Merged PR 2408: updated context for current state at 19062026
updated context for current state at 19062026 Related work items: #23754
This commit is contained in:
@@ -122,3 +122,24 @@ Current context:
|
||||
- Householder blocked-message suppression
|
||||
- CPO ended-message / deadline consistency
|
||||
- missing or conflicting process information handling
|
||||
|
||||
---
|
||||
|
||||
### Q-005: Portal API Security Boundary Assessment
|
||||
|
||||
date: 2026-06-19
|
||||
author: Architect Review
|
||||
scope: API endpoints and ownership enforcement
|
||||
type: question
|
||||
rationale: Discovery programme complete. Security/access boundary review identified as the highest-value architecture stream.
|
||||
impact: security, privacy, maintainability
|
||||
status: open
|
||||
|
||||
Question:
|
||||
What is the current ownership-validation and access-control posture across public and authenticated API endpoints?
|
||||
|
||||
Needed from:
|
||||
Architecture review stream
|
||||
|
||||
Decision deadline:
|
||||
Before major domain-layer adoption or API modernization work.
|
||||
|
||||
Reference in New Issue
Block a user