Skip to content

security(backend): enforce sender and recipient authorization on every stream path #69

Description

@arisu6804

Problem

A guessed stream ID or alternate endpoint can expose or mutate a stream outside the caller's sender or recipient scope.

Objective

Deliver a production-quality improvement to stream access control and route/service boundaries that creates measurable value for correctness, security, reliability, performance, or maintainability.

Implementation scope

  • Centralize ownership and participant policy at the service layer; cover list, detail, update, cancel, and withdraw paths; prevent enumeration.

Acceptance criteria

  • Only permitted participants can access each action; unauthorized responses do not reveal existence; privileged access is explicit and audited.

Required validation

  • Authorization matrix and API integration tests across sender, recipient, unrelated actor, and operator roles.
  • Existing tests and CI remain passing.
  • Add regression coverage for the original failure mode.
  • Do not weaken, delete, or skip unrelated tests to obtain a green build.

PR quality bar

  • Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
  • Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.

Out of scope

  • Broad rewrites not required by the acceptance criteria.
  • Changes to unrelated services, contracts, or user flows.

Metadata

Metadata

Assignees

No one assigned

    Labels

    GRANTFOX OSSOpen-source issue tracked by GrantFoxMAYBE REWARDEDThis issue may carry a rewardThird CampaignThird Campaign contributionenhancementNew feature or requestpriority:highHigh implementation priority

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions