fix(auth): fail closed without write-capable admin on public bind - #155
fix(auth): fail closed without write-capable admin on public bind#155seonghobae wants to merge 20 commits into
Conversation
|
Warning Review limit reachedNext included review available in 53 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh exact-head revalidation (2026-09-03 KST): protected base is still The current-PR required OpenCode lane is still non-terminal: run No source churn, self-approval, routine bypass, or predecessor/wrong-PR evidence reuse is warranted. Re-read the unchanged head after the central lane becomes terminal, then apply the live solo-maintainer ruleset once its owner repair converges. |
|
Exact-current gate refresh, 2026-09-06 KST: unchanged This PR remains the canonical Wardnet authentication foundation for write-capable management authority. Stale feature lanes that change management-write RBAC, including #112's old aggregate API branch, must not independently integrate a competing |
Fixes #78 only when this exact candidate reaches protected
main.Security boundary
Wardnet must never expose unauthenticated management writes on a non-loopback listener. Loopback-only development may remain credential-free, but production-facing binds require a write-capable administrator credential before readiness. The bounded delta rejects missing/ambiguous write authority, preserves
401vs403, constant-time token comparison, readonly/write separation, andauth_mode=developmentonly for loopback credential-free operation.Protected-main adoption
Prior exact candidate
f74ff25a321dfb1d7109719e2a1fc77e47dc4898was already non-destructively aligned with protected5829a0f08d78de464dd24393ce5d0f25fba9d126. Protected/defaultmainthen advanced through #171 to exacta52ccd0a24a727d9349bb32def7713882d8cad1e.Fresh comparison proved the intervening protected delta is only
docs/adr/2026-09-05-anti-bot-acquisition-boundary.mdplusdocs/adr/README.md, neither overlapping this authentication/security delta. Two-parent mergefb93b61a4a4da30a3471453051ebfb0ed3f63d34adopted that protected truth without force push or destructive rebase. Current compare remains merge-base=a52ccd0..., behind 0; the effective feature delta remains the same 13 authentication/deployment/test/doctoring paths.Exact-current evidence — 2026-09-07 KST
Current exact source remains unchanged
fb93b61a4a4da30a3471453051ebfb0ed3f63d34, Ready/mechanically mergeable on protectedmain. The earlier no-run snapshot is superseded. Without source churn, current gates have executed:34020141305: SUCCESS;34020141277: SUCCESS;34020141306: SUCCESS;34020141279: SUCCESS;34020141314: FAILURE only at delegated terminal-verdict enforcement.CodeQL detect-language job
101451083576is terminal success. Compatibility job101455725295also acquired a hosted runner and completedRequest current-head CodeQL scan dispatch; it fails only atRelease runner or enforce current-head CodeQL verdict. This is the same central authenticated dispatcher/verdict boundary tracked in.github#712/ the live CodeQL owner path, not a management-authentication source/test failure. Do not source-churn this unchanged security candidate, transfer predecessor verdicts, or weaken CodeQL.Ready metadata is not merge authorization. Live organization ruleset
18156473still carries the structurally incompatible solo-maintainer generic approval count plus routineOrganizationAdmin/alwaysbypass tracked by.github#772. Self/model approval, routine or implicit administrator bypass, force push, destructive rebase and merge-as-probe remain forbidden.Merge only through the ordinary protected path after one unchanged exact head has an authenticated terminal current-source CodeQL verdict, zero valid unresolved findings/threads, fresh candidate-base compatibility, and every then-live deterministic/security/coverage/package/SBOM/provenance/governance requirement terminal-valid.