cgreene / cgreene/farewright

Run independent adversarial security and external-effects review

Open
#22 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

adversarial-review demo-integrity security workstream:auth-payments
Dominant language
No language data
Stars
0
Forks
0
Avg merge
8h 21m
Merged PRs (30d)
2

Description

Outcome

An independent model attempts to bypass authority, expose sensitive data, or duplicate money/supplier effects before the deployed demo is trusted.

Scope

  • Attack OAuth audience/tenancy, RBAC, local/broker revocation, non-authorizing handoffs, browser sessions, CSRF, and approval/review TOCTOU.
  • Attack Stripe and supplier idempotency, webhook/browser ordering, crash reconciliation, refund-target overcommitment, service refunds, and inactive-run callbacks.
  • Inspect vault, redaction, erasure, logs, URLs, receipts, effects/attempts/jobs, errors, and console/MCP projections.
  • Attack fixture materialization privilege and active-run switching with unresolved work.

Acceptance

  • Reviewer did not author the reviewed code or its fixes.
  • Severity-ranked findings include reproducible evidence or concrete arguments.
  • Locator-only browser use, wrong user, replay, stale reprice, revoked authority, callback inversion, overlapping refund obligations, and racing effect observations are attempted.
  • All blocking findings are fixed and re-reviewed or explicitly accepted by the product owner.
  • The review states which deeper production-hardening items remain post-demo.

Dependencies

  • #19, #20, #21, #14, and #15.

Review

This issue is the mandatory stage 4 security/effects gate artifact.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the implementations and review artifacts from dependencies #19, #20, #21, #14, and #15, then map the listed OAuth, authorization, browser, payment, callback, logging, and fixture scenarios to the deployed demo. Attempt each acceptance-case attack with reproducible evidence, rank findings by severity, and document fixes, explicit product-owner acceptance, and remaining post-demo hardening work.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, authorization, payments, security, testing
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.