From bdfb375b9fdc601cf8d2973778ff30cc025f2682 Mon Sep 17 00:00:00 2001 From: JOY <5027251+JOY@users.noreply.github.com> Date: Sat, 12 Sep 2026 22:01:30 +0700 Subject: [PATCH] docs(audit): retract SEC-14, add SEC-26, and record the v1.7.0 release SEC-14 claimed the BindEnv order let ambient legacy variables such as PORT and DATABASE_URL override the documented AGENT_DESK_* configuration. That is false, and two independent checks prove it. A test that sets both spellings to conflicting values still resolves to the prefixed one after the order is deliberately reversed, and viper 1.21 find() at viper.go:1227-1245 returns from getEnv(mergeWithEnvPrefix(...)) before it ever reaches the alias list, because Load enables AutomaticEnv with SetEnvPrefix. The 51-line reorder in 0c6b9061 is therefore a no-op - and it reached upstream/main through PR #39 carrying a comment that describes the wrong mechanism. The reorder stays, to avoid diverging from upstream; the comment no longer misstates how it works. The DSN half of SEC-14 was real and is fixed in 910bd4f0. Add SEC-26. Nothing in the repository calls SetTrustedProxies, sets TrustedPlatform or touches ForwardedByClientIP, so Gin runs on defaultTrustedCIDRs = [0.0.0.0/0, ::/0] (gin.go:39-47). validateHeader (gin.go:482-501) then walks X-Forwarded-For right to left and only stops at an untrusted proxy, so with everything trusted it returns the leftmost, client-supplied value. ctx.ClientIP() is forgeable with a single header, which means t_login_credential_log.client_ip and t_user.last_login_ip are already recording attacker-chosen values, and any IP-keyed rate limit or lockout built on top would be bypassable. That makes SEC-26 a prerequisite for SEC-08 and SEC-09 rather than a peer of them. Gin ships PlatformCloudflare = "CF-Connecting-IP" (gin.go:85), which matches this deployment. Also record: the v1.7.0-crove.1 release and how the published image digest and revision label were read from the build log, why the tag carries a -crove.N suffix, SEC-02 downgraded from Done to Partial because the plaintext password response is an intentional feature, PROC-01 closed by PR #6, the release-skill rewrite, the four new AGENTS.md rules, and the near-miss in which a parallel session moved HEAD onto its own feature branch and a git merge --ff-only was issued against that branch. Register 114 -> 115, P1 21 -> 22, SEC 25 -> 26. Every declared count in the document is cross-checked against the register tables by script, covering 24 declaration sites, because three earlier arithmetic errors in this file were caught the same way. --- docs/CROVE_DESK_AUDIT.html | 56 ++++++++++++++++++++++++++------------ 1 file changed, 39 insertions(+), 17 deletions(-) diff --git a/docs/CROVE_DESK_AUDIT.html b/docs/CROVE_DESK_AUDIT.html index c5eb5a8e..a07af88b 100644 --- a/docs/CROVE_DESK_AUDIT.html +++ b/docs/CROVE_DESK_AUDIT.html @@ -3,7 +3,7 @@ -Crove Desk — Audit & Issue Register (v4) +Crove Desk — Audit & Issue Register (v5)