Skip to content

security(csrf): extract browser-provenance follow-up from checksum owner #1361 #1705

Description

@seonghobae

Current authority — 2026-09-17

The original ownership finding is source-repaired but not yet evidence-complete, so this issue remains open.

What was wrong

Post-restack #1361 still mixed two responsibilities in backend/main.py / backend/tests/test_main.py: bounded checksum registration and an unrelated browser-provenance/origin-consistency hardening. That violated the checksum lane's single-writer boundary even though the security delta itself was valid.

Historical verification also corrected the predecessor story: merged #563 is not the backend authority for this later provenance distinction; its merged delta is AI-Hub/frontend work. The relevant browser-side origin history is #653, while the backend provenance behavior required its own owner.

Implemented succession and prerequisite repair

Dedicated owner #1706 remains the single writer for the browser-provenance boundary. Its predecessor direct-develop head b283f3bd33541cb1f7b2b8110a169c1f87636b3c exposed a real prerequisite failure: Security Scan 35086721109 failed in Trivy because protected develop still carried vulnerable dependencies outside #1706 ownership:

  • Next.js 16.0.10 — HIGH GHSA-h25m-26qc-wcjf and GHSA-v6x2-4r74-8gmx;
  • Sharp 0.34.3 / libvips 8.17.1 — HIGH CVE-2026-33191.

Canonical dependency-security owner #1623 already owns the required Next.js/Sharp floor and regression contract. #1706 therefore did not duplicate dependency files or suppress Trivy. It was ordinary/non-force restacked onto exact #1623:

Review gate is now GREEN on the current head

CodeRabbit completed a fresh review after #1706 had been retargeted onto #1623. Formal review PRR_kwDOSNjZ2s8AAAABN6kH6Q is APPROVED at 2026-09-16T21:59:23Z; current review-thread inventory is empty. The review covered exact 4788be4b..., selected the three effective browser-provenance files, and produced no actionable finding. This review remains valid only while the exact head is unchanged.

Hosted evidence is still RED for the current integration context

The exact 4788be4b... push created six PR workflow runs at 2026-09-16T21:50:12Z while the PR still targeted develop; the PR was retargeted to #1623 at 21:50:13Z. Those runs therefore belong to the earlier direct-base event context. Fresh lookup still shows those same six runs queued/pending, but later completion would not make them proof of the current #1623 integration context.

No dummy/no-op commit, temporary retarget, copied workflow, synthetic status, or blind rerun will be used to manufacture a current-context receipt. #1706's remaining acceptance is hosted current-base execution only.

The browser-provenance contract remains deliberately narrower than a generic cookie-CSRF claim. Browser-derived state-changing requests carrying provenance signals must fail closed on inconsistent/missing Origin/Referer evidence, while provenance-free API requests continue to the bearer-authentication boundary.

Canonical checksum owner #1361 remains separate:

Generated checksum duplicate #1707 remains Draft zero-effective-delta provenance on #1361; it is not a second product owner.

Remaining acceptance before this issue may close

  1. fix(deps): patch frontend audit security floors #1623 must complete its own central CodeQL prerequisite path or be completely succeeded through protected integration.
  2. security(csrf): separate browser provenance verification from checksum lane #1706 must obtain terminal required hosted evidence for its current fix(deps): patch frontend audit security floors #1623 integration context. Its current-head independent review is already satisfied while 4788be4b... remains unchanged.
  3. feat(tools): add bounded content checksum generator #1361 must complete its normal prerequisite chain and obtain current-context hosted/review evidence.
  4. Re-fetch exact heads and verify the browser-provenance delta remains exclusively owned by security(csrf): separate browser provenance verification from checksum lane #1706 and absent from feat(tools): add bounded content checksum generator #1361 effective product state.
  5. Only then may this issue close.

Refs #1361, #1623, #1691, #1706, #1707. No force push, destructive rebase, silent security deletion, scanner suppression, duplicate writer, self-approval, synthetic status, source-neutral wake commit, or gate weakening.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpriority: highHigh-priority or P1 work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions