mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 06:33:13 +00:00
docs(claude): strip completed-audit process relics from CLAUDE.md (#261)
Remove the Audit Status section, Agent Delegation Rules pipeline, severity levels, critical-findings list, 65% context pause rule, and AUDIT-REPORT.md references now that the 2026-05-27 audit and remediation are complete. Keep the finding-ID convention (API-C1, WEB-H3, etc.) since those IDs are still embedded in code comments and commit history, and leave all arch/ADR/ infra content untouched.
This commit is contained in:
parent
d2d95a952c
commit
eb5ddb4bd3
1 changed files with 5 additions and 36 deletions
41
CLAUDE.md
41
CLAUDE.md
|
|
@ -37,47 +37,16 @@ Internal: Lambdas → .NET Function URL with Secrets Manager API key via custom
|
|||
|
||||
Deploys to the **seahaven-prod** account (`011934824531`), us-east-1. (mgmt `328440206208` is frozen for workloads; staging is hard-disabled in `infra/lib/config.ts` until retargeted to seahaven-dev `710827005802`.) Aurora PostgreSQL 15 Serverless v2 (RDS Data API + pgvector), S3, SQS+DLQ, Cognito+Google OAuth, Bedrock KB (Aurora pgvector store — ADR 0001), GitHub Actions OIDC, CloudFront+S3 OAC. Prod deploys run via the `deploy.yaml` pipeline (workflow_dispatch) only — no local `cdk deploy` to prod.
|
||||
|
||||
## Agent Delegation Rules
|
||||
|
||||
### For audit and hardening work, use the Explore-Plan-Execute pipeline:
|
||||
|
||||
1. Spawn specialist subagents for parallel investigation (api-security, web-audit, mobile-audit, lambda-pipeline, infra-cicd, qa-testing)
|
||||
2. Consolidate findings into AUDIT-REPORT.md before implementing
|
||||
3. Prioritize: Critical > High > Medium > Low
|
||||
4. Implement fixes in logical phases, commit after each phase
|
||||
5. Use separate git worktrees/branches for parallel implementation where safe
|
||||
|
||||
### Working Rules
|
||||
## Working Rules
|
||||
|
||||
- Never commit secrets, credentials, .env files, or local artifacts
|
||||
- If secrets found in code: document, remove safely, ensure proper config mechanism
|
||||
- Preserve existing business logic unless broken, insecure, or contradicted
|
||||
- Run lint/typecheck/build/test after each phase
|
||||
- If context reaches 65%, pause, commit, update AUDIT-REPORT.md with HANDOFF ADDENDUM
|
||||
|
||||
### Severity Levels
|
||||
## Finding-ID Convention
|
||||
|
||||
- **Critical**: security/data exposure/auth bypass/data corruption
|
||||
- **High**: broken core workflow, deployment blocker, missing authz, invalid infra
|
||||
- **Medium**: reliability, validation, logging, test gaps
|
||||
- **Low**: cleanup, DX, docs, polish
|
||||
Code comments and commit messages reference finding IDs from a prior security-audit remediation (e.g. `API-C1`, `WEB-H3`, `LAM-H4`). These IDs are embedded directly in the codebase, so keep the convention documented:
|
||||
|
||||
## Audit Status
|
||||
|
||||
AUDIT-REPORT.md completed 2026-05-27. 5 Critical, 36 High, 75+ Medium, 60+ Low findings. Phase 1-5 complete: all Critical/High fixed, 17 Medium fixed, CI runs 186 tests (123 xUnit, 26 vitest, 37 pytest).
|
||||
|
||||
### Critical Findings (fix first)
|
||||
|
||||
- **API-C1**: InternalApiKeyMiddleware applies globally, bypasses JWT on any route
|
||||
- **API-C2**: JWT signature validation skipped when Authority is empty
|
||||
- **WEB-C1**: JWT stored in localStorage (XSS token theft)
|
||||
- **LAM-C1 / INF-H1**: Function URL authType NONE, publicly accessible
|
||||
- **QA-C1**: Zero test coverage, no test projects, CI runs no tests
|
||||
|
||||
### Remediation Conventions
|
||||
|
||||
- Reference finding IDs (API-C1, WEB-H3, LAM-H4, etc.) in commit messages and code comments
|
||||
- Format: `// Fix: API-C1 — scope internal key to /internal/ paths`
|
||||
- Update AUDIT-REPORT.md after each phase: mark fixed findings, note deferred items
|
||||
- Parallel-safe worktree splits: api/ changes, web/ changes, and infra/ changes don't conflict
|
||||
- Verify after each phase: `dotnet build` (api), `npx tsc --noEmit` (web), `npx cdk synth` (infra)
|
||||
- Reference finding IDs in commit messages and code comments
|
||||
- Format: `// Fix: API-C1 — scope internal key to /internal/ paths`
|
||||
Loading…
Add table
Reference in a new issue