fix(auth): fail closed without write-capable admin on public bind - #155
Merged
seonghobae merged 20 commits intoSep 11, 2026
Conversation
|
Warning Review limit reachedNext included review available in 53 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Sep 2, 2026
This was referenced Sep 11, 2026
seonghobae
added a commit
that referenced
this pull request
Sep 11, 2026
…istence Ordinary reverse-direction adoption of protected #155 into the bounded deterministic-persistence branch. Preserve feature delta and protected auth/security invariants; no force or rebase.
seonghobae
added a commit
that referenced
this pull request
Sep 11, 2026
…trols Ordinary reverse-direction adoption of protected #155 into Wardnet-owned CI/Fuzz source-head and concurrency controls. Preserve central-owner boundaries and existing workflow semantics.
seonghobae
added a commit
that referenced
this pull request
Sep 11, 2026
…cture Ordinary reverse-direction adoption of protected #155 into the Proposed Wardnet reputation architecture branch. Preserve EgressWeave ownership boundary and non-runtime status.
This was referenced Sep 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #78 only when this exact candidate reaches protected
main.Security boundary
Wardnet must never expose unauthenticated management writes on a non-loopback listener. Loopback-only development may remain credential-free, but production-facing binds require a write-capable administrator credential before readiness. The bounded delta rejects missing/ambiguous write authority, preserves
401vs403, constant-time token comparison, readonly/write separation, andauth_mode=developmentonly for loopback credential-free operation.Protected-main adoption
Prior exact candidate
f74ff25a321dfb1d7109719e2a1fc77e47dc4898was already non-destructively aligned with protected5829a0f08d78de464dd24393ce5d0f25fba9d126. Protected/defaultmainthen advanced through #171 to exacta52ccd0a24a727d9349bb32def7713882d8cad1e.Fresh comparison proved the intervening protected delta is only
docs/adr/2026-09-05-anti-bot-acquisition-boundary.mdplusdocs/adr/README.md, neither overlapping this authentication/security delta. Two-parent mergefb93b61a4a4da30a3471453051ebfb0ed3f63d34adopted that protected truth without force push or destructive rebase. Current compare remains merge-base=a52ccd0..., behind 0; the effective feature delta remains the same 13 authentication/deployment/test/doctoring paths.Exact-current evidence — 2026-09-07 KST
Current exact source remains unchanged
fb93b61a4a4da30a3471453051ebfb0ed3f63d34, Ready/mechanically mergeable on protectedmain. The earlier no-run snapshot is superseded. Without source churn, current gates have executed:34020141305: SUCCESS;34020141277: SUCCESS;34020141306: SUCCESS;34020141279: SUCCESS;34020141314: FAILURE only at delegated terminal-verdict enforcement.CodeQL detect-language job
101451083576is terminal success. Compatibility job101455725295also acquired a hosted runner and completedRequest current-head CodeQL scan dispatch; it fails only atRelease runner or enforce current-head CodeQL verdict. This is the same central authenticated dispatcher/verdict boundary tracked in.github#712/ the live CodeQL owner path, not a management-authentication source/test failure. Do not source-churn this unchanged security candidate, transfer predecessor verdicts, or weaken CodeQL.Ready metadata is not merge authorization. Live organization ruleset
18156473still carries the structurally incompatible solo-maintainer generic approval count plus routineOrganizationAdmin/alwaysbypass tracked by.github#772. Self/model approval, routine or implicit administrator bypass, force push, destructive rebase and merge-as-probe remain forbidden.Merge only through the ordinary protected path after one unchanged exact head has an authenticated terminal current-source CodeQL verdict, zero valid unresolved findings/threads, fresh candidate-base compatibility, and every then-live deterministic/security/coverage/package/SBOM/provenance/governance requirement terminal-valid.