mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-06 17:02:01 +00:00
docs: update CLAUDE.md audit status for Phase 5
This commit is contained in:
parent
af4ba1bfb7
commit
8212c48d1e
1 changed files with 22 additions and 2 deletions
24
CLAUDE.md
24
CLAUDE.md
|
|
@ -17,7 +17,7 @@ Proposal management platform for Sea Haven Industries. Dispatchers submit servic
|
||||||
## Auth Model
|
## Auth Model
|
||||||
|
|
||||||
External: Cognito JWT via API Gateway (web + mobile client IDs, groups: dispatchers/admins/sysadmins)
|
External: Cognito JWT via API Gateway (web + mobile client IDs, groups: dispatchers/admins/sysadmins)
|
||||||
Internal: Lambdas call .NET Function URL with Secrets Manager API key via custom middleware
|
Internal: Lambdas → .NET Function URL with Secrets Manager API key via custom middleware
|
||||||
|
|
||||||
## Request Flow
|
## Request Flow
|
||||||
|
|
||||||
|
|
@ -54,4 +54,24 @@ AWS us-east-1, RDS PostgreSQL 15, S3, SQS+DLQ, Cognito+Google OAuth, OpenSearch
|
||||||
- **Critical**: security/data exposure/auth bypass/data corruption
|
- **Critical**: security/data exposure/auth bypass/data corruption
|
||||||
- **High**: broken core workflow, deployment blocker, missing authz, invalid infra
|
- **High**: broken core workflow, deployment blocker, missing authz, invalid infra
|
||||||
- **Medium**: reliability, validation, logging, test gaps
|
- **Medium**: reliability, validation, logging, test gaps
|
||||||
- **Low**: cleanup, DX, docs, polish
|
- **Low**: cleanup, DX, docs, polish
|
||||||
|
|
||||||
|
## Audit Status
|
||||||
|
|
||||||
|
AUDIT-REPORT.md completed 2026-05-27. 5 Critical, 36 High, 75+ Medium, 60+ Low findings. Phase 1-5 complete: all Critical/High fixed, 17 Medium fixed, CI runs 108 tests.
|
||||||
|
|
||||||
|
### Critical Findings (fix first)
|
||||||
|
|
||||||
|
- **API-C1**: InternalApiKeyMiddleware applies globally, bypasses JWT on any route
|
||||||
|
- **API-C2**: JWT signature validation skipped when Authority is empty
|
||||||
|
- **WEB-C1**: JWT stored in localStorage (XSS token theft)
|
||||||
|
- **LAM-C1 / INF-H1**: Function URL authType NONE, publicly accessible
|
||||||
|
- **QA-C1**: Zero test coverage, no test projects, CI runs no tests
|
||||||
|
|
||||||
|
### Remediation Conventions
|
||||||
|
|
||||||
|
- Reference finding IDs (API-C1, WEB-H3, LAM-H4, etc.) in commit messages and code comments
|
||||||
|
- Format: `// Fix: API-C1 — scope internal key to /internal/ paths`
|
||||||
|
- Update AUDIT-REPORT.md after each phase: mark fixed findings, note deferred items
|
||||||
|
- Parallel-safe worktree splits: api/ changes, web/ changes, and infra/ changes don't conflict
|
||||||
|
- Verify after each phase: `dotnet build` (api), `npx tsc --noEmit` (web), `npx cdk synth` (infra)
|
||||||
Loading…
Add table
Reference in a new issue