{
  "engagement_id": "DSCO-SEC-2026-10-06-02",
  "accountable_lead": "Arthur Colle",
  "executed_by": "Codex-assisted automated test runner",
  "function": "Research & Engineering - Offensive Security Testing",
  "start_utc": "2026-10-06T22:39:12.707610+00:00",
  "end_utc": "2026-10-06T23:39:12.707610+00:00",
  "start_local": "2026-10-06T18:39:12.707610-04:00",
  "end_local": "2026-10-06T19:39:12.707610-04:00",
  "targets": "Owned Tool Management API engineering checkout, in-process ASGI clients and controlled execution fixtures",
  "excluded": "Production endpoints, third-party systems, live model calls, real secrets, customer data, denial of service and sandbox-escape execution",
  "data_handling": "Synthetic identities; inert tokens and generated RSA test keys; substituted JWKS and execution transport; temporary DuckDB and in-memory stores. Only sanitized outcome details are published.",
  "revision": "d9e542700deba3380cb2bcebe0a9a15903c8bdcf",
  "working_tree": "Existing uncommitted engineering changes retained; selected source files hashed before and after execution.",
  "source_sha256": {
    "src/tool_management/api/tools_api.py": "09dd156513b518b5c8317346e6f0a98f83c77728528d340f21cff05f79192018",
    "src/tool_management/api/user_routes.py": "134823b14baa1735c378e44d1a5261314423459358208998d71f84adc84e3fa0",
    "src/tool_management/auth/unified.py": "924c0e5e110857ac7f42d2fd4f853c57699b33ed46e11bf2352eee82160a7b72",
    "src/tool_management/oauth.py": "c7062486ac13c548a4cfd2718cfe0202522f1fc6c5398b094bd24f352b014604",
    "src/tool_management/persistence/oauth_store.py": "9195c596b2c850545683c3fb9be1576b4a4edf00d503919326ac5e61bed58f58",
    "src/tool_management/services/backend_policy.py": "3e00e656f8b7455d935abe1897c797450a68e6102df7651f7eb4eb869d1e75c8",
    "tests/test_canonical_identity_authority.py": "3b2dad374090f69d671759ef6b727fde3b48bf5a0c4e5b707681f1bac0b3ed54",
    "tests/test_customer_mcp_oauth.py": "d88280bbfca8c956bd14597b8d9605bcc345d58cff5b779989eeb1a1b086fd6d",
    "tests/test_oauth_security.py": "da05c13bc247c5dd8fc7b18172ce8aaedca0e55e9afacce0e52c38fc2b29b65a",
    "tests/test_private_native_boundaries.py": "8302ada223afc6a3aeff8ea772f2bc2c6bd7cd7b371fadd42b8f6a9f828c4dc7"
  },
  "cases": [
    {
      "id": "retired_identity_paths",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_retired_post_paths_never_read_or_mutate_identity_stores",
      "attempt": "Submit signup, login, local-key rotation and retired OAuth operations",
      "expected": "410 responses; no local credential-store access, tokens, redirects or sentinel disclosure",
      "number": "A01",
      "checks": 12,
      "status": "PASS",
      "observed": "410 responses; no local credential-store access, tokens, redirects or sentinel disclosure"
    },
    {
      "id": "redirect_authority",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_metadata_and_frontdoors_use_fixed_central_authority",
      "attempt": "Supply an untrusted redirect destination to account entry paths",
      "expected": "Fixed canonical authority and account redirect; no cookie issued",
      "number": "A02",
      "checks": 1,
      "status": "PASS",
      "observed": "Fixed canonical authority and account redirect; no cookie issued"
    },
    {
      "id": "org_confusion",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_two_people_in_same_idp_org_do_not_share_a_customer_account",
      "attempt": "Reuse a shared identity-provider organization ID as a customer account",
      "expected": "401/403 denial and no stored secret exposure",
      "number": "A03",
      "checks": 1,
      "status": "PASS",
      "observed": "401/403 denial and no stored secret exposure"
    },
    {
      "id": "cross_tenant_header",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_explicit_signed_accounts_isolate_existing_tenant_state",
      "attempt": "Use a valid account token with another account in the selection header",
      "expected": "Foreign account rejected; permitted account returns its own metadata without raw secrets",
      "number": "A04",
      "checks": 1,
      "status": "PASS",
      "observed": "Foreign account rejected; permitted account returns its own metadata without raw secrets"
    },
    {
      "id": "claim_confusion",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_unbound_or_malformed_account_metadata_fails_closed",
      "attempt": "Supply malformed, unbound or conflicting account metadata",
      "expected": "401 denial",
      "number": "A05",
      "checks": 9,
      "status": "PASS",
      "observed": "401 denial"
    },
    {
      "id": "identity_constraints",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_explicit_account_still_requires_verified_identity_and_audience",
      "attempt": "Use wrong issuer/audience or an expired token with an explicit account",
      "expected": "401 denial",
      "number": "A06",
      "checks": 4,
      "status": "PASS",
      "observed": "401 denial"
    },
    {
      "id": "legacy_token_bypass",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_static_operator_retained_but_local_keys_and_signed_migration_tokens_denied",
      "attempt": "Try obsolete local keys, migration tokens and passwords at protected routes",
      "expected": "Unauthorized forms denied; explicit inert operator control remains separate from tenant identity",
      "number": "A07",
      "checks": 1,
      "status": "PASS",
      "observed": "Unauthorized forms denied; explicit inert operator control remains separate from tenant identity"
    },
    {
      "id": "signing_key_substitution",
      "file": "tests/test_canonical_identity_authority.py",
      "test": "test_claims_signed_by_untrusted_key_cannot_select_tenant",
      "attempt": "Sign otherwise plausible account claims with an untrusted RSA key",
      "expected": "401 denial",
      "number": "A08",
      "checks": 1,
      "status": "PASS",
      "observed": "401 denial"
    },
    {
      "id": "oauth_redirect_injection",
      "file": "tests/test_oauth_security.py",
      "test": "test_authorize_requires_an_exact_registered_redirect_uri",
      "attempt": "Supply an unregistered destination through both OAuth authorization requests",
      "expected": "400 denial and no authorization code created",
      "number": "A09",
      "checks": 1,
      "status": "PASS",
      "observed": "400 denial and no authorization code created"
    },
    {
      "id": "authorization_code_replay",
      "file": "tests/test_oauth_security.py",
      "test": "test_authorization_code_is_bound_to_its_client_and_not_burned_on_mismatch",
      "attempt": "Exchange an authorization code using a different OAuth client",
      "expected": "Wrong client rejected; authorized client can still redeem code",
      "number": "A10",
      "checks": 1,
      "status": "PASS",
      "observed": "Wrong client rejected; authorized client can still redeem code"
    },
    {
      "id": "missing_client_secret",
      "file": "tests/test_oauth_security.py",
      "test": "test_confidential_client_secret_is_required_for_code_exchange",
      "attempt": "Exchange a confidential-client code without its secret",
      "expected": "401 invalid-client denial; correct-secret positive control succeeds",
      "number": "A11",
      "checks": 1,
      "status": "PASS",
      "observed": "401 invalid-client denial; correct-secret positive control succeeds"
    },
    {
      "id": "refresh_token_replay",
      "file": "tests/test_oauth_security.py",
      "test": "test_refresh_token_is_client_bound_and_bad_attempts_do_not_consume_it",
      "attempt": "Replay a refresh token with a different client or wrong client secret",
      "expected": "Invalid grants/clients denied; authorized exchange succeeds and rotates refresh token",
      "number": "A12",
      "checks": 1,
      "status": "PASS",
      "observed": "Invalid grants/clients denied; authorized exchange succeeds and rotates refresh token"
    },
    {
      "id": "authorization_state_outage",
      "file": "tests/test_oauth_security.py",
      "test": "test_identity_denies_unavailable_authorization_state_and_recovers",
      "attempt": "Make authorization-store opening, revocation checks or grant checks fail",
      "expected": "Identity rejected without leaking test tokens/private markers; normal access recovers after restoration",
      "number": "A13",
      "checks": 3,
      "status": "PASS",
      "observed": "Identity rejected without leaking test tokens/private markers; normal access recovers after restoration"
    },
    {
      "id": "introspection_outage",
      "file": "tests/test_oauth_security.py",
      "test": "test_introspection_denies_unavailable_store_without_claiming_revocation",
      "attempt": "Make revocation-state lookup unavailable during token introspection",
      "expected": "503 inactive response without false revocation claim or token/marker leakage",
      "number": "A14",
      "checks": 1,
      "status": "PASS",
      "observed": "503 inactive response without false revocation claim or token/marker leakage"
    },
    {
      "id": "revocation_failure",
      "file": "tests/test_oauth_security.py",
      "test": "test_revocation_write_failure_is_not_acknowledged_and_can_be_retried",
      "attempt": "Fail the revocation write then retry after restoring storage",
      "expected": "Failure not acknowledged as revocation; subsequent revocation succeeds and token becomes inactive",
      "number": "A15",
      "checks": 1,
      "status": "PASS",
      "observed": "Failure not acknowledged as revocation; subsequent revocation succeeds and token becomes inactive"
    },
    {
      "id": "control_plane_access",
      "file": "tests/test_customer_mcp_oauth.py",
      "test": "test_customer_oauth_cannot_call_control_plane_meta_tools",
      "attempt": "Request a control-plane analytics tool as a customer identity",
      "expected": "Application-level tool denial; backend is not called",
      "number": "A16",
      "checks": 1,
      "status": "PASS",
      "observed": "Application-level tool denial; backend is not called"
    },
    {
      "id": "private_worker_access",
      "file": "tests/test_private_native_boundaries.py",
      "test": "test_customer_cannot_reach_shared_native_state",
      "attempt": "Bind two customer tenants to 15 private backend identifiers",
      "expected": "ACCESS_DENIED in all combinations; no transport, circuit-breaker, usage-recording or billing call",
      "number": "A17",
      "checks": 30,
      "status": "PASS",
      "observed": "ACCESS_DENIED in all combinations; no transport, circuit-breaker, usage-recording or billing call"
    }
  ],
  "exit_code": 0,
  "completed_at": "2026-10-06T22:39:16.625977+00:00",
  "source_unchanged": true,
  "junit_sha256": "2394f981202546b0995e9222e3d904360f299f0c33edb9563470e5a69d0898b0",
  "tests_passed": 70,
  "failures": 0,
  "errors": 0,
  "skipped": 0,
  "test_families": 17,
  "pytest_runtime_seconds": 3.52,
  "relationship_to_prior_run": "Focused rerun of cases overlapping the earlier 113-test suite; counts must not be added as unique coverage."
}
