[Security] Preserve authentication source, service-account ceilings and tenant-only grants #21

Closed
opened 2026-09-08 00:59:22 +02:00 by zemion · 1 comment
Owner

Implemented locally: consistent cold/cache authentication, preserved service-account scope ceilings and provenance, tenant-only concrete credential permissions, SQL-bounded session listing. Regression coverage: full91-test Access suite and expanded4-test documentation suite passed. EN/DE documentation updated. Compatibility: accidental system/wildcard permissions on tenant API keys are intentionally no longer granted. Password-reset-required remains advisory until a complete password-change/recovery workflow is implemented; documentation now states that limitation accurately.

Coordinated review: GovOPlaN/govoplan-core#296. Changes are uncommitted/unpushed and this issue remains open pending publication and final integrated checks. No live application data was mutated.

Implemented locally: consistent cold/cache authentication, preserved service-account scope ceilings and provenance, tenant-only concrete credential permissions, SQL-bounded session listing. Regression coverage: full91-test Access suite and expanded4-test documentation suite passed. EN/DE documentation updated. Compatibility: accidental system/wildcard permissions on tenant API keys are intentionally no longer granted. Password-reset-required remains advisory until a complete password-change/recovery workflow is implemented; documentation now states that limitation accurately. Coordinated review: GovOPlaN/govoplan-core#296. Changes are uncommitted/unpushed and this issue remains open pending publication and final integrated checks. No live application data was mutated.
Author
Owner

Implemented and released in Access0.1.25: consistent cold/cached authentication-source handling, preserved service-account provenance/current ceilings, tenant-only credential grants, and SQL-bounded session listing. The91-test Access suite, four documentation tests, and final integrated gate passed. EN/DE documentation covers the intentional removal of accidental system/wildcard permissions. Forced-password-change enforcement remains advisory and is deliberately left to Access #22.

Publication evidence: Meta #51 records verified source tags, native packages and signed catalog Git publication. catalog-v0.1.45 is commit 03ac237949a1963189d1b7a4b3cc3397e60b10a1, annotated tag object 3d4735ea3028edfa47341e4f0b53650a4ae868d6, sequence 202609080236; exact stable.json SHA-256 00dd1fa8390b7823dc082eddaca0bd826f9fcee0c479f56cd82ea55f93bf3cc8.

This is not a live website deployment: a fresh public read still serves0.1.18/sequence202608061915. Website #9 owns authorized website rollout and its separate image-review gates. No application runtime distribution was published; Meta #52 remains held. No real mail/file/workflow operations or deployment were used to verify this closure.

<!-- govoplan-release-0.1.45-bounded-close:govoplan-access:21 --> Implemented and released in Access0.1.25: consistent cold/cached authentication-source handling, preserved service-account provenance/current ceilings, tenant-only credential grants, and SQL-bounded session listing. The91-test Access suite, four documentation tests, and final integrated gate passed. EN/DE documentation covers the intentional removal of accidental system/wildcard permissions. Forced-password-change enforcement remains advisory and is deliberately left to [Access #22](https://git.add-ideas.de/GovOPlaN/govoplan-access/issues/22). Publication evidence: [Meta #51](https://git.add-ideas.de/GovOPlaN/govoplan/issues/51) records verified source tags, native packages and signed catalog Git publication. [catalog-v0.1.45](https://git.add-ideas.de/add-ideas/addideas-govoplan-website/src/tag/catalog-v0.1.45/public/catalogs/v1/channels/stable.json) is commit `03ac237949a1963189d1b7a4b3cc3397e60b10a1`, annotated tag object `3d4735ea3028edfa47341e4f0b53650a4ae868d6`, sequence `202609080236`; exact stable.json SHA-256 `00dd1fa8390b7823dc082eddaca0bd826f9fcee0c479f56cd82ea55f93bf3cc8`. This is not a live website deployment: a fresh public read still serves0.1.18/sequence202608061915. [Website #9](https://git.add-ideas.de/add-ideas/addideas-govoplan-website/issues/9) owns authorized website rollout and its separate image-review gates. No application runtime distribution was published; [Meta #52](https://git.add-ideas.de/GovOPlaN/govoplan/issues/52) remains held. No real mail/file/workflow operations or deployment were used to verify this closure.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-access#21