- Shipped
- October 5, 2026 at 1:45 AM UTC
- Author
- Kamo
- Commit
- 1c9cde4
Both impersonation doors write IMPERSONATION_STARTED (HIGH) in the target's org with logEventSync after every refusal check and before the session is minted; a row that cannot be written answers 503 AUDIT_UNAVAILABLE and mints nothing. Enter-As writes ENTER_AS in the destination org before minting: MEDIUM for one's own membership (a failed write is a WARN), HIGH as the System User (a failed write is 503, nothing minted). The row names the ticket the System User grant rests on, never the one the body claimed. Logout of a session whose SUDO_MEMBER_ID differs from its memberID also writes IMPERSONATION_ENDED (MEDIUM). The cross-org door now reads the caller's orgID for the row and answers 401 when the session lacks it, as the same-org door already did. New: security/ImpersonationAudit (spec 5.6, D12-D14).
