sh-mcp/docs
Adam Moussa 52c58a5a0a Fold in cross_reviewer (GPT-4.1) auth/trifecta findings
Cross-family review caught defense-in-depth gaps:
- CR-1: validate aud at edge AND server-side (per-tier authorizer doesn't replace
  design.md §2.5 server enforcement); alarm on wrong-audience tokens.
- CR-6: finance-audience token must not reach Gmail/Calendar even with a Google token.
- CR-2: verify+enforce received sub is the Google Workspace sub, not a Salesforce id.
- CR-3: pre-token Lambda fails closed on cross-audience scope.
- CR-5: pre-token + group-sync are the auth SPOF — alarms + group-claim freshness bound.
- CR-4/CR-7: restrict per-client Cognito scopes; WAF is defense-in-depth only.
Reflected in §0.1 B3/B4, §1h tests, §4 monitoring, §5 cross-review log.
2026-06-11 12:53:33 -04:00
..
agentforce-plan.md Fold in cross_reviewer (GPT-4.1) auth/trifecta findings 2026-06-11 12:53:33 -04:00
design.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00