risk-nexus/findings/RISK-F-0010-embedded-backup-webdav-credential.md
tegwick bbbede5f47 Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 07:56:58 +02:00

6.7 KiB
Raw Blame History

id type title status owner reported_by reported_via routed_by date_reported date_filed system environment fix_owner fix_tracking closure_condition verification severity severity_at_production impact likelihood fidelity_modifier production_rescore disclosure embargo_condition embargo_since embargo_review escalation last_checked next_check cadence clean_streak waiting_on graded_by ruling checked_by
RISK-F-0010 finding Forgejo backup source embeds a WebDAV credential default open risk-nexus railiance-platform railiance-platform risk-nexus 2026-08-23 2026-08-23 railiance-platform production railiance-platform RPF-WP-0029-T02 provider invalidation plus governed ciphertext upload and restore receipts; source fallback removal alone does not lift the embargo RISK-V-0003 low low I2 L2 false false embargoed the provider credential is revoked or invalidated and the literal source default is removed 2026-09-01 2026-09-15 none 2026-09-05T00:05:51Z 2026-09-05T00:05:51Z instant 0
who what since would_change default default_at
railiance-platform complete RPF-WP-0029-T02: revoke or invalidate the provider credential and demonstrate governed ciphertext upload plus restore; source fallback removal is established 2026-09-01 the finding becomes fixed and the embargo lifts the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation 2026-09-15
risk-nexus RISK-RULING-2026-09-01-A codex/risk-nexus

RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default

What is true, as reported

railiance-platform/tools/cmd/forgejo-backup line 13 assigns a literal default to RAILIANCE_BACKUP_NC_TOKEN. The credential value is deliberately omitted from this finding, along with any fingerprint, length, or copy.

The literal is in repository history and can be recovered by anyone with access to affected clones or history. It was also surfaced in captured agent command output during an attended review on 2026-08-23, which expands the set of places that must be treated as potentially exposed.

The value was not used in that operation and its current validity was not tested. The configured Nextcloud endpoint was independently observed to be a write-only file drop: metadata listing and reads were denied while the approved OpenBao-sourced credential could upload ciphertext. Therefore, the established risk is an embedded credential and possible unauthorized write or storage injection if it remains live; read access to existing backups is not established. The age recovery private key is separate and was not found in the script.

How it was found

Found by source inspection while selecting the approved encrypted off-host snapshot lane for preparation-only scenario WARDEN-WP-0027-T02-DRILL-20260822-01. No attempt was made to authenticate with or probe the embedded value.

Suggested direction

Suggestion, owned by railiance-platform:

  1. Revoke and regenerate the Nextcloud file-drop credential at the provider.
  2. Write the replacement only to the governed OpenBao lane platform/workloads/railiance/backup/offsite-lane through a mode-0600 input file, then securely remove the input.
  3. Remove the source-code default so backup execution fails closed unless the value arrives through OpenBao or an explicit sanctioned environment.
  4. Review reachable Git history, CI and agent logs, and clones under the applicable retention policy; do not reproduce the credential while doing so.
  5. Verify a ciphertext upload and restore after rotation, then clear any exposure taint only with evidence.

Risk Nexus owns severity, disclosure, escalation, and review cadence. This report intentionally does not assign them.

Register ruling — 2026-09-01

low (I2 × L2), embargoed, no escalation.

I2: limited to one backup lane on the facts established. If the embedded value remains valid, it can authorize an ungoverned write or storage injection at the Nextcloud file-drop endpoint. Metadata listing and reads were denied, backup content is ciphertext, and the age recovery private key is separate. Nothing here establishes disclosure of an existing backup or estate-wide credential reach.

L2: recoverable through access the estate does grant. The value is in Git history and appeared in captured agent output, so a repository clone or retained log is a sufficient foothold. Current validity is unknown and is not tested by this register; unknown is not treated as either live or revoked.

Embargoed. While the source default remains and validity is unresolved, publishing that a recoverable provider credential exists materially shortens the path beyond reading the private repository. The hold lifts only when revocation or invalidation and removal of the literal are both observable. The credential value, fingerprint, and shape remain excluded from every record and message.

No escalation. There is no evidence of a read, loss, real-person data exposure, legal notification duty, new spend, ownership dispute, or a stalled remediation yet. Railiance Platform owns both the source and provider action. Silence defaults on 2026-09-15 to the existing grade and a recorded stall; it does not soften the assessment.

Reasoning: docs/rulings/2026-09-01-inbox-sweep.md.

Source remediation reconciled — 2026-09-05

RPF-WP-0029-T01 records source fallback removal and fail-closed input checks. This register confirmed the named fallback is absent in the current script without displaying or testing any credential. RPF-WP-0029-T02 remains wait for provider invalidation and governed encrypted upload/restore receipts.

RISK-V-0003 records the boundary: source removal does not establish invalidation of the predecessor. Open, low, embargoed and no escalation remain appropriate on the available evidence. The 2026-09-15 review/default is unchanged. The historical source-default statements above describe the earlier assessments.

Reviews

  • 2026-09-01 — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant.
  • 2026-09-02 — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z.
  • 2026-09-05 — not clean: Confirmed source fallback removal and RPF-WP-0029 tracking; provider invalidation and encrypted upload/restore receipts remain pending. Low grade and embargo retained; see RISK-V-0003. Cadence 1h → instant; checked again immediately.