KamoCRM

PHI_ACCESS_ALERT canonical template

Featurekamo-shared-library
Shipped
4 ஆகஸ்ட், 2026 அன்று 4:19 AM UTC
Author
Kamo
Commit
19cc558

SecurityService's hourly review of phi_access_log needs somewhere to send what it finds. Rather than invent a channel it uses the existing transactional-email rail, which means a canonical key: absent from CANONICAL_KEYS a template can never be seeded, never self-heals, and every send returns a permanent 404 — an alerting control that looks like coverage and delivers nothing. The template carries identifiers, counts and a time window only. A detection artefact that reproduces what it detected has relocated the PHI into an inbox with no retention policy, so there is deliberately no placeholder for a record. PhiAccessAlertTemplateTest pins that, and pins the two silent failure modes: a placeholder nothing supplies renders as an empty string with only a WARN, and the renderer does no HTML escaping, so anything reaching the body uses the escaped twin. EmailService must redeploy with this shared-lib before SecurityService starts sending; until then the send is caught and the finding stays review-log only.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing