-
Notifications
You must be signed in to change notification settings - Fork 0
promote: reviewed IAM recovery slice #44
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
102 commits
Select commit
Hold shift + click to select a range
c35f62d
feat(iam): define hashed invitation token invariants
BeforeLights 92b18ed
feat(iam): publish invitation invariants in domain aggregate
BeforeLights 46b6939
feat(iam): add invitation issue and redemption service
BeforeLights 9f14db2
feat(iam): add scoped invitation repository adapter
BeforeLights 2a65756
feat(iam): persist invitation token records
BeforeLights 5ce9fe3
docs(iam): record invitation token evidence
BeforeLights bf311ec
feat(iam): add keyed invitation crypto adapters
BeforeLights ab4d22c
feat(iam): expose invitation HTTP composition
BeforeLights 003f7c9
feat(iam): add durable principal email lookup
BeforeLights b7701a7
feat(iam): add atomic account registration service
BeforeLights a6a6168
feat(iam): persist account registration atomically
BeforeLights 4fd6236
fix(repo): normalize invitation formatting
BeforeLights a8ec43e
feat(iam): expose account registration endpoint
BeforeLights 26dd0ee
feat(iam): add bounded recovery challenge invariants
BeforeLights 371ccdf
feat(iam): add recovery service and transactional state effects
BeforeLights 857aa05
feat(iam): persist recovery security state atomically
BeforeLights 66abc06
feat(iam): expose account recovery endpoints
BeforeLights 20888ec
feat(iam): clear recovery gate after MFA verification
BeforeLights c7faf68
feat(iam): propagate MFA recovery re-enrollment state
BeforeLights 42bb322
fix(iam): compare and set recovery challenge revisions
BeforeLights 1269428
feat(iam): add bounded recovery admission
BeforeLights 33882d9
fix(iam): avoid password hashing for invalid recovery tokens
BeforeLights c6b7228
feat(iam): enforce recovery mfa gate on approvals
BeforeLights 94b8766
feat(iam): guard high-risk step-up during mfa reenrollment
BeforeLights e60170f
feat(iam): add shared recovery admission adapter
BeforeLights 8f0a7c2
feat(iam): compose shared recovery admission
BeforeLights 32d8687
feat(iam): bind recovery admission to redis eval
BeforeLights 20b592e
feat(iam): provide context-aware mfa step-up
BeforeLights 1302f88
feat(iam): bound recovery completion attempts
BeforeLights fe8380d
feat(iam): separate recovery completion admission
BeforeLights fee9579
fix(repo): align iam mocks with async lint contract
BeforeLights 65afa44
Merge pull request #43 from DatabreezeService/feat/iam-recovery
BeforeLights 265923b
feat(iam): define service account identity contract
BeforeLights 9c238e8
feat(iam): scope service account permissions
BeforeLights 1db0186
feat(iam): add service account repository port
BeforeLights 4a23c05
feat(iam): authorize service account lifecycle
BeforeLights 9ebad8f
feat(iam): generate one-time service account secrets
BeforeLights 87530e7
feat(iam): persist service account records
BeforeLights 73b4d99
feat(iam): add service account prisma adapter
BeforeLights e32ea58
feat(iam): expose service account lifecycle api
BeforeLights 7bf5ba0
feat(iam): resolve service accounts by secret digest
BeforeLights d02aa7e
feat(iam): authenticate service account credentials
BeforeLights 03ef9db
feat(audit): register service account lifecycle actions
BeforeLights 528f0c9
feat(iam): publish service account api contract
BeforeLights f015b11
feat(audit): add signed seal attestations
BeforeLights 34b79bc
feat(bua): issue bounded entitlement leases
BeforeLights 796a681
feat(bua): persist offline entitlement leases
BeforeLights 52d1607
feat(bua): persist entitlement lease schema
BeforeLights 4d057e4
feat(bua): add entitlement lease repository
BeforeLights 5c25a81
feat(bua): issue and verify entitlement leases
BeforeLights ecfbb25
feat(bua): expose entitlement lease api
BeforeLights 89f7bfb
feat(bua): add provider-neutral lease signing
BeforeLights 82b0e22
fix(bua): bind lease acceptance to canonical payload
BeforeLights ea59eb1
feat(audit): define seal attestation repository port
BeforeLights 3705546
feat(audit): add in-memory seal attestations
BeforeLights 304eecf
feat(audit): persist seal attestation schema
BeforeLights 2834320
feat(audit): add Prisma seal attestation adapter
BeforeLights fb9d5c2
feat(audit): issue and verify seal attestations
BeforeLights 4b40c9b
feat(audit): compose attestation providers
BeforeLights a100a75
feat(audit): expose attestation api
BeforeLights cb0dd27
fix(bua): validate entitlement snapshot plans
BeforeLights e4ad354
feat(bua): compose HMAC lease signing
BeforeLights d9a8386
docs(traceability): record IAM AUD BUA security slice
BeforeLights c9ebd1f
fix(traceability): keep audit ownership precise
BeforeLights 99141b9
chore: format IAM and entitlement security slice
BeforeLights c2442ad
fix(iam): satisfy service account lint guard
BeforeLights 20ceddd
test(api): track security migration and route contracts
BeforeLights df4d0a2
fix(deps): pin patched fast-uri release
BeforeLights b32584d
Merge pull request #45 from DatabreezeService/feat/iam-security-compl…
BeforeLights 597dc5d
fix(iam): persist recovery challenges before delivery
BeforeLights eb2d3c9
fix(iam): compose service accounts from derived repository
BeforeLights bfdcd5d
fix(iam): enforce strong digest keys
BeforeLights 8860135
fix(iam): reject recovery for inactive users
BeforeLights ea70d9f
fix(iam): guard service-account replacement scope
BeforeLights 2946e92
fix(iam): persist invitations before delivery
BeforeLights 75af992
fix(iam): map invitation invariant conflicts
BeforeLights 7910db8
fix(iam): enforce one active invitation per membership
BeforeLights a723292
fix(iam): validate service-account permissions before issuance
BeforeLights b54f0b4
fix(bua): use server time for lease verification
BeforeLights 716229a
fix(iam): make MFA reenrollment state explicit
BeforeLights 03a2101
fix(security): fail closed on signer errors and MFA clear
BeforeLights c6c5cee
fix(api): preserve integer and UTC timestamp contracts
BeforeLights c4a08a2
fix(bua): compare immutable leases by fields
BeforeLights 418b56a
fix(aud): use targeted scoped seal lookups
BeforeLights 3f1c4e9
fix(aud): return typed attestation replays
BeforeLights 05149f6
fix(iam): make registration outcomes indistinguishable
BeforeLights c61bb1c
fix(iam): throttle registration before password hashing
BeforeLights fa15e4b
fix(iam): honor service-account create idempotency
BeforeLights 40af06b
test(iam): exercise registration transaction rollback
BeforeLights 397087b
test(prisma): fix migration assertion escaping
BeforeLights 5f1bc30
docs(iam): refresh invitation slice checkpoint
BeforeLights 8b48661
test(iam): verify registration admission composition
BeforeLights 108cc0a
test(iam): prove registration rollback after staged write
BeforeLights 000554c
fix(iam): distinguish revoked invitation tokens
BeforeLights 417885e
docs(iam): refresh registration slice evidence
BeforeLights 6231dfd
test(iam): fail closed on unreadable account replay
BeforeLights e1ff67f
test(iam): verify registration admission digest boundaries
BeforeLights 277e699
test(iam): cover replay envelope bounds
BeforeLights 0bdd655
test(iam): correct registration timestamp assertions
BeforeLights ba41a8b
test(iam): preserve service-account create replay
BeforeLights e957e43
test(iam): keep admission fixtures lint-clean
BeforeLights 2a49f79
Merge pull request #47 from DatabreezeService/fix/coderabbit-iam-crit…
BeforeLights File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # IAM-010 durable invitation token slice — 2026-08-03 | ||
|
|
||
| ## Scope | ||
|
|
||
| This evidence record covers the durable persistence boundary for the IAM-010 invitation-token | ||
| slice. It is a partial implementation record, not a release approval or a claim that Plan 020 is | ||
| complete. | ||
|
|
||
| ## Delivered | ||
|
|
||
| - `2a65756` adds the `iam.invitation_tokens` Prisma model and centrally ordered migration. | ||
| - Only the token digest and recipient-email digest are persisted; the raw bearer value is accepted | ||
| only by the delivery port and is never returned by the application result or stored in a row. | ||
| - `PrismaIamInvitationRepositoryAdapter` maps persisted rows through domain validation, enforces | ||
| tenant scope visibility, rejects sibling-token reads, prevents multiple active invitations per | ||
| membership, and uses compare-and-set revisions for redemption and membership activation. | ||
| - The versioned invitation controller and IAM module composition now expose the acceptance flow | ||
| through the same replaceable repository and delivery ports; the HTTP boundary never returns the | ||
| raw token. | ||
| - The Prisma foundation test proves the schema diff and migration inventory include the new table. | ||
|
|
||
| ## Verification | ||
|
|
||
| - `corepack pnpm --filter @databreeze/api exec prisma validate --config prisma.config.ts` | ||
| - `corepack pnpm --filter @databreeze/api test` — 352 tests passed. | ||
| - `corepack pnpm --filter @databreeze/domain test` — 134 tests passed. | ||
| - `git diff --check` passed before commit. | ||
|
|
||
| ## Explicitly not complete | ||
|
|
||
| Transactional AUD append, registration for unknown recipients, resend/revocation administration, | ||
| an SMTP/SES delivery adapter, and production PostgreSQL/backup/security evidence remain future | ||
| work. IAM-010 therefore remains `partial` and `not-verified` in the requirement manifest. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,52 @@ | ||
| # IAM, audit, and entitlement security slice — 2026-08-03 | ||
|
|
||
| ## Scope | ||
|
|
||
| This evidence record covers the 30-commit `feat/iam-security-completion` batch based on | ||
| `origin/dev`. It is implementation evidence only. It does not claim that Plan 020 or any | ||
| P0/P1 release gate is complete. | ||
|
|
||
| ## Delivered | ||
|
|
||
| - IAM service-account identities now use bounded permissions, digest-only secrets, one-time | ||
| secret issuance, rotation, permanent revocation, last-use monotonicity, tenant-scoped | ||
| repositories, Prisma persistence, and versioned lifecycle HTTP contracts. | ||
| - AUD action vocabulary includes service-account lifecycle actions. Audit seal attestations | ||
| are canonical, independently signed, immutable, tenant-scoped, transaction-aware, and | ||
| available through in-memory and Prisma adapters with API verification. | ||
| - BUA entitlement snapshots validate their complete provider-independent plan projection. | ||
| Signed offline leases are bounded to 24 hours and snapshot expiry, bind revision and | ||
| security epoch, persist immutably, verify canonical payloads, and use a replaceable HMAC | ||
| signer or injected HSM/KMS-compatible signer. | ||
| - BUA and AUD module composition defaults to unavailable signing when key material is absent; | ||
| no secret is generated, logged, or committed by the repository. | ||
|
|
||
| ## Verification | ||
|
|
||
| - Domain build and 148 domain tests pass, including canonical lease acceptance, malformed plan | ||
| rejection, attestation binding, tenant ancestry, and signature tampering cases. | ||
| - Focused API TypeScript compilation, ESLint, Prisma validation, OpenAPI generation/check, | ||
| Redocly validation, and focused IAM/AUD/BUA tests pass. | ||
| - Prisma migrations are ordered and add only `bua.entitlement_leases` and | ||
| `aud.audit_seal_attestations`; no migration was applied to a live environment. | ||
| - Traceability entries for IAM-013, AUD-015, AUD-016, BUA-017, and BUA-018 remain `partial` | ||
| and `not-verified`. They point to the concrete code, tests, and this evidence record. | ||
|
|
||
| ## Security and rollback notes | ||
|
|
||
| - Lease payloads are canonicalized before signature verification; malformed, stale, expired, | ||
| overlong, wrong-scope, and tampered leases fail closed. | ||
| - Attestation storage never broadens a caller scope and rejects immutable-identity changes. | ||
| - HMAC keys must be at least 32 bytes and should be supplied by a secret manager. HMAC is a | ||
| portable default, not a replacement for a production KMS/HSM policy. | ||
| - Every commit on the feature branch is independently reversible. The migration commits must | ||
| be reverted only with a reviewed down-migration/restore procedure; no destructive rollback | ||
| was executed here. | ||
|
|
||
| ## Remaining gates | ||
|
|
||
| Full audit export/legal-hold/retention administration, atomic cross-module audit coordination, | ||
| offline authorization snapshots, entitlement reconciliation/usage exports, real PostgreSQL | ||
| integration, backup restoration, security assessment, and release evidence remain outstanding. | ||
| The feature PR targets `dev` without CodeRabbit; CodeRabbit remains reserved for the later | ||
| `dev` to `main` promotion PR and is invoked once there. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # IAM recovery slice — 2026-08-03 | ||
|
|
||
| This evidence records the partial account-recovery boundary delivered on `feat/iam-recovery`. | ||
| It does not claim that IAM-015 or the IAM plan is complete. | ||
|
|
||
| ## Scope | ||
|
|
||
| - Validate a bounded recovery request and return the same accepted response for known and unknown email addresses. | ||
| - Generate a short-lived, single-use bearer, deliver the raw value only through the delivery port, and persist only keyed HMAC digests. | ||
| - Consume the bearer exactly once and atomically rotate the Argon2id credential, advance the user security epoch, revoke active sessions and MFA factors, and mark MFA re-enrollment required. | ||
| - Clear the re-enrollment gate in the same MFA transaction when a newly enrolled factor is successfully verified; failed proofs do not clear it. | ||
| - Carry the live gate through credential lookup, session lookup, protected request context, and sign-in/current-session projections without trusting client-supplied state. | ||
| - Apply a bounded, replaceable recovery-admission port before account lookup; unknown and throttled addresses receive the same generic response. | ||
| - The `RedisRecoveryAdmissionAdapter` implements that port for horizontally scaled deployments. It accepts only keyed digests, namespaces counter keys, requires an injected atomic `INCR`/`PEXPIRE` implementation, and fails closed on malformed input or counter failure. The in-memory adapter remains the alpha default until a Redis client is provisioned. | ||
| - Completion attempts use a separate admission port and, when Redis is configured, a distinct `databreeze:iam:recovery:completion:v1:` namespace so email-request and token-brute-force limits cannot collide. | ||
| - Keep the public completion response free of bearer material; no session is automatically created. | ||
| - Select the Prisma recovery adapter only when persistence is configured, and fail closed when the delivery, digest, or password boundary is missing. | ||
|
|
||
| ## Evidence | ||
|
|
||
| - Recovery state-machine tests: `packages/domain/test/recovery-v1.test.mjs`. | ||
| - Abuse-control tests: `services/api/test/features/iam/recovery-admission.test.ts` and `redis-recovery-admission.adapter.test.ts`. | ||
| - In-memory transaction/service tests: `services/api/test/features/iam/recovery.service.test.ts`. | ||
| - Durable schema adapter and atomic side-effect tests: `services/api/test/features/iam/prisma-recovery-repository.test.ts`. | ||
| - MFA re-enrollment transaction tests: `services/api/test/features/iam/mfa.service.test.ts` and `services/api/test/features/iam/prisma-mfa-repository.test.ts`. | ||
| - Live principal/context propagation tests: `services/api/test/features/iam/prisma-credential-lookup.test.ts`, `services/api/test/features/iam/prisma-session-lifecycle.test.ts`, and `services/api/test/platform/http/session-tenant-context.test.ts`. | ||
| - Composition/controller/HTTP tests: `services/api/test/features/iam/recovery-composition.test.ts`, `recovery-controller.test.ts`, and `recovery-http.test.ts`. | ||
| - Public routes: `services/api/openapi/v1.json` (`POST /v1/auth/recovery` and `POST /v1/auth/recovery/complete`). | ||
| - Bilingual problem copy: `packages/i18n/src/catalogs-v1.ts` and `packages/i18n/test/catalogs-v1.test.mjs`. | ||
|
|
||
| ## Verification | ||
|
|
||
| The scoped API TypeScript build, recovery tests, i18n tests, OpenAPI generation/check, and Prisma validation passed on 2026-08-03. The requirement remains `partial` and `not-verified` until authenticated MFA re-enrollment enforcement, audit events, rate limits, abuse monitoring, restoration drills, and the complete IAM release gates are delivered. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,27 @@ | ||
| # IAM registration slice — 2026-08-03 | ||
|
|
||
| This evidence records the partial account-registration boundary delivered on `feat/iam-registration`. | ||
| It does not claim that IAM-001 or the IAM plan is complete. | ||
|
|
||
| ## Scope | ||
|
|
||
| - Normalize and validate the email, display name, locale, and password at the application boundary. | ||
| - Hash the password through the existing Argon2id password port; raw passwords never enter persistence. | ||
| - Create the user, credential, personal organization, workspace, internal project, and owner membership in one transaction. | ||
| - Keep duplicate-email responses generic and map persistence races to a safe rejection. | ||
| - Return a generic `202 Accepted` body (`{"accepted":true}`) from `POST /v1/auth/register`; the endpoint never returns hierarchy identifiers, bearer material, or an account-existence signal and never automatically creates a session. | ||
| - Apply bounded, domain-separated admission before Argon2id hashing: the control plane hashes the normalized client IP and normalized email into separate rate-limit namespaces, and the durable Redis adapter fails closed on counter errors. | ||
| - Select the Prisma registration adapter only when durable registration storage and the password boundary are configured; otherwise the endpoint fails closed. | ||
|
|
||
| ## Evidence | ||
|
|
||
| - Service and in-memory transaction tests: `services/api/test/features/iam/registration.service.test.ts`. | ||
| - Durable adapter and rollback tests: `services/api/test/features/iam/prisma-registration-repository.test.ts`. | ||
| - Composition and controller tests: `services/api/test/features/iam/registration-composition.test.ts` and `services/api/test/features/iam/registration-controller.test.ts`. | ||
| - HTTP and problem-details tests: `services/api/test/features/iam/registration-http.test.ts`. | ||
| - OpenAPI route: `services/api/openapi/v1.json` (`POST /v1/auth/register`). | ||
| - Bilingual error catalog coverage: `packages/i18n/src/catalogs-v1.ts` and `packages/i18n/test/catalogs-v1.test.mjs`. | ||
|
|
||
| ## Verification | ||
|
|
||
| The scoped API TypeScript build, registration tests, i18n tests, OpenAPI generation/check, and Redocly validation passed on 2026-08-04. The rollback test stages the row in the transaction before injecting a persistence failure, proving no partial hierarchy remains. Admission tests prove IP/email throttling occurs before password hashing and persistence. The requirement remains `partial` and `not-verified` until the complete IAM release gates, audit integration, recovery, MFA, and restoration evidence are delivered. |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Correct the migration list in the evidence record.
Lines 30-31 state that the migrations add only
bua.entitlement_leasesandaud.audit_seal_attestations. The same change set also containsservices/api/prisma/migrations/20260803060000_iam_service_accounts/migration.sql, which creates the service-account tables described at lines 11-13. Add that migration to the list so the evidence record matches the applied schema changes.🤖 Prompt for AI Agents