Skip to content

security: enforce process-unit scope in Customer Master relationship network #1045

Description

@seonghobae

#1042 remains the LineageWeave repair lane for the Customer Master relationship-network process-unit authorization defect.

Current exact head is f23f5a567bd66113603837f86f030c3c459e69e6 on protected main@83eba56149eb802cd63642c507c324c9976ec78e. The production repair reuses source_post_scope_sql / SOURCE_POST_ELIGIBILITY_SQL, distinguishes omitted versus explicit empty process scope, binds non-empty process units for private evidence, and has read_customer_master forward account.process_unit_ids explicitly. No copied ABAC, corporate→process inference, hidden request context, or cross-service SQL was introduced.

The reduced-coverage collector repair on this head recognizes only explicit plugin-marker mappings (pytest.mark.anyio -> anyio) while direct/transitive imports remain authoritative for optional extras; arbitrary markers such as pytest.mark.redis cannot suppress collection merely because an identically named module is absent.

Fresh exact-head repository Tests 34721721155, Security 34721721167, and SAST 34721721186 are terminal GREEN. Required CodeQL 34721721113, Required OpenCode 34721720227, and Required Noema 34721720347 are terminal FAILURE.

Strix 34721720240 has now terminalized FAILURE, so #1042 has been returned to Draft. Admission/scope/workspace materialization, contextual-orchestrator sidecar provisioning, pinned Strix install and input preparation all succeeded. The quick scan completed with report collection/upload succeeding. Immutable artifact 10309695301 (strix-reports, 95,509 bytes, sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8) contains one real Medium finding: CWE-862 cross-tenant disclosure of full-population period-report aggregates for mixed-visibility project/thread/team groupings. This is not a provider/wrapper-only false failure.

That report-aggregate defect is already owned by #1050/#1054. #1054 implements whole-population admission before serializing stored aggregates and carries authenticated PostgreSQL detail/list/comparison regressions. Do not duplicate that repair into #1042. Treat normal integration of the #1054 security prerequisite as preceding any future non-force #1042 restack/reconstruction.

Earlier Strix findings remain separated by owner: #1044/#1047 persisted Post Chat replay authorization; #1050/#1054 mixed-visibility report aggregates; #1051 REST/shared Global Ask admission; #1052/#1055 Customer Master customer-hint identity/ownership separation; #1053 Post Chat shared-persistence mutation authority.

Keep this issue open until the report prerequisite is integrated and one unchanged #1042 descendant proves caller/lower-level process-scope regressions, optional-extra collector regressions, authenticated Customer Master HTTP/E2E separation, touched-surface docstring acceptance, repository/PostgreSQL/frontend validation and coverage, Security/SAST/CodeQL/Strix/model-review GREEN, qualifying independent approval, and normal protected integration. Do not transfer predecessor receipts or manufacture validation through no-op churn.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions