- Shipped
- August 19, 2026 at 1:52 AM UTC
- Author
- kamo
- Commit
- 94d6744
Three fixed, the rest explained. The headline number needed narrowing three times and the first two attempts were wrong the same way — enumerating helper names rather than detecting structurally — so the document says plainly that a baseline of "unguarded" endpoints is evidence to investigate, not a finding to report. 370 entries: 142 MLOS, 150 that do refuse callers through a helper the ratchet does not follow, 12 in the deliberately-anonymous borrower portal, and most of the remainder correctly public. Fixed: DiagnosticsController (all four, including a Redis session enumerator and an environment dump filtered by denylist), **************** (the whole organization estate), and a test stub deleted. 370 to 364. Left with reasons: EntitlementController is the same trust-the-proxy-header problem as KamoLOS and cannot be fixed in the service without breaking the working path, and the organization lookups are plausibly pre-auth by necessity where the real concern is that they return entities rather than DTOs.