You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
security(auth): owner decisions on the sign-in lock and the audit address hash (D-064, D-065) #879
Two limits accepted in #688 (PR #874) need an owner decision before any code, because each one touches auth or crypto design (CLAUDE.md, escalation rules). They are recorded as D-064 and D-065 in docs/DECISIONS.md.
Audit hash can be reversed (D-065). Failed sign-ins are audited with email_sha256=<hex>, an unsalted SHA-256. Anyone who can read the audit trail and holds a list of candidate addresses can recover which address was targeted. The same hash keys the password-reset limiter (domain.HashEmailForReset).
Acceptance criteria
Set once the owner decides; until then this issue is status:blocked.
D-064 is decided and the chosen option is implemented, or recorded as accepted with no code.
D-065 is decided and the chosen option is implemented, or recorded as accepted with no code.
Definition of Done
Both decisions moved to Resolved in docs/DECISIONS.md.
Any resulting code: tests + gates green, PR with Closes.
Problem
Two limits accepted in #688 (PR #874) need an owner decision before any code, because each one touches auth or crypto design (CLAUDE.md, escalation rules). They are recorded as D-064 and D-065 in
docs/DECISIONS.md.email_sha256=<hex>, an unsalted SHA-256. Anyone who can read the audit trail and holds a list of candidate addresses can recover which address was targeted. The same hash keys the password-reset limiter (domain.HashEmailForReset).Acceptance criteria
Set once the owner decides; until then this issue is
status:blocked.Definition of Done
docs/DECISIONS.md.Closes.