DataTalksClub / DataTalksClub/website

Complete residual cross-domain security and authorization traceability

Open
#63 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement integration P0 security testing
Dominant language
Python
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Parent epic: #8

Normative authority:

Outcome

Complete the residual, cross-domain security and authorization traceability after the owning implementation issues land. Produce one reviewed record that proves every release-critical actor, asset, route/action/export boundary, threat, control, owner, test, redacted artifact, freshness rule, and exception is covered before production data or authority is enabled.

This is an integration and evidence-completion issue. It consumes accepted domain contracts; it does not redesign OIDC, sessions, roles, credentials, legacy course APIs, privacy, edge controls, recovery, or exports.

Current authority and baseline

Audited against current origin/main at face8e4808d65afbf0374d1ced7a88079950d663.

  • #141 is closed, accepted, merged, and is the non-identity web/data-boundary baseline. Its headers, request limits, CSP, content/input, SSRF, filesystem, CSV, redaction, dependency, and container evidence must be consumed rather than reimplemented here.
  • #20, #23, and #28 are closed owner decisions. They are inputs, not open blockers. In particular, #20 selects the shared Cognito route and explicitly removes any dedicated break-glass credential workflow; management-API parity is the recovery direction, with direct database access only as the last-resort operational fallback owned by #7.
  • #61 is the identity/session producer and #63 is only its residual traceability consumer. The accepted handoff must expose the durable local user identity plus safe StaffSession authentication/status/revocation evidence through the accounts boundary. Raw provider claims, OIDC tokens, browser credentials, provider payloads, and editorial Person identity do not cross into this issue.
  • #32 and #33 own the production Studio/high-risk and admin-API principal/credential controls. The three bounded #32 slices are currently an uncommitted, superseded-base candidate and are not a complete current-main handoff.
  • DataTalksClub/aws-infra#24 remains open. Cognito TOTP does not prove MFA for the Google-federated path; accepted secret-free Workspace/shared-Cognito evidence is still required before production staff identity can be called ready.
  • No #63 implementation, independent tester-final report, PM acceptance, focused commit, merge, or on-call result exists. All criteria below remain open.

Scope

  • Freeze the exact current-main route/action/export and actor/data-flow inventory across public, learner, Studio, admin API, legacy course API, webhook, durable-job, content, and export boundaries.
  • Reconcile the #141 baseline with accepted evidence from #61, #32, #33, #52, #64, and #66. Each residual row names the actor, protected asset, method/boundary, attack, current control, owning issue, focused test, redacted artifact, approval owner, freshness rule, residual risk, exception expiry, and downstream #76/#73/#74 consumer.
  • Enumerate legacy token_required, require_staff_token, staff_required, staff_json_required, is_staff, is_superuser, and every export/send-audit surface. Add or consume a deterministic no-new-legacy-auth-use guard with an explicit frozen allowlist and owner/expiry exception process. The guard prevents drift; it does not approve or change an existing compatibility route.
  • Verify that identity/session rows consume only #61's accounts-owned local identity and safe session-status/revocation boundary, and that #32/#33 apply explicit deny-by-default function, object, field, principal, scope, high-risk, audit, concurrency, idempotency, and credential controls.
  • Verify that privacy/export/retention rows consume #64 and legacy course authorization/export rows consume #52; do not silently treat inventory as approval.
  • Publish the frozen residual traceability artifact and its exact evidence digests for #76. Every unresolved finding has an owner, risk, expiry, approval state, and release disposition.

Non-goals

  • No OIDC/provider implementation, claim or account-linking policy, timeout value, offboarding bound, MFA inference, provider/AWS mutation, secret access, real identity creation, or production-data access.
  • No dedicated break-glass account, credential, workflow, storage, rotation, drill, UI, or production Django-admin recovery path.
  • No role/capability invention, API-principal or token lifecycle implementation, high-risk-policy redefinition, legacy-auth migration, export field/scope change, privacy/retention decision, edge/WAF change, restore exercise, or domain behavior change.
  • No claim that #141, a deterministic identity adapter, optional Cognito TOTP, an inventory, or a guard proves production identity/MFA or approves an existing risk.
  • No stale test, plan, screenshot, CI, deployment, or production evidence from a superseded source/configuration envelope.

Exact prerequisites and dispatch gate

Satisfied inputs: #1, #20, #23, #28, #31, and #141.

Blocking current-main handoffs:

  1. #61 identity/session: accepted and merged provider protocol, account-linking/admission policy, idle/absolute/offboarding/outage behavior, safe accounts-owned identity/session handoff, and deterministic negative evidence. Any remaining external MFA check is explicitly [HUMAN], owned, and secret-free.
  2. #32 Studio/high-risk: accepted and merged complete role/capability, object/field, session freshness, high-risk confirmation/API-equivalent proof, audit/export, denial, and production Django-admin policy. The three bounded uncommitted slices are insufficient.
  3. #33 admin API: accepted and merged production human/service principal and credential lifecycle plus bidirectional Studio/API registry, service, policy, audit, idempotency, concurrency, rate, result, and OpenAPI parity.
  4. #52 legacy course authorization/export: accepted and merged migration or explicit bounded disposition for every legacy staff/token/route/action/export row, including removal gates and compatibility evidence.
  5. #64 privacy: accepted privacy export, correction, deletion/anonymization, retention, propagation, and restored-backup tombstone evidence for the protected data in this matrix.
  6. #66 operations: accepted redacted telemetry, alert, failure, backup/restore, RPO/RTO, and replay evidence needed by security-critical rows.
  7. External production MFA: DataTalksClub/aws-infra#24 supplies accepted, secret-free evidence for the exact Google Workspace/shared-Cognito staff path.

Do not dispatch final #63 engineering or verification until prerequisites 1–6 are current-main handoffs. The external MFA gate may remain a separately owned [HUMAN] item only if the resulting delivery uses Refs #63, retains human, leaves the issue open, and makes no production-readiness claim. Recompute all evidence from the then-current source/configuration envelope.

Acceptance criteria

  • The accepted #141 non-identity baseline is mapped into one frozen residual traceability artifact without reimplementing or overstating its scope.
  • Every in-scope actor, asset, route/action/export boundary, attack, control, owner, owning issue, focused test, redacted artifact, approval, freshness rule, residual risk, exception expiry, and #76/#73/#74 consumer appears exactly once, with no unowned or implicitly accepted row.
  • Identity/session rows consume the accepted #61 local-user plus safe StaffSession boundary; raw claims/tokens/provider payloads/editorial identity never cross it, local explicit permission remains authoritative, and the exact federated MFA evidence is recorded without inference.
  • Studio/admin-API/high-risk rows consume accepted #32/#33 evidence and prove deny-by-default function/object/field/principal/scope policy, session/credential separation and revocation, parity, high-risk confirmation/reauthentication, redacted audit, and safe failure behavior.
  • Every legacy auth and export/send-audit use is frozen in the inventory and either mapped to accepted #52/#64 ownership and removal/approval evidence or retained as an explicit owned, expiring release exception; the deterministic guard rejects an unapproved new use without changing existing runtime behavior.
  • Privacy, secrets, tokens, PII, error, log, metric, trace, audit, browser-artifact, dependency/container, failure, alert, and restore rows consume current accepted #64/#66 and graph-selected evidence; no protected value appears in retained artifacts.
  • The versioned verification plan and report are generated from one exact current-main candidate, classify every component once, validate every reused evidence envelope/digest, run every selected fresh gate, and contain no unexplained skip or stale/partial verdict.
  • The final #76 handoff lists every remaining exception with owner, risk, expiry, approval, and release disposition; #73/#74 remain no-go until their required residual rows and the external production gates are accepted.

Verification scenarios

  1. Deterministically enumerate routes, methods, adapters, registry entries, permissions/policies, exports, legacy decorators/gates, jobs, webhook boundaries, and protected data; fail on an unknown, duplicate, missing-owner, or unapproved new legacy use.
  2. Validate every matrix evidence reference and digest against its exact source/configuration envelope; changed or missing inputs invalidate reuse and select fresh verification.
  3. Exercise representative positive and adversarial identity/session, object/field, credential, CSRF/CORS/CSP, request-limit, SSRF/XSS/traversal/CSV, webhook replay, export, redaction, privacy, and failure boundaries through the owning issue's accepted tests. Inventory-only evidence never substitutes for behavior evidence.
  4. Scan retained reports and artifacts with synthetic canaries and prove they contain no secret, token, authorization header, cookie, provider payload, email, protected profile/registration value, or production identity/data.
  5. Verify every critical finding and exception has an authorized owner, risk, expiry, approval, remediation/recheck trigger, and downstream release disposition.

Browser and operational evidence

#63 itself is expected to be repository/evidence integration with no product render change. Screenshots are not_applicable only when the current graph independently confirms no render impact; otherwise the independent tester captures and inspects every selected desktop/mobile state under .tmp/screenshots/. Existing #61/#32/#33/#52/#64 browser evidence is reusable only through an exact validated envelope.

Use only synthetic identities and redacted artifacts. No provider/AWS/production mutation, production credential issuance, or production-data access is authorized by this issue. External deployed checks remain separately owned [HUMAN] evidence.

Downstream and delivery

#76 consumes the completed matrix and evidence. #73 and #74 remain downstream no-go gates; they are not prerequisites that #63 may bypass.

Follow _docs/PROCESS.md. Engineer work remains uncommitted; a separate tester verifies the exact frozen candidate and all required evidence; PM accepts; then the engineer creates a focused commit. Use Closes #63 only when every automated and required external criterion is accepted. Otherwise use Refs #63, add human, and leave the issue open. The orchestrator locally merges with --no-ff, pushes main, and on-call alone observes CI/deployment. No pull request is created.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading _docs/security/non-identity-threat-control-matrix.md, _docs/security/issue-141-traceability.md, and the referenced specifications on the current-main evidence envelope. Wait for accepted handoffs from #61, #32, #33, #52, #64, and #66, then reconcile their evidence into one frozen residual traceability artifact. Done means every required row, digest, exception, owner, expiry, and downstream disposition is recorded without stale or unexplained evidence.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, django, python
Domain
authorization, documentation, security, testing
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.