fix(auth): fail closed without write-capable admin on public bind - #155
fix(auth): fail closed without write-capable admin on public bind#155seonghobae wants to merge 19 commits into
Conversation
|
Warning Review limit reachedNext included review available in 53 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh exact-head revalidation (2026-09-03 KST): protected base is still The current-PR required OpenCode lane is still non-terminal: run No source churn, self-approval, routine bypass, or predecessor/wrong-PR evidence reuse is warranted. Re-read the unchanged head after the central lane becomes terminal, then apply the live solo-maintainer ruleset once its owner repair converges. |
Fixes #78 only when this exact candidate reaches protected
main.Security boundary
Wardnet must never expose unauthenticated management writes on a non-loopback listener. Loopback-only development may remain credential-free, but production-facing binds require a write-capable administrator credential before readiness. The bounded delta rejects missing/ambiguous write authority, preserves
401vs403, constant-time token comparison, readonly/write separation, andauth_mode=developmentonly for loopback credential-free operation.Protected/default
mainremains5829a0f08d78de464dd24393ce5d0f25fba9d126. Current exact headf74ff25a321dfb1d7109719e2a1fc77e47dc4898is non-destructively aligned with that protected truth; no force push or destructive rebase was used.Exact-head evidence — 2026-09-06 KST
33904633002— SUCCESS;33904632999— SUCCESS;33904633208— SUCCESS;33904633082— SUCCESS;33904632978— historical terminal FAILURE in the central delegated dispatch/verdict path, not an authentication source finding.The central implementation has advanced since that CodeQL failure:
.github#1926and.github#1932are protected. Remaining trusted-dispatcher settings/canary convergence is.github#1929, which must preserve both intended sendersgithub-actions[bot]andopencode-agent[bot]with actor==sender validation. Do not no-op churn or repeatedly rerun this unchanged clean authentication head before that owner plane can produce an authenticated verdict.Live ruleset
18156473still carries the structurally impossible generic one-approval requirement for the declared solo-maintainer model and routine administrator bypass..github#772owns that governance repair; self/model approval and routine bypass remain forbidden.Merge only through the ordinary protected path after unchanged
f74ff25...has every then-live deterministic/security/coverage/package/SBOM/provenance/review/thread gate terminal-valid, fresh protected-base compatibility, and governance satisfiable without fabricated approval. No force push/destructive rebase, gate weakening, predecessor-evidence reuse or routine bypass.