Security: complete audit remediations #31
Merged
wasabi opened 1 week ago

Summary

  • Complete the platform security audit remediation across public data, Directus tenant isolation, ingestion, sandboxing, event/scheduler execution, workflow governance, consent, and Solidity deployment safety.
  • Add fail-closed execution allowlists, MQTT HMAC/topic binding, URL/XML/expression hardening, KGP pause protection, and deployment/upgrade preflight checks.
  • Add Directus relational tenant validation and repair existing permission rows idempotently.
  • Add the final audit report with CodeQL and Semgrep results and residual-risk classification.

Verification

  • Solidity: 31 tests passed.
  • Platform-integrity suite: 248 passed, 1 skipped.
  • Directus hooks: 60 tests passed and TypeScript build passed.
  • Focused post-audit regression suite: 214 passed, 1 skipped.
  • Directus permission seed applied successfully with ON_ERROR_STOP=1 and live tenant scopes verified.
  • CodeQL 2.26.1 and Semgrep OSS 1.170.0 scans completed; raw generated databases and SARIF artifacts were intentionally excluded from Git.
Commits were merged into target branch
1/1
Submitter wasabi
Target main
Source chore/full-codebase-audit-remediations
Jobs
Merge Strategy
Create Merge Commit
Watchers (1)
Reference
pull request KI-31
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover