Skip to content

BReg subject access log: review follow-ups from #1766 #1768

Description

@jeremi

Non-blocking findings from the review of #1766 (subject access logs). Line numbers refer to 8ae9467.

  1. Exemption audit can record an entry that was never stored. crates/registry-breg/src/subject_access_log.rs:183-205 writes the exemption audit ("begin", then "authorized") before the log INSERT, inside the read transaction. If that transaction rolls back, the operational audit shows a delayed entry that never landed.
  2. Nothing checks trusted intermediaries at authoring time. crates/registry-breg/src/evidence_source.rs:440 enables forwardAccessAttribution whenever the entity declares accessLog, but nothing checks that the Evidence connection's client is listed in trustedIntermediaries. If it isn't, BReg refuses the forwarded headers and every lookup fails at runtime. That fails safe, but bregctl or evidencectl source add could catch it before deployment.
  3. The Evidence export protocol change needs a changelog entry. The exported protocol moves from breg-evidence-lookup-v1 to -v2, and access-attribution-v1 is added to readSemantics for every entity, whether logged or not (evidence_source.rs:519). This changes the behaviorRevision of every exported Evidence source and needs a breaking-change entry in the release notes.
  4. ACCESS-LOG.md doesn't cover every read path. It doesn't say whether these reads are logged:
    • change-request views
    • reads inside Rhai action handlers
    • hook and webhook payloads
    • exports

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions