Skip to content

feat(sidecar): inspect Windows CA private key ACLs - #32

Merged
kev1n77 merged 1 commit into
mainfrom
codex/sidecar-windows-ca-acl
Jul 16, 2026
Merged

kev1n77 merged 1 commit into
mainfrom
codex/sidecar-windows-ca-acl

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 16, 2026

Copy link
Copy Markdown
Owner

Summary

  • inspect both mitmproxy private-key files with native Windows owner/DACL APIs
  • allow private material access only to the current user, SYSTEM, Administrators, and owner-rights principals
  • classify null DACLs and unknown accessible principals as insecure, while preserving unchecked for unreadable or unsupported ACL shapes
  • cover restricted and Everyone-readable ACLs with real Windows filesystem tests
  • advance CAP-005 to 35%

Scope

This remains a read-only CAP-005 increment. System trust-store checks and privileged CA installation/removal are intentionally separate follow-up changes.

Verification

  • cargo fmt --all -- --check
  • cargo test --workspace --all-targets
  • cargo clippy --workspace --all-targets -- -D warnings
  • Tauri formatting, 10 native tests, and Clippy
  • desktop frontend: 16 tests and production build
  • sidecar addon/packaging: 17 tests

@kev1n77
kev1n77 merged commit 498103a into main Jul 16, 2026
9 checks passed
@kev1n77
kev1n77 deleted the codex/sidecar-windows-ca-acl branch July 16, 2026 00:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant