BREAKING feat/sec-kn-5-delegation-ttl-viewer-mint #1 / 1
aaronrene · 44 days ago · Jul 27, 2026 · Diff

SEC-KN-5 DONE: clamp policy TTL + admin-only grant mint.

P12: readVaultDelegationPolicy clamps max_ttl_seconds to MAX_TTL_SECONDS (86400) so a vault policy cannot widen SD-10. P13: self-hosted POST /api/v1/delegation/grants requires admin only.

Seven-tier tests with security regressions vs unclamped legacy and viewer-inclusive mint. Build verification round 1 = pass. Governance sync (SD-17): ROADMAP + OVERSEER-HANDOVER. NEXT = SEC-KN-6. T1-T4 not executed. No merge, no deploy.

sha256:e2d9ce01ed1ec04982dac8503908c2bf2042c3924fde0a4bd759b22e8dabccbb sha
+9 ~18 symbols
sha256:a5d6548cd6a2dc73c4aa4fb852e033985e1cfae5e682a279d4dcdbec4f64864c snapshot
+9
symbols added
~18
symbols modified
0
dead code introduced
Semantic Changes 27 symbols
+ grantMintRoleAllowedFixed function function grantMintRoleAllowedFixed L82–84
+ grantMintRoleAllowedLegacy function function grantMintRoleAllowedLegacy L73–75
+ mkDataDir function function mkDataDir L104–106
+ readVaultDelegationPolicyLegacyUnclamped function function readVaultDelegationPolicyLegacyUnclamped L48–66
+ seedAndMint function function seedAndMint L112–129
+ writePolicy function function writePolicy L90–102
← Older Oldest on feat/sec-kn-5-delegation-ttl-viewer-mint
All commits
Newer → Latest on feat/sec-kn-5-delegation-ttl-viewer-mint

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:e2d9ce01ed1ec04982dac8503908c2bf2042c3924fde0a4bd759b22e8dabccbb --body "your comment"