Add governed test plane and close T04/T08
Encode fail-closed admission, target registrations, and a credential broker that never returns secret values. Calibrate audit-core shaped probes in-process. Send no packets and request no live credentials. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
parent
0aab0cb4c6
commit
95129d7a35
35 changed files with 1599 additions and 103 deletions
|
|
@ -1,10 +1,12 @@
|
|||
# Target applicability for WHITEHAT-WP-0001
|
||||
|
||||
Status: active review, 2026-08-22
|
||||
Status: encoded in `targets/`, 2026-08-22
|
||||
|
||||
The E2 attacker model requires an authenticated identity that is legitimately
|
||||
authorized for tenant A and not tenant B. A target name alone is insufficient;
|
||||
the target must expose a boundary where that identity exists.
|
||||
the target must expose a boundary where that identity exists. Machine-readable
|
||||
records live in [`targets/`](../targets/README.md). The test plane will not
|
||||
admit a `not_applicable` or `pending` target.
|
||||
|
||||
## audit-core — applicable
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue