Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
8277789
Gate security-event reporting on platform enrolment, not a config flag
patchstackdave Aug 31, 2026
6788616
Carry the reporting state to the platform, and keep it current
patchstackdave Aug 31, 2026
6d2d5b8
Acknowledge the settled reporting state, and disclose the new default
patchstackdave Aug 31, 2026
c227e04
Count capability acknowledgements apart from event delivery
patchstackdave Aug 31, 2026
5f3fe5b
Acknowledge the settled state after a refresh, not only after boot
patchstackdave Aug 31, 2026
1411e8b
Resolve a client address from what the runtime observed, with its pro…
patchstackdave Aug 31, 2026
d49614c
Validate every field of a trust policy, and keep an IPv6 zone or refu…
patchstackdave Aug 31, 2026
088e43a
Read a trust policy and a forwarded header from own properties only
patchstackdave Aug 31, 2026
99ce09d
Refuse a mapped IPv4 address that carries a zone
patchstackdave Aug 31, 2026
ec6740b
Resolve the client address once per request, and share it
patchstackdave Sep 1, 2026
2f24e72
Carry every addressable field, and the resolved address, all the way …
patchstackdave Sep 1, 2026
2fc0cb8
Keep raw evidence, and let no callback rewrite what the platform is told
patchstackdave Sep 1, 2026
b1f9579
Narrow the callback's view of a rule, and take raw evidence only from…
patchstackdave Sep 1, 2026
66c2665
Take request evidence only from the request, and record the address c…
patchstackdave Sep 1, 2026
27d5421
Take an inherited request field only from a framework accessor
patchstackdave Sep 1, 2026
063e800
Retry a security event that is worth retrying, once, under one key
patchstackdave Sep 1, 2026
c2d692d
Leave nothing outstanding when reporting stops, and bound a request i…
patchstackdave Sep 1, 2026
794e23b
Authenticate a detection on its own, and let a shutdown wait for the …
patchstackdave Sep 1, 2026
4dd329e
End the drain when the shutdown budget runs out, and wait for every b…
patchstackdave Sep 1, 2026
4c4f7f6
Bound the block log's shutdown, and track the sends a queue no longer…
patchstackdave Sep 1, 2026
9717dbf
Give the block log a controller that exists before a shutdown needs it
patchstackdave Sep 1, 2026
7e8d69e
Let a shutdown own the block log's queue from the moment it begins
patchstackdave Sep 1, 2026
615311c
Derive what a rule permits to be captured, and capture nothing yet
patchstackdave Sep 1, 2026
554bf7d
Take capture permissions from the rule contract, and publish the opt-in
patchstackdave Sep 1, 2026
84f13e4
Read the evidence a plan permits, from the reading the match was deci…
patchstackdave Sep 1, 2026
200af7f
Send the evidence a rule permitted, and say so in the shipped docs
patchstackdave Sep 1, 2026
a2a363b
Report the settled baseline, bound evidence at the wire, and say so e…
patchstackdave Sep 1, 2026
df45589
Carry the baseline on every runtime and phase, and validate what reac…
patchstackdave Sep 1, 2026
de617f3
Read a capture's own fields only, and state the egress baseline as it…
patchstackdave Sep 1, 2026
1ed9a41
State the shared baseline once, the phase-specific fields twice, and …
patchstackdave Sep 1, 2026
eacf012
Say what queryKeysOf returns
patchstackdave Sep 1, 2026
b3645d7
Refuse to publish while the server side is not ready
patchstackdave Sep 1, 2026
9e5a351
Note the reporting release dependencies where a release is cut
patchstackdave Sep 1, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
193 changes: 175 additions & 18 deletions AGENT-INSTALL.md

Large diffs are not rendered by default.

19 changes: 19 additions & 0 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,25 @@ You can also publish an existing tag directly:
gh workflow run publish.yml -f version=0.3.3
```

## Before publishing detection reporting

Detection reporting depends on two server-side behaviours. Check both before cutting a
release that includes it, because a published version cannot be withdrawn from anyone
who has already installed it:

- **The detections endpoint deduplicates on `Idempotency-Key`.** Connect sends a stable
key for every attempt at a batch and a fresh one per batch, so a redelivery is
identifiable — but whether it is counted once is the endpoint's to decide. Published
ahead of that, a retry after a lost acknowledgement inflates the counts these reports
are read for.
- **Ingest accepts and stores the current payload:** the `capture` object, the baseline
fields `method`, `user_agent`, `query_keys` and `query_keys_total`, and
`reporting_state` on the detections body. An endpoint that rejects or silently drops
them turns every report into a delivery failure, or into a record missing the evidence
it was sent to carry.

Delete this section once both have shipped.

## Notes

- Tags must be `vX.Y.Z` (the leading `v` is stripped to get the npm version).
Expand Down
30 changes: 28 additions & 2 deletions rule-contract.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"$comment": "Generated from src/protect/rules/contract.js by scripts/emit-rule-contract.mjs. Do not edit.",
"version": "2.7",
"version": "2.8",
"sources": {
"raw": {
"keyed": false
Expand Down Expand Up @@ -359,6 +359,9 @@
"method"
],
"null_valued_properties": "refused",
"null_exempt_properties": [
"capture"
],
"rule_property_shapes": {
"max_bytes": "positive-number",
"bypass_limit": "boolean",
Expand Down Expand Up @@ -386,8 +389,31 @@
"set_headers",
"remove_headers",
"cookie_flags",
"ensure"
"ensure",
"capture"
],
"capture": {
"version": 1,
"required": [
"version",
"raw_chars"
],
"additional_properties": false,
"properties": {
"version": {
"type": "integer",
"const": 1
},
"raw_chars": {
"type": "integer",
"minimum": 1
}
},
"raw_chars_effective_maximum": 512,
"unknown_version": "grants no capture; the rule still applies",
"unreadable": "grants no capture; the rule still applies",
"raw_chars_note": "a request for a bounded PREFIX of the body; more than the effective maximum yields the maximum"
},
"limits": {
"maxRules": 5000,
"maxWhitelists": 2000,
Expand Down
447 changes: 447 additions & 0 deletions src/protect/capture-plan.js

Large diffs are not rendered by default.

Loading
Loading