audit-core/WORK-RECORDS.md
tegwick aaa2b4c50b
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Scope the read path by tenant (AUDIT-WP-0008-T04).
_read gated on may_read alone and never called permits_tenant, so any reader
credential could read every tenant through /v1/events, /v1/events/<id>,
/v1/dead-letters and /v1/secret-findings. Deployment bounded the exposure --
the only production sender holds may_read: false -- but the boundary was not in
the code, which is the difference between E2 and E1 on the tenancy posture
enforcement ladder.

Two rules, because the surfaces divide cleanly. Event reads are filtered to the
tenants the credential may act for. Surfaces with no tenant key to filter on --
stats, integrity, dead letters, secret findings -- require full tenant scope and
are refused rather than served instance-wide facts to a scoped reader.

A cross-tenant fetch returns 404 rather than 403. A distinguishable forbidden
would confirm that an event id exists and which tenant holds it, turning the
read surface into an existence oracle. Correlation lookup is filtered rather
than refused, since a correlation id legitimately spans tenants.

_readable_by fails closed: a record with no tenant is readable only at full
scope. Three existing tests read instance-wide surfaces with a scoped
credential, which this makes a 403; bound_app now carries an unrestricted
operator identity and those reads use it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:05:52 +02:00

4.9 KiB

Work Records — audit-core

Generated by statehub fix-consistency (CUST-WP-0061-T04, work-record stage 3). Do not edit by hand — edit the source file/block listed for each record and re-run fix-consistency to refresh this index. Archived workplans are omitted; closed decisions/intakes/engagements stay listed so recently-resolved work is still visible. [auto]

Kind ID Status Lane Source
workplan AUDIT-WP-0001 finished workplans/AUDIT-WP-0001-statehub-bootstrap.md
workplan AUDIT-WP-0002 finished workplans/AUDIT-WP-0002-pluggable-audit-backend.md
workplan AUDIT-WP-0003 finished workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
workplan AUDIT-WP-0004 finished workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
workplan AUDIT-WP-0005 finished workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
workplan AUDIT-WP-0006 finished workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
workplan AUDIT-WP-0007 finished workplans/AUDIT-WP-0007-integrity-verification.md
workplan AUDIT-WP-0008 ready workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0001-T01 done workplans/AUDIT-WP-0001-statehub-bootstrap.md
task AUDIT-WP-0001-T02 done workplans/AUDIT-WP-0001-statehub-bootstrap.md
task AUDIT-WP-0001-T03 done workplans/AUDIT-WP-0001-statehub-bootstrap.md
task AUDIT-WP-0002-T01 done workplans/AUDIT-WP-0002-pluggable-audit-backend.md
task AUDIT-WP-0003-T01 done workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0003-T02 done workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0003-T03 cancel workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0003-T04 cancel workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0004-T01 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T02 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T03 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T04 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T05 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T06 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T07 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0005-T01 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T02 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T03 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T04 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T05 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T06 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0006-T01 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T02 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T03 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T04 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T05 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0007-T01 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T02 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T03 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T04 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T05 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0008-T01 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T02 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T03 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T04 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T05 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T06 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md