. Wheel installation does not require Rust;
building from source requires Rust 1.90 or newer.

## How it works

A trusted application module performs the real permission or entitlement check,
then issues a proof for named arguments. A sensitive function declares the proof
it requires using `@requires`. Before the body runs, Rust verifies the exact
issuer, ordered subject identities and active scope.

Equal raw IDs named separately have different identities. Type hints and the
AST linter add checks for accidental misuse. The library does not decide your
policy, prevent permission revocation or make a check and write atomic. Python
code running in the same process can bypass a decorator; this is not a sandbox.

See the [Python API](https://github.com/cloudthinker-ai/proofbound/blob/main/docs/python.md),
[guarantee matrix](https://github.com/cloudthinker-ai/proofbound/blob/main/docs/guarantees.md)
and [executable SQLite example](https://github.com/cloudthinker-ai/proofbound/tree/main/examples/python).
The [repository README](https://github.com/cloudthinker-ai/proofbound) includes
trusted checker and protected function examples.

## Attribution

Inspired by Guillermo Rauch's MIT-licensed
[gdp-ts](https://github.com/rauchg/gdp-ts), Matt Noonan's
[Ghosts of Departed Proofs](https://kataskeue.com/gdp.pdf), and Ollie Charles's
[Who Authorized These Ghosts!?](https://blog.ocharles.org.uk/posts/2019-08-09-who-authorized-these-ghosts.html).
The original copyright notice and MIT license are preserved in the distribution.

