Skip to content

#164: Expose an authorization-scoped stored-evidence passive auth tracer - #150

Merged
justsml merged 7 commits into
mainfrom
dan/issue-21-artifact-browser
Aug 28, 2026
Merged

#164: Expose an authorization-scoped stored-evidence passive auth tracer#150
justsml merged 7 commits into
mainfrom
dan/issue-21-artifact-browser

Conversation

@justsml

@justsml justsml commented Aug 27, 2026

Copy link
Copy Markdown
Owner

Closes #162
Closes #163
Closes #164

Scope

  • Normalize bounded passive discovery evidence into deterministic auth-surface candidates, blockers, and provenance.
  • Persist passive auth summaries through the canonical artifact and RAG path.
  • Expose a bounded passive-auth tracer over already-stored evidence.
  • Require exact target authorization and authoritative stored source/target provenance.
  • Reject raw client evidence, caller-supplied labels, cross-target collection artifacts, and unsupported or oversized inputs before persistence or indexing.
  • Allow curated project-scoped reference evidence while keeping collection evidence target-bound.
  • Perform no network, browser, shell, or download work.

Verification

  • 7 focused integration tests pass across the passive tracer, normalizer, and ArtifactService read-contract consumer.
  • Typecheck passes.
  • Targeted Biome and diff checks pass for the new surface.

@justsml justsml mentioned this pull request Aug 27, 2026
19 tasks
@justsml justsml changed the title #21: Normalize and persist passive reconnaissance evidence #164: Expose an authorization-scoped stored-evidence passive auth tracer Aug 27, 2026
@justsml
justsml changed the base branch from main to dan/issue-163-passive-auth-summary August 27, 2026 06:00
@justsml

justsml commented Aug 27, 2026

Copy link
Copy Markdown
Owner Author

Council of Dans review: repair/defer. Highest-priority gate: Add a durable report fingerprint/idempotency contract so retries do not duplicate Artifact rows, blobs, or RAG chunks; land only with redaction and attribution prerequisites. Feature flags are not a substitute for authority, evidence-integrity, or durability fixes; use typed modes only where they provide a real rollout boundary.

@justsml
justsml changed the base branch from dan/issue-163-passive-auth-summary to main August 28, 2026 14:43
@justsml
justsml merged commit 5f5a1f3 into main Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant