Skip to content

feat(security): enforce shared capture policy - #11

Merged
kev1n77 merged 1 commit into
mainfrom
codex/capture-policy
Jul 14, 2026
Merged

kev1n77 merged 1 commit into
mainfrom
codex/capture-policy

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 14, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a versioned Capture Policy contract and schema for exact hosts, POST methods, approved endpoint paths, and normalized sensitive field names
  • enforce the same policy in the Python mitmproxy sidecar and a new trusted Rust Core ingestion boundary
  • reject out-of-scope envelopes and re-scrub headers, query fields, and nested JSON before persistence
  • embed the policy in PyInstaller artifacts and fix Windows onefile probe process-tree cleanup
  • update security evidence and progress without marking SEC-001 complete before DB/log/temp canary validation

Verification

  • cargo fmt --all -- --check
  • cargo test --workspace --all-targets
  • cargo clippy --workspace --all-targets -- -D warnings
  • python -m unittest discover -s sidecars/mitmproxy/tests -v (10 tests)
  • npm run desktop:check (3 tests)
  • packaged Windows sidecar integration probe: forwarding preserved, prompt preserved, credential canaries in envelope = 0
  • packaged sidecar process count after probe = 0
  • HTML links/fragments and git diff --check

Security boundary

Only SanitizedCapture values returned by codeischeap-core are eligible for persistence. Real persistence remains blocked on DAT-001 and the remaining SEC-001 DB/log/temp canary checks.

@kev1n77
kev1n77 merged commit a986d0a into main Jul 14, 2026
9 checks passed
@kev1n77
kev1n77 deleted the codex/capture-policy branch July 14, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant