[E24-S01] Threat model #147

Open
opened 2026-08-27 00:04:38 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E24] Security (#52)

Intent

Document a threat model covering the platform's attack surfaces so risks are understood before hardening.

Acceptance criteria

  • The threat model covers admin identity/session and CSRF.
  • The threat model covers XSS/block rendering and SSR.
  • The threat model covers uploads, import/export, and database migrations.
  • The threat model covers extension activation, extension settings, and visitor cookies.
  • The threat model covers proxy headers.

Explicitly out of scope

  • Implementing rate limits (E24-S02) and CSP/security headers (E24-S03).
  • Dependency/security response process (E24-S04).

Test plan

  • Review the threat model and confirm each listed surface has a documented threat entry.

Rollback note

  • Documentation only; no state change.

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E24] Security (#52) ## Intent Document a threat model covering the platform's attack surfaces so risks are understood before hardening. ## Acceptance criteria - The threat model covers admin identity/session and CSRF. - The threat model covers XSS/block rendering and SSR. - The threat model covers uploads, import/export, and database migrations. - The threat model covers extension activation, extension settings, and visitor cookies. - The threat model covers proxy headers. ## Explicitly out of scope - Implementing rate limits (E24-S02) and CSP/security headers (E24-S03). - Dependency/security response process (E24-S04). ## Test plan - Review the threat model and confirm each listed surface has a documented threat entry. ## Rollback note - Documentation only; no state change. ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 7 milestone 2026-08-27 00:04:38 +00:00
kpcto added the
status
proposed
kind
story
labels 2026-08-27 00:04:38 +00:00
Sign in to join this conversation.