Record the SecurityService unauthenticated-endpoint triage

Docskamo-internal
Shipped
August 19, 2026 at 1:52 AM UTC
Author
kamo
Commit
94d6744

Three fixed, the rest explained. The headline number needed narrowing three times and the first two attempts were wrong the same way — enumerating helper names rather than detecting structurally — so the document says plainly that a baseline of "unguarded" endpoints is evidence to investigate, not a finding to report. 370 entries: 142 MLOS, 150 that do refuse callers through a helper the ratchet does not follow, 12 in the deliberately-anonymous borrower portal, and most of the remainder correctly public. Fixed: DiagnosticsController (all four, including a Redis session enumerator and an environment dump filtered by denylist), **************** (the whole organization estate), and a test stub deleted. 370 to 364. Left with reasons: EntitlementController is the same trust-the-proxy-header problem as KamoLOS and cannot be fixed in the service without breaking the working path, and the organization lookups are plausibly pre-auth by necessity where the real concern is that they return entities rather than DTOs.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing