mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-09-30 04:13:14 +00:00
docs: repoint pending cross_reviewer follow-ups to security-review cross_review.py (#30)
Some checks failed
deploy / deploy (push) Has been cancelled
Some checks failed
deploy / deploy (push) Has been cancelled
This commit is contained in:
parent
6766a15dcf
commit
faa497de73
2 changed files with 21 additions and 7 deletions
|
|
@ -262,6 +262,11 @@ reviewer applied AWS/CDK conventions to a Salesforce-deploying repo and over-cla
|
|||
Pattern holds (per `feedback_fable_review_gates`): cross-family reviewers assert convention-application
|
||||
confidently — verify and correct, don't adopt wholesale. Structural verdict unchanged: sound, auth spike-gated.
|
||||
|
||||
> Note: the orchestrator repo was archived 2026-07-14; cross-family review now runs via
|
||||
> `python3 ~/Documents/repositories/seahaven/security-review/cross_review.py` (repo
|
||||
> `Sea-Haven-Industries/security-review`). Mentions of `cross_reviewer` below are historical,
|
||||
> naming the reviewer as it was invoked through the now-retired orchestrator.
|
||||
|
||||
**Cross-family review (GPT-4.1 `cross_reviewer`, 2026-06-11) — auth/trifecta sections.** Run per the mandatory
|
||||
cross-review gate for auth/IAM design (Fable is Claude-family, not a substitute). Findings folded in:
|
||||
- **CR-1 (BLOCK):** validate `aud` at the edge **AND** server-side (defense in depth) — the per-tier authorizer
|
||||
|
|
@ -273,8 +278,10 @@ cross-review gate for auth/IAM design (Fable is Claude-family, not a substitute)
|
|||
- **CR-3 (FIX):** pre-token Lambda fails closed + alarms if any cross-audience scope would appear. → §0.1 B4, §1h.
|
||||
- **CR-5 (FIX):** pre-token + group-sync are the auth SPOF — alarms + freshness bound on group claims. → §0.1 B4, §4.
|
||||
- **CR-4/CR-7 (NIT):** restrict each Cognito app client's allowed scopes; WAF is defense-in-depth only. → §0.1.
|
||||
Re-run `cross_reviewer` on the concrete pre-token Lambda + IAM/Cognito resource-server config once written
|
||||
(design.md §10 asked for the real artifacts).
|
||||
Re-run cross-family review via
|
||||
`python3 ~/Documents/repositories/seahaven/security-review/cross_review.py` (the orchestrator's
|
||||
`cross_reviewer` is retired as of 2026-07-14) on the concrete pre-token Lambda + IAM/Cognito
|
||||
resource-server config once written (design.md §10 asked for the real artifacts).
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -471,7 +478,9 @@ handbook is one-deploy-target-per-repo. Coexistence:
|
|||
read the JWT key, since the actual deploy target is the Salesforce org, not AWS.
|
||||
- **Cross-review gate extends to Agentforce metadata** that changes tool exposure, audience, or scope binding —
|
||||
security-relevant just like an IAM diff (design.md §8). `ASSUMPTION`: GenAiPlannerBundle/connection changes and
|
||||
the `cd-sfdx` connected-app trust go through `cross_reviewer` (GPT-4.1) the same as IAM.
|
||||
the `cd-sfdx` connected-app trust go through cross-family review (GPT-4.1, now run via
|
||||
`python3 ~/Documents/repositories/seahaven/security-review/cross_review.py` — the orchestrator's
|
||||
`cross_reviewer` retired 2026-07-14) the same as IAM.
|
||||
- **Naming boundary (N3):** Salesforce Developer/API names (`Seahaven_Ops`, Flex template names) **cannot contain
|
||||
hyphens** and conventionally use PascalCase/snake. The handbook kebab-case rule governs **AWS resources + repo
|
||||
names** (the repo `sh-agentforce` IS kebab); it does NOT apply to Salesforce-side metadata API names. Recorded so
|
||||
|
|
|
|||
|
|
@ -370,8 +370,12 @@ tests run in phase 2/4 before each bot is deprecated, not on every PR.
|
|||
- Project memory: `project_sh_mcp.md` created; cross-links to exec-aide, slack-bot, payments,
|
||||
identity-center, lenel/door-unlock memories.
|
||||
- **Cross-review gate (mandatory):** Cognito↔Google federation, group→scope mapping, the
|
||||
token-forwarding design, and every MCP server's IAM role go through `cross_reviewer` before
|
||||
token-forwarding design, and every MCP server's IAM role go through cross-family review before
|
||||
any commit/merge. IAM + auth = the breaking-change category that gates.
|
||||
> Note: the orchestrator repo was archived 2026-07-14; cross-family review now runs via
|
||||
> `python3 ~/Documents/repositories/seahaven/security-review/cross_review.py` (repo
|
||||
> `Sea-Haven-Industries/security-review`). Mentions of `cross_reviewer` elsewhere in this doc are
|
||||
> historical, naming the reviewer as it was invoked through the now-retired orchestrator.
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -423,9 +427,10 @@ FIX (resolved / tracked):
|
|||
|
||||
NIT: PKCE if a public client is added (§2.5); keep pre-token Lambda fast/no external calls (§2.3).
|
||||
|
||||
These auth/IAM specifics are signed off by the cross-review gate. Re-run `cross_reviewer` on the
|
||||
actual IAM policy JSON and pre-token Lambda code once written (the reviewer asked for the concrete
|
||||
artifacts for a deeper pass).
|
||||
These auth/IAM specifics are signed off by the cross-review gate. Re-run cross-family review via
|
||||
`python3 ~/Documents/repositories/seahaven/security-review/cross_review.py` (the orchestrator's
|
||||
`cross_reviewer` is retired as of 2026-07-14) on the actual IAM policy JSON and pre-token Lambda
|
||||
code once written (the reviewer asked for the concrete artifacts for a deeper pass).
|
||||
|
||||
## 11. Investigation: endpoint connectivity & guardrail parity (2026-06-09)
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue