feat(controls): B3 — categorize the rest of needs_tooling (architectural + RBAC)
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m41s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m41s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
Closes out B's coverage of the 16 needs_tooling CRA controls: - cra-ai-2,3,4,5 (minimal attack surface, secure architecture, least-privilege, tamper protection) are design properties, not local code patterns -> marked not_code_checkable (out of static-scan scope) with reviewer notes. - cra-ai-12 (RBAC) is surface-checkable (authorization points) -> added to the grounded surface pass; note points to the gated grounded mechanism. Final CRA coverage: covered 13 | needs_tooling 8 (all grounded-covered, gated) | not_code_checkable 19. The 16 needs_tooling now fully categorized: 4 custom-semgrep (B1) + 8 grounded surface (B2/B3, gated) + 4 architectural (B3). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
4ef257bfe2
commit
7cd4ffdaab
@@ -47,6 +47,17 @@ pub const SURFACES: &[Surface] = &[
|
||||
"ratelimit",
|
||||
],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-12", // Rollenbasierte Autorisierung (RBAC)
|
||||
terms: &[
|
||||
"authorize",
|
||||
"permission",
|
||||
"role",
|
||||
"rbac",
|
||||
"require_role",
|
||||
"has_role",
|
||||
],
|
||||
},
|
||||
Surface {
|
||||
control_id: "cra-ai-24", // Security-Logging
|
||||
terms: &["login", "authorize", "permission", "role", "admin", "audit"],
|
||||
@@ -196,10 +207,11 @@ mod tests {
|
||||
|
||||
#[test]
|
||||
fn surfaces_cover_the_absence_based_controls() {
|
||||
assert_eq!(SURFACES.len(), 7);
|
||||
assert_eq!(SURFACES.len(), 8);
|
||||
for id in [
|
||||
"cra-ai-6",
|
||||
"cra-ai-11",
|
||||
"cra-ai-12",
|
||||
"cra-ai-24",
|
||||
"cra-ai-27",
|
||||
"cra-ai-28",
|
||||
|
||||
Reference in New Issue
Block a user