Commit Graph

2 Commits

Author SHA1 Message Date
null 9ab57f6c72 feat(security): ten standing checks the list did not have
Grep across docs/** found zero mentions of security headers, token storage,
account enumeration, audit trail, test environment or rate limiting. The
standing list had four entries and stopped at the boundary of the repository.

Grouped by the question each group answers rather than listed flat, because the
grouping is the argument:

- Authorisation, the three questions login does not answer. Logged-out callers
  refused, objects and lists scoped to the caller, privileged routes checking a
  role. Login is the front door; every room inside needs its own lock.
- What the browser is handed. No secret in the built bundle, session tokens in
  HttpOnly cookies rather than localStorage, a CSP and a frame policy with
  nothing on plain HTTP.
- What a stranger can learn or exhaust. Responses that do not confirm whether an
  account exists, and *(precautionary)* rate limits on authentication and on
  anything costing money per request.
- The compliance bar, which is not the launch bar: a record of who changed what
  and when, and an environment that is not production to test against. Called
  out as a different bar on purpose -- the rest of the list gets a release out
  of the door, those two get it through the first compliance review.

Each entry says what it proves, per this file's own rule that a check whose
purpose is unstated gets skipped the first time it is inconvenient.

closes #4

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-17 22:54:48 -05:00
null 6965915dbd chore(repo): put the template under version control
The basis for every project here was itself unversioned: no .git, no remote,
no history. Changes to it had no diff and no revert, and two of its own guards
could not run at all -- doc-claims.sh and doc-triggers.py both read git
history, so the script written to catch documentation drift could not be run
against the documents that define drift.

This is the tree as it stands, including work that until now existed only as
loose files on disk: WORK_CYCLE.md, TOOLS.md, the Portainer image-line fix in
deploy.py, the status vocabulary corrected to the four words the conformance
checker actually enforces, the Exempt: mechanism documented, and the Forgejo
instance named in README.md.

secrets.sh --tracked reports one candidate, migrate.sh:480. It is the comment
documenting the three Postgres credential shapes that script redacts, with
literal placeholders, and it is left alone deliberately: GUARDS.md section 2
is that a source-grep guard must tell code from the comment about code, and
deleting an explanation to quiet a scanner is the failure it names.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-17 22:44:26 -05:00