Skip to content

security(backend): enforce sender and recipient authorization on every stream path #69

Description

@arisu6804

Problem

A guessed stream ID or alternate endpoint can expose or mutate a stream outside the caller's sender or recipient scope.

Objective

Deliver a production-quality improvement to stream access control and route/service boundaries that creates measurable value for correctness, security, reliability, performance, or maintainability.

Implementation scope

  • Centralize ownership and participant policy at the service layer; cover list, detail, update, cancel, and withdraw paths; prevent enumeration.

Acceptance criteria

  • Only permitted participants can access each action; unauthorized responses do not reveal existence; privileged access is explicit and audited.

Required validation

  • Authorization matrix and API integration tests across sender, recipient, unrelated actor, and operator roles.
  • Existing tests and CI remain passing.
  • Add regression coverage for the original failure mode.
  • Do not weaken, delete, or skip unrelated tests to obtain a green build.

PR quality bar

  • Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
  • Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.

Out of scope

  • Broad rewrites not required by the acceptance criteria.
  • Changes to unrelated services, contracts, or user flows.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    GRANTFOX OSSOpen-source issue tracked by GrantFoxMAYBE REWARDEDThis issue may carry a rewardThird CampaignThird Campaign contributionenhancementNew feature or requestpriority:highHigh implementation priority

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions