init
This commit is contained in:
commit
b15b95781c
108 changed files with 14802 additions and 0 deletions
64
docs/agents/validation/05-api-keys-validation.md
Normal file
64
docs/agents/validation/05-api-keys-validation.md
Normal file
|
|
@ -0,0 +1,64 @@
|
|||
# Validation Report Template
|
||||
|
||||
## Validator
|
||||
|
||||
Name: Codex Validation Agent
|
||||
|
||||
Stage Reviewed: Agent 05 - API Keys And Access Control
|
||||
|
||||
Date: 2026-04-14
|
||||
|
||||
## Reviewed Inputs
|
||||
|
||||
- `/Users/delete/projects/update_server/docs/agents/WORKFLOW.md`
|
||||
- `/Users/delete/projects/update_server/PRODUCT_SPEC.md`
|
||||
- `/Users/delete/projects/update_server/IMPLEMENTATION_PLAN.md`
|
||||
- `/Users/delete/projects/update_server/DEVELOPMENT_WORKFLOW.md`
|
||||
- `/Users/delete/projects/update_server/docs/agents/OPERATOR_QUICKSTART_RU.md`
|
||||
- `/Users/delete/projects/update_server/docs/agents/handoffs/05-api-keys.md`
|
||||
- `/Users/delete/projects/update_server/docs/agents/handoffs/05-api-keys-fix.md`
|
||||
- previous stage validation report: `/Users/delete/projects/update_server/docs/agents/validation/04-projects-releases-validation.md`
|
||||
- implementation files under `internal/apikeys`, `internal/db`, `internal/http`, `internal/app`, and `web/templates`
|
||||
- `GOCACHE=/tmp/go-build-agent05-revalidate GOMODCACHE=/tmp/go-mod-agent05-revalidate go test ./...` -> passed
|
||||
- `GOCACHE=/tmp/go-build-agent05-rebuild GOMODCACHE=/tmp/go-mod-agent05-rebuild go build -o /tmp/update-server-agent05-revalidate ./cmd/server` -> passed
|
||||
- `GOCACHE=/tmp/go-build-agent05-remigrate GOMODCACHE=/tmp/go-mod-agent05-remigrate go build -o /tmp/update-migrate-agent05-revalidate ./cmd/migrate` -> passed
|
||||
- live smoke checks against `127.0.0.1:18085` after starting `/tmp/update-server-agent05-revalidate` with a fresh `DATA_DIR`:
|
||||
- `GET /healthz` -> `200 OK`
|
||||
- `GET /admin/api-keys` without session -> `303 See Other` to `/admin/login?next=%2Fadmin%2Fapi-keys`
|
||||
- `POST /admin/login` -> `303 See Other` with session cookie
|
||||
- `POST /admin/projects` -> project created
|
||||
- `POST /admin/tags` -> tag created
|
||||
- `POST /admin/projects/1/tags` -> tag attached
|
||||
- `POST /admin/api-keys` -> `200 OK` with `Cache-Control: no-store, private, max-age=0`, `Pragma: no-cache`, and `Expires: 0`
|
||||
- the create response showed the raw key once and also showed the persisted saved values immediately: name, description, selected scope mode, permissions, selected tag rule, and effective access preview
|
||||
- `GET /admin/api-keys/1` after creation -> `200 OK`, raw key no longer present in HTML
|
||||
- SQLite inspection confirmed only `key_hash` was stored and confirmed the persisted tag scope row in `api_key_tag_access`
|
||||
|
||||
## Findings
|
||||
|
||||
No blocking findings.
|
||||
|
||||
The previously reported issues are fixed:
|
||||
|
||||
- the secret-bearing creation response is explicitly marked non-cacheable;
|
||||
- the immediate post-create detail page is hydrated from persisted data while still showing the raw key only on that one response.
|
||||
|
||||
The stage now satisfies the agreed scope:
|
||||
|
||||
- API keys are generated securely and stored hashed;
|
||||
- admin UI supports create, update, and revoke flows;
|
||||
- allow-list and deny-list groundwork is in place for both projects and tags;
|
||||
- middleware and scope evaluation are covered by tests and the create-flow regressions are fixed.
|
||||
|
||||
## Required Fixes
|
||||
|
||||
None.
|
||||
|
||||
## Optional Improvements
|
||||
|
||||
- Consider a future POST-Redirect-GET plus short-lived flash-secret design if you want to avoid browser refresh resubmitting the create form while still keeping the raw key out of persistent storage.
|
||||
- Later client API validation should explicitly exercise disabled and expired keys through the public `/api/v1` endpoints once Agent 06 wires them in.
|
||||
|
||||
## Status
|
||||
|
||||
`APPROVED`
|
||||
Loading…
Add table
Add a link
Reference in a new issue