Skip to content

feat: small change for drift test run - #4

Open
xntrik wants to merge 1 commit into
mainfrom
drift-change
Open

xntrik wants to merge 1 commit into
mainfrom
drift-change

Conversation

@xntrik

@xntrik xntrik commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

Copy link
Copy Markdown

Threat Drift Review by Threatcl

🧟 Phantom controls (0) · 📜 Stale assertions (0) · 🆕 Unmodeled surface (1)
🗺 DFD drift (1) · 📦 Dependency drift (0) · 🔎 Unclassified data (0)

Two review-recommended drift findings were found; the highest-priority issue is the unmodeled delivery of Restricted telemetry to caller-nominated HTTPS destinations.

Context used
  • ✅ Threat model: threatmodel/sensorhub.tm.hcl — 6 threats, 6 controls (6 implemented), 4 information assets, 1 third-party dependency, 1 data flow diagram
  • 📄 Diff: 2 of 2 changed files reviewed
  • 🤖 Analysis: gpt-5.6-sol at high effort, over 2 of 2 changed file(s)

Review recommended

1. Caller-nominated telemetry delivery is an unmodeled attack surface — 🆕 Unmodeled surface

Model excerpt — threatmodel/sensorhub.tm.hcl:31

information_asset "telemetry_data" classification=Restricted

Code evidence

  • internal/dashboard/server.go:56 — Registers a new authenticated POST endpoint for fleet-export delivery.
  • internal/dashboard/server.go:145 — The request body supplies the outbound destination URL.
  • internal/dashboard/server.go:152 — Destination validation requires HTTPS and a host but does not constrain the nominated host further.
  • internal/dashboard/server.go:158 — Renders the tenant's fleet telemetry CSV into the outbound request buffer.
  • internal/dashboard/server.go:166 — Builds a server-side POST request to the caller-nominated destination with the telemetry CSV as its body.
  • internal/dashboard/server.go:173 — Executes the new outbound request through the default HTTP client.

Relevance: strong — The change adds a new network and deserialization surface that transmits a modeled Restricted asset to caller-controlled destinations, but no threat or control assertion represents that behavior.

Suggested fix: Add a telemetry-export delivery threat and accurately implemented destination-validation and egress controls.

Agent prompt
Update threatmodel/sensorhub.tm.hcl in threatmodel "SensorHub": add a threat covering the authenticated POST /api/fleet/export/deliver route and its server-side delivery of Restricted telemetry_data to a caller-nominated HTTPS URL. The route is registered at internal/dashboard/server.go:56, accepts the destination at line 145, validates only its scheme and host at line 152, and sends the CSV at lines 166 and 173. Associate the threat with telemetry_data and document controls for destination authorization, private-network and redirect handling, and outbound egress policy; mark controls implemented only where code and tests enforce them.
2. Outbound telemetry export flow is absent from the DFD — 🗺 DFD drift

Model excerpt — threatmodel/sensorhub.tm.hcl:264

data_flow_diagram_v2 "sensorhub"

Code evidence

  • internal/dashboard/server.go:158 — Builds a CSV containing tenant fleet telemetry for delivery.
  • internal/dashboard/server.go:166 — Creates a new Dashboard API outbound flow to a dynamically supplied URL.
  • internal/dashboard/server.go:173 — Sends the telemetry to the external destination.

Relevance: strong — The modeled DFD has no external reporting destination or Dashboard API outbound telemetry flow corresponding to this newly implemented trust-boundary crossing.

Suggested fix: Add the caller-nominated export destination and Dashboard API-to-destination telemetry flow to the sensorhub DFD.

Agent prompt
Update threatmodel/sensorhub.tm.hcl in data_flow_diagram_v2 "sensorhub": add an external element such as "Caller-Nominated Export Destination" in the appropriate external trust zone and an outbound flow from "Dashboard API" to that element carrying telemetry_data. This is required because internal/dashboard/server.go:158 renders fleet telemetry into a buffer, line 166 creates a POST to the supplied destination, and line 173 sends it externally.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant