Skip to content

PR #32 — Security Boundaries & Database Canon - #32

Merged
NomosLudens merged 3 commits into
mainfrom
codex/pr32-security-boundaries-database-canon
Jul 12, 2026
Merged

NomosLudens merged 3 commits into
mainfrom
codex/pr32-security-boundaries-database-canon

Conversation

@NomosLudens

Copy link
Copy Markdown
Owner

This PR implements security boundary hardening, public conversation isolation, client portal token validations, and database canon constraints to resolve PR #32 requirements.

Proposed Changes

1. Database Hardening & Schema Canon

  • Revoked all wildcard write (INSERT, UPDATE) grants on the public schema.
  • Added a PostgreSQL check constraint (single_target_link) to prevent payments from linking both an appointment and an order at once.
  • Hardened RLS policies on public threads and messages to enforce strict isolation.

2. Public Chat & Submission Isolation

  • Created the secure helper resolveOwnedPublicThread that validates visitor key ownership before operations.
  • Migrated all public action endpoints (submitGuardianPublicProof, submitGuardianPublicContact, and sendGuardianPublicMessage) to enforce the new secure thread resolver.
  • Restricted public proof submissions so that they can never link both appointment and order concurrently, asserting target record ownership and existence.

3. Client Portal Hardening

  • Implemented Zod .superRefine check on portal token creation to prevent scope/target mismatches.
  • Hardened token validation to prevent double-dangling tokens and ensure perfect cross-tenant context alignment.
  • Blocked re-evaluation or modification of resource statuses if they are already in a final state (confirmed, cancelled, or rejected).

4. Integrity Logging (Observability)

  • Unified auditing is written to writeKuanIntegrityLog for public/portal proofs and client decisions.

Verification

  • Clean compilation checked via npm run build.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
kuan 0418aca Jul 12 2026, 01:07 AM

@NomosLudens
NomosLudens merged commit aea8968 into main Jul 12, 2026
2 checks passed
@NomosLudens
NomosLudens deleted the codex/pr32-security-boundaries-database-canon branch September 4, 2026 00:22
NomosLudens pushed a commit that referenced this pull request Sep 4, 2026
…-database-canon

PR #32 — Security Boundaries & Database Canon
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants