feat(security): household visibility threat model with executable fail-closed access cases - #4
Merged
Merged
Conversation
…losed access cases Delivers security/THREAT-MODEL.md (actors, assets, trust boundaries, two-dimension rule, abuse cases with severity) and executable negative access cases against contract v0.1 shapes (art_I2TCG08V): 17 tests, all passing, each documenting the exact deny assertion. Spike package not pushed; shapes mocked per contract rule 1, wiring labeled pending. Co-authored-by: Gilbert Polanco <gilbertpolanco42@gmail.com>
This was referenced Sep 17, 2026
obvious-autobuild Bot
pushed a commit
that referenced
this pull request
Sep 17, 2026
…without a source
Product-owner ruling (binding): absence of logged sleep data may never be
stated as a confirmed absence ("No nap today") nor carry a behavioral
prediction ("expect an early meltdown"). The takeover brief fact-4
headline, plan note, Q&A answer, and both citation refs now state
absence-of-record ("No nap recorded", "coverage: ..."), ported verbatim
from the canonical arena fixture (c3c1dc3).
Tests: five-fact #4 asserts the corrected headline; the Q&A source
assertion pins "coverage:"; a new negative control sweeps the whole
fixture so "meltdown" can only appear in the drop-off event's own
context — never as a forecast — and bans confirmed-absence phrasing on
all prediction surfaces. Suite: 24 tests / 113 assertions, green on
this HEAD (negative control verified to fail on regressed text).
Co-authored-by: Gilbert Polanco <gilbertpolanco42@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Human author: Gilbert Polanco (gilbertpolanco42@gmail.com)
Why
The journal's most sensitive data — raw caregiver transcripts, child-scoped timelines, extraction events — has no documented authorization model. In a co-parenting product, the realistic attacker is not a hacker but a credentialed, well-meaning caregiver of a different household whose every request is well-formed. Without an explicit model, the failure mode is ad-hoc checks that leak one boundary at a time.
What
security/THREAT-MODEL.md— actors (Caregiver A, Caregiver B, non-member caregiver, anonymous), assets (child profile, entries, raw transcripts — highest sensitivity, extraction events), trust boundaries (authentication edge, household membership, child scoping, publication state), 11 abuse cases with severity, and the fail-closed rules.Entry.status: draft|published, contract v0.1) and audience permission (household membership × child scoping) are SEPARATE dimensions — deliberately not onedraft/sharedenum. Publication never widens audience; membership never pierces drafts. Truth table + composition test (DIM-1) included.security/access/policy.ts—evaluateAccess, a pure fail-closed decision function with contract-denial reason codes;visibleEntriestimeline projection.security/access/policy.test.ts— 17 executable named cases: cross-household read (AB-1), cross-household write (AB-2), non-member reads any child (AB-3), draft invisible to co-member but visible to author (AB-4 + PC-4), anonymous read/write (AB-5/6), published-but-still-scoped (AB-7/7b), attribution spoof (AB-9), draft-event side-channel (AB-10), fail-closed on missing scoping data (AB-12/12b), plus 4 positive controls proving denials are surgical. Every test documents the exact assertion that denies access (outcomeANDcodepinned — denying for the wrong reason fails the suite).Dependency label (pending, per contract rule 1): the schema contract landed in
spikes/effect-compaton branchspike/effect-contracts-adapters, which was not pushed to origin when this was written. Tests run against the documented shape mock (schema-mock.ts, field-for-field from art_I2TCG08V); wiring to the real package is pending — swap the import when the spike lands. Household/child scoping types are labeled required contract extensions (§8), not schema claims.How to Review
security/THREAT-MODEL.md§5 (two-dimension rule) and §6 (abuse-case table mapping each abuse case to its executable test).security/access/policy.tsis the whole enforcement surface — 5 ordered checks, first failure denies.Test Evidence
bun test ./security— 17 pass, 0 fail, 22 assertions (bun 1.3.14). Named cases visible in run output:Also
tsc --strict --exactOptionalPropertyTypesclean onsecurity/access/*.ts.🔗 Obvious Project · 🧵 Obvious Thread