{"record":{"id":"baf5180d027a53bd","repo":"affaan-m/ECC","slug":"aurauntrusted","errorCode":null,"errorMessage":"AuraUntrusted","messagePattern":"AuraUntrusted","errorType":"exception","errorClass":"AuraUntrusted","httpStatus":null,"severity":"error","filePath":"integrations/aura/adapter.py","lineNumber":209,"sourceCode":"            settle_payment(counterparty_did, amount)\n        except AuraUntrusted as e:\n            abort(str(e))\n\n    Explicitly allow brand-new agents in an onboarding flow:\n        before_settle(did, allow=(\"trusted\", \"caution\", \"new\"))\n\n    fail_open=True makes an *unreachable* AURA pass through (transport failure\n    only — a reachable AURA that returns `unknown` is still rejected). Off by\n    default — absence of evidence is not evidence of trust.\n    \"\"\"\n    v = aura_verdict(did, base_url=base_url, timeout=timeout, _fetch=_fetch)\n\n    if v.verdict in allow:\n        return v\n    # fail_open only excuses a transport failure, never a reachable `unknown`.\n    if fail_open and not v.reachable:\n        return v\n    raise AuraUntrusted(v)\n\n\n# Alias — same gate, name that reads better at non-payment call sites.\nrequire_trust = before_settle\n","sourceCodeStart":191,"sourceCodeEnd":214,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/integrations/aura/adapter.py#L191-L214","documentation":"before_settle (alias require_trust) is the fail-closed trust gate: it takes an AuraVerdict and raises AuraUntrusted unless the verdict's class is in the `allow` set, or fail_open is set AND the verdict was a transport failure (not reachable). A reachable 'unknown' verdict is never excused, so any agent identity AURA could not positively trust is rejected before the payment/settlement proceeds.","triggerScenarios":"Calling before_settle(v) where v.verdict is 'new', 'unknown', or 'high-risk' (anything outside the allow list); fail_open=True but the verdict was a reachable 'unknown' rather than a transport error; allow list configured too narrowly (defaulting to not including 'new').","commonSituations":"A newly onboarded agent with no AURA history hits the default-deny gate on its first settlement; AURA service reachable but returning 'unknown' for the DID; opting into fail_open expecting it to bypass unknowns; payment code calling require_trust with a default allow set that excludes legitimate classes.","solutions":["Inspect the AuraVerdict (v.verdict, v.reason, v.score) to see why the agent was not trusted","If the class is legitimately acceptable for this call site, add it to the allow set, e.g. before_settle(v, allow={'trusted', 'caution', 'new'})","Build reputation first: let the agent perform non-payment actions until AURA assigns a trusted/caution verdict","Do not rely on fail_open to bypass a reachable 'unknown' — only transport failures are excused; fix the DID or AURA lookup instead"],"exampleFix":"# before\nbefore_settle(aura_verdict(did))  # raises AuraUntrusted for 'new'\n\n# after — explicitly opt new agents in where policy allows\nbefore_settle(aura_verdict(did), allow={\"trusted\", \"caution\", \"new\"})","handlingStrategy":"try-catch","validationCode":"v = aura_verdict(did)\nif v.verdict not in allow and not (fail_open and not v.reachable):\n    # handle untrusted path explicitly before calling before_settle","typeGuard":"def is_settleable(v: AuraVerdict, allow=frozenset({\"trusted\", \"caution\"})) -> bool:\n    return v.verdict in allow or (fail_open and not v.reachable)","tryCatchPattern":"try:\n    before_settle(v, allow=ALLOWED_CLASSES)\nexcept AuraUntrusted as e:\n    # inspect e.verdict.verdict / .reason; route agent to reputation-building flow\n    quarantine_agent(did, reason=e.verdict.reason)","preventionTips":["Explicitly declare the allow set per call site instead of relying on defaults","Treat 'new' agents as expected to be gated — provision a warm-up flow before first settlement","Never expect fail_open to bypass reachable 'unknown' verdicts; fix the DID/AURA lookup instead","Log the AuraVerdict (verdict, reason, score) on every AuraUntrusted for auditing"],"tags":["python","trust-gate","aura","fail-closed"],"backgroundTag":"permission-denied","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}