aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Security boundaries - 2.1.0rc9
|
||||
|
||||
Preserve the established web/auth/queue/executor separation: non-root web and existing non-root executor, fixed Core executable/config, Unix peer checks, normal service groups, both narrow staging exceptions and no new sudo/capability/key-export path. This is a trusted-controller execution service, not a hostile-tenant or malicious-playbook sandbox.
|
||||
|
||||
Argon2id, opaque server sessions, Secure/HttpOnly/SameSite cookies under HTTPS, CSRF/origin/trusted-proxy policy, throttles, current grants, explicit scope/revision review and last-admin checks remain. One-run credentials are collected only for the owning reservation and travel via private frames/FD. No password in job data, reports, journal, browser storage, logs, argv, environment or files. Keep existing deadlines, no automatic retry/POST replay and honest handoff-accepted wording. Reference cleanup is not physical memory erasure.
|
||||
|
||||
## Approved persistence boundary
|
||||
|
||||
This release intentionally replaces ephemeral-only progress with a **bounded structured journal**. It does not store raw Ansible stdout/stderr, debug values, rendered terminal transcripts, invocation/module dictionaries or decrypted Vault data. Only validated public detail metadata/fixed hints is retained; unknown additional event fields are dropped. Core's withheld labels/hosts remain withheld. A rejected/missing final response cannot be promoted from an earlier event.
|
||||
|
||||
Operation reports are explicitly declared Core data, not automatically harmless content. Validate the recorded public schema, request host/mode association, scope, limits and availability. Supplied-secret checks are defense in depth. Static labels and unknown configuration values can still disclose information; Core filtering is not universal secret detection. Full parsed Checkmk sections therefore require explicit retention opt-in, defaulting to availability/file/redaction metadata only.
|
||||
|
||||
All replay/report reads and statistics enforce the same owner/admin access as jobs; plan references remain owner-only. Session/job access is rechecked during streams. Cursors are not bearer authorization. Auth revocation ends live views; already displayed/downloaded/copied information cannot be recalled from a user.
|
||||
|
||||
Only textContent/escaped templates render report strings. No arbitrary URLs, file downloads, source paths, HTML/Rich markup, schema references or executable validators are followed. JSON is bounded and fetched one slot on demand. No report/graph/history data is placed in browser localStorage. Copy JSON is a deliberate user clipboard action, not an automatic export.
|
||||
|
||||
Delete a job -> remove journal/report rows and its statistical contribution; leave only compact audit deletion metadata. No shadow archive. Protected backups, browser transient memory, SQLite free pages and storage remnants require independent operator policy; deletion is not certified erasure. Audit is local, not tamper-proof.
|
||||
|
||||
## Failures and qualification
|
||||
|
||||
Core verdict, native target stats, report availability and journal coverage remain distinct. Native exit0/result_validation is not success and must not auto-replay. Queue overflow or journal write loss does not independently prove task failure. An interrupted stream remains unknown where Core cannot establish a final result.
|
||||
|
||||
No native/systemd/proxy/browser-security qualification is claimed from source fixtures. See VERIFICATION.md and run CONTROLLER-PILOT.md with approved disposable scope. Maintain native Ansible2.19.11, Core's declared dependency range, validated TLS/global SSH trust and current operational-source review.
|
||||
Reference in New Issue
Block a user