Albrecht Degering zemion
  • Joined on 2025-08-22
zemion pushed to main at GovOPlaN/govoplan-campaign 2026-08-04 10:51:51 +02:00
9137300780 Add bulk recipient activation controls
zemion commented on issue GovOPlaN/govoplan-files#35 2026-08-04 10:41:53 +02:00
[Security] Re-enable SMB connectors only with pinned peers and DFS referrals

Codex State: progress

Summary

  • Implemented a Files-owned SMB session/cache boundary with exact connection-time peer pinning for initial connections, reconnects, aliases, and DFS referral…
zemion closed issue GovOPlaN/govoplan-files#34 2026-08-04 10:41:33 +02:00
[Security] Re-enable S3 connectors only with pinned SDK peers and redirects
zemion commented on issue GovOPlaN/govoplan-files#34 2026-08-04 10:41:33 +02:00
[Security] Re-enable S3 connectors only with pinned SDK peers and redirects

Codex State: done

Summary

  • Implemented exact connection-time peer pinning for every S3 SDK socket, including retries, redirects, endpoint discovery, and provider-selected aliases while…
zemion pushed to main at GovOPlaN/govoplan-files 2026-08-04 10:40:56 +02:00
92e649477f Pin S3 and SMB connector peers
zemion closed issue GovOPlaN/govoplan-core#278 2026-08-04 10:08:12 +02:00
[Feature] Controlled one-time production administrator enrollment
zemion commented on issue GovOPlaN/govoplan-core#278 2026-08-04 10:08:12 +02:00
[Feature] Controlled one-time production administrator enrollment

Codex State: done

Summary

  • Implemented an expiring, random, single-use production first-administrator credential with a mode-0600 local artifact and no secret console output.
  • Added a…
zemion pushed to main at GovOPlaN/govoplan 2026-08-04 10:07:54 +02:00
9e956eec6f Classify first-run bootstrap endpoints
zemion pushed to main at GovOPlaN/govoplan-access 2026-08-04 10:07:39 +02:00
668f7cf108 Provide first system administrator authority
zemion pushed to main at GovOPlaN/govoplan-core 2026-08-04 10:07:34 +02:00
25da7d49a9 Add controlled first-admin enrollment
zemion closed issue GovOPlaN/govoplan-core#282 2026-08-04 09:32:17 +02:00
[Task] Enforce tenant module entitlements across non-request execution paths
zemion commented on issue GovOPlaN/govoplan-core#282 2026-08-04 09:32:17 +02:00
[Task] Enforce tenant module entitlements across non-request execution paths

Codex State: done

Summary

  • Tenant-effective module policy now gates authenticated and signed-link routes, capability lookup, scheduled scans, durable consumers, outboxes, and background…
zemion pushed to main at GovOPlaN/govoplan-workflow-engine 2026-08-04 09:32:00 +02:00
6e0fcf6b3b Partition workflow execution by tenant
zemion pushed to main at GovOPlaN/govoplan-scheduling 2026-08-04 09:31:37 +02:00
9fd2ccd0a5 Enforce tenant policy on public scheduling links
zemion pushed to main at GovOPlaN/govoplan-poll 2026-08-04 09:31:32 +02:00
3c126a7ee1 Resolve public poll invitations to tenant policy
zemion pushed to main at GovOPlaN/govoplan-notifications 2026-08-04 09:31:18 +02:00
bb59342b24 Resolve notification worker items to tenants
zemion pushed to main at GovOPlaN/govoplan-mail 2026-08-04 09:30:37 +02:00
7c8cb21144 Partition mail retention by tenant
zemion pushed to main at GovOPlaN/govoplan-dataflow 2026-08-04 09:30:34 +02:00
42f87ddc88 Partition dataflow workers by tenant
zemion pushed to main at GovOPlaN/govoplan-campaign 2026-08-04 09:30:19 +02:00
f98fe06143 Resolve campaign worker jobs to tenants
zemion pushed to main at GovOPlaN/govoplan-calendar 2026-08-04 09:30:14 +02:00
00add294a8 Gate calendar sync workers by tenant entitlement