Record the SecurityService unauthenticated-endpoint triage

Docskamo-internal
Ya
19 Agosti 2026, 01:52 UTC
Mwandishi
kamo
Ahadi ya
94d6744

Three fixed, the rest explained. The headline number needed narrowing three times and the first two attempts were wrong the same way — enumerating helper names rather than detecting structurally — so the document says plainly that a baseline of "unguarded" endpoints is evidence to investigate, not a finding to report. 370 entries: 142 MLOS, 150 that do refuse callers through a helper the ratchet does not follow, 12 in the deliberately-anonymous borrower portal, and most of the remainder correctly public. Fixed: DiagnosticsController (all four, including a Redis session enumerator and an environment dump filtered by denylist), **************** (the whole organization estate), and a test stub deleted. 370 to 364. Left with reasons: EntitlementController is the same trust-the-proxy-header problem as KamoLOS and cannot be fixed in the service without breaking the working path, and the organization lookups are plausibly pre-auth by necessity where the real concern is that they return entities rather than DTOs.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei