Monorepo: Gitea CI, docs, auth/sync, backend APIs, gitignore
- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA - Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling - Track docs/api/generated ReDoc bundle; refresh api docs README - Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs - Docs, scripts (generate-api-docs), modules and core updates Made-with: Cursor
This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
# Tenant, API key, and unit header — threat model notes
|
||||
|
||||
## What exists today
|
||||
|
||||
- **API key** (`SMOA_API_KEY` / `X-API-Key`): shared-secret gate for `/api/v1/*` when configured. It does **not** identify a tenant or row-level security domain by itself.
|
||||
- **`smoa.tenant.require-unit`**: when true, requests may require `X-Unit` (or equivalent) so clients must declare a unit; the backend can filter **read** paths that honor the header (see `TenantFilter`). This is **not** cryptographic proof of membership in that unit.
|
||||
- **Multi-government payloads:** optional `issuingAuthority` in credential `payload_json` documents jurisdiction and org hierarchy for issuance audit; it does not enforce access control unless application logic is added.
|
||||
|
||||
## Gaps (explicit)
|
||||
|
||||
- **No** binding between API key and allowed `unit` / `holderId` / tenant id in the database layer.
|
||||
- **No** row-level security (RLS) in PostgreSQL; all rows are visible to any authenticated client unless controllers add filters.
|
||||
- **Compromise of API key** implies compromise of all data the backend stores until the key is rotated.
|
||||
|
||||
## Hardening directions
|
||||
|
||||
1. Issue **per-device or per-tenant** credentials (mTLS, JWT with `tenant_id` / `sub`, or OAuth2 client credentials) instead of a single static API key where feasible.
|
||||
2. Map principal → **allowed units** in policy service; enforce in every sync/pull handler.
|
||||
3. Enable **PostgreSQL RLS** or schema-per-tenant for strict isolation.
|
||||
4. Log and monitor **`X-Request-Id`** and principal for sync audit (already partially covered by `sync_audit_log`).
|
||||
|
||||
See also `docs/reference/GAPS-AND-INCONSISTENCIES.md` and backend `TenantFilter`.
|
||||
Reference in New Issue
Block a user