Commit Graph

1 Commits

Author SHA1 Message Date
Jon Chery 04053df16e docs(P05): identity-layer threat model (REQ-347, C-6.2, C-9.2, security-engineer)
---ci---
project: acdl
phase: 5
milestone: v1.28
status: execute
persona: security-engineer
---
Add docs/threat-model.md covering 8 threats + mitigations: (T-1) password
compromise → Argon2id + fail-closed (D-228) + no raw passwords (INV-16);
(T-2) PAT theft → credentials.json stores OIDC token not raw PAT (C-7.3)
+ max TTL ≤24h dev/≤1h service-account (C-6.2) + strong-read revocation
(D-229); (T-3) JWKS DDoS → reserved concurrency 10 + 1h client cache +
optional CloudFront/WAF (C-6.2); (T-4) ABAC bypass → fail-closed
(C-6.1/C-7.1, INV-17, 7 tests); (T-5) KMS key compromise → key policy
restricts kms:Sign + 90-day rotation; (T-6) DER→raw ECDSA gotcha →
cryptography decode_dss_signature + CAP-037 round-trip test; (T-7) no
AWS-managed identity (INV-15); (T-8) audit trail integrity (INV-12 +
policy_sha D-231). Includes the C-9.2 INV-18..21 compression audit:
the spec's 4 attestation concerns (immutability, signature
verifiability, key derivation, no-managed-identity) are fully captured
by INV-6 + INV-15 + INV-16 + INV-17 + REQ-332 — no semantic gap.
2026-08-19 23:22:00 +00:00