From 8212c48d1e88d8c1311246af899a6a431228fe99 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 27 May 2026 17:56:43 -0400 Subject: [PATCH] docs: update CLAUDE.md audit status for Phase 5 --- CLAUDE.md | 24 ++++++++++++++++++++++-- 1 file changed, 22 insertions(+), 2 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 405fc39..fa96f5a 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -17,7 +17,7 @@ Proposal management platform for Sea Haven Industries. Dispatchers submit servic ## Auth Model External: Cognito JWT via API Gateway (web + mobile client IDs, groups: dispatchers/admins/sysadmins) -Internal: Lambdas call .NET Function URL with Secrets Manager API key via custom middleware +Internal: Lambdas → .NET Function URL with Secrets Manager API key via custom middleware ## Request Flow @@ -54,4 +54,24 @@ AWS us-east-1, RDS PostgreSQL 15, S3, SQS+DLQ, Cognito+Google OAuth, OpenSearch - **Critical**: security/data exposure/auth bypass/data corruption - **High**: broken core workflow, deployment blocker, missing authz, invalid infra - **Medium**: reliability, validation, logging, test gaps -- **Low**: cleanup, DX, docs, polish \ No newline at end of file +- **Low**: cleanup, DX, docs, polish + +## Audit Status + +AUDIT-REPORT.md completed 2026-05-27. 5 Critical, 36 High, 75+ Medium, 60+ Low findings. Phase 1-5 complete: all Critical/High fixed, 17 Medium fixed, CI runs 108 tests. + +### Critical Findings (fix first) + +- **API-C1**: InternalApiKeyMiddleware applies globally, bypasses JWT on any route +- **API-C2**: JWT signature validation skipped when Authority is empty +- **WEB-C1**: JWT stored in localStorage (XSS token theft) +- **LAM-C1 / INF-H1**: Function URL authType NONE, publicly accessible +- **QA-C1**: Zero test coverage, no test projects, CI runs no tests + +### Remediation Conventions + +- Reference finding IDs (API-C1, WEB-H3, LAM-H4, etc.) in commit messages and code comments +- Format: `// Fix: API-C1 — scope internal key to /internal/ paths` +- Update AUDIT-REPORT.md after each phase: mark fixed findings, note deferred items +- Parallel-safe worktree splits: api/ changes, web/ changes, and infra/ changes don't conflict +- Verify after each phase: `dotnet build` (api), `npx tsc --noEmit` (web), `npx cdk synth` (infra) \ No newline at end of file