Files
smoa/docs/security/TENANT-THREAT-MODEL.md
T
defiQUG a2dc194a49 Monorepo: Gitea CI, docs, auth/sync, backend APIs, gitignore
- Add Gitea Actions workflow; point README to gitea.d-bis.org/Sankofa_Phoenix/SMOA
- Expand .gitignore for Spring H2 data, secrets, Kotlin .kotlin/, tooling
- Track docs/api/generated ReDoc bundle; refresh api docs README
- Android: network/auth/sync, UI shell, tests; backend credentials/integrity APIs
- Docs, scripts (generate-api-docs), modules and core updates

Made-with: Cursor
2026-03-23 20:19:24 -07:00

1.6 KiB

Tenant, API key, and unit header — threat model notes

What exists today

  • API key (SMOA_API_KEY / X-API-Key): shared-secret gate for /api/v1/* when configured. It does not identify a tenant or row-level security domain by itself.
  • smoa.tenant.require-unit: when true, requests may require X-Unit (or equivalent) so clients must declare a unit; the backend can filter read paths that honor the header (see TenantFilter). This is not cryptographic proof of membership in that unit.
  • Multi-government payloads: optional issuingAuthority in credential payload_json documents jurisdiction and org hierarchy for issuance audit; it does not enforce access control unless application logic is added.

Gaps (explicit)

  • No binding between API key and allowed unit / holderId / tenant id in the database layer.
  • No row-level security (RLS) in PostgreSQL; all rows are visible to any authenticated client unless controllers add filters.
  • Compromise of API key implies compromise of all data the backend stores until the key is rotated.

Hardening directions

  1. Issue per-device or per-tenant credentials (mTLS, JWT with tenant_id / sub, or OAuth2 client credentials) instead of a single static API key where feasible.
  2. Map principal → allowed units in policy service; enforce in every sync/pull handler.
  3. Enable PostgreSQL RLS or schema-per-tenant for strict isolation.
  4. Log and monitor X-Request-Id and principal for sync audit (already partially covered by sync_audit_log).

See also docs/reference/GAPS-AND-INCONSISTENCIES.md and backend TenantFilter.