- Ya
- 4 Agosti 2026, 04:19 UTC
- Mwandishi
- Kamo
- Ahadi ya
- 19cc558
SecurityService's hourly review of phi_access_log needs somewhere to send what it finds. Rather than invent a channel it uses the existing transactional-email rail, which means a canonical key: absent from CANONICAL_KEYS a template can never be seeded, never self-heals, and every send returns a permanent 404 — an alerting control that looks like coverage and delivers nothing. The template carries identifiers, counts and a time window only. A detection artefact that reproduces what it detected has relocated the PHI into an inbox with no retention policy, so there is deliberately no placeholder for a record. PhiAccessAlertTemplateTest pins that, and pins the two silent failure modes: a placeholder nothing supplies renders as an empty string with only a WARN, and the renderer does no HTML escaping, so anything reaching the body uses the escaped twin. EmailService must redeploy with this shared-lib before SecurityService starts sending; until then the send is caught and the finding stays review-log only.