Skip to content

[security] proposal list cross-actor recon within namespace #395

@ohdearquant

Description

@ohdearquant

Integration codex security review S-2.

list(kind=proposal, proposer=X) lets any caller enumerate any other actor's proposals within a namespace. Within-tenant cross-actor reconnaissance.

Multi-actor fix: filter results to caller's actor unless explicit moderator capability. OSS single-user unaffected.

Metadata

Metadata

Assignees

No one assigned

    Labels

    adr-alignmentADR v1 series alignment workfollow-upDeferred from another PR

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions