Skip to content

docs(roadmap): link security-edge-hardening initiative - #31

Merged
alexnikolskiy merged 1 commit into
mainfrom
docs/security-edge-hardening-link
Jul 17, 2026
Merged

docs(roadmap): link security-edge-hardening initiative#31
alexnikolskiy merged 1 commit into
mainfrom
docs/security-edge-hardening-link

Conversation

@alexnikolskiy

Copy link
Copy Markdown
Collaborator

Local-roadmap pointer to the cross-repo security-edge-hardening initiative card and audit report in control-center (docs/analysis/08-security-boundary-audit.md).

Office-relevant part (P0): office-server's guard is mounted only when OFFICE_OPERATOR_PASSWORD is set, and the lab VPS compose path never sets it while publishing office-server on 0.0.0.0:8787 with server-held platform-read/lab-chat tokens → reaching the port initiates actions without an operator credential; /operator/confirm bypasses the human-in-the-loop step. Make it fail-closed + add a confirm authority guard + default BIND_ADDR=127.0.0.1.

Docs-only. No code/behavior change.

🤖 Generated with Claude Code

Adds a cross-repo initiatives section pointing at the security edge-hardening
card + audit report (control-center docs/analysis/08-security-boundary-audit.md).
Office part: office-server starts unauthenticated by default and is published on
0.0.0.0:8787 via the lab VPS compose while holding server-side platform/lab
tokens; /operator/confirm bypasses HITL. Make it fail-closed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@alexnikolskiy
alexnikolskiy merged commit 61581a9 into main Jul 17, 2026
1 check passed
@alexnikolskiy
alexnikolskiy deleted the docs/security-edge-hardening-link branch July 17, 2026 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant