[E17-S01-T02] >=256-bit random token #319

Open
opened 2026-08-27 08:05:46 +00:00 by kpcto · 0 comments
Owner

Parent story: [E17-S01] Anonymous preference identity (#123)

Intent

Generate the anonymous identity token from at least 256 bits of cryptographically secure randomness.

Acceptance criteria

  • The token is generated from at least 256 bits of secure randomness.
  • The raw token is sent only to the browser, never stored verbatim.
  • Token generation uses the platform CSPRNG.

Explicitly out of scope

  • Lazy creation, hashing, expiration, cookie contents and corrupt-token handling (sibling tasks T01, T03-T06).

Test plan

  • Assert the token source provides at least 256 bits of entropy.
  • Assert the raw token is not persisted server-side.

Rollback note

  • Revert the commit. No data changes.

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E17-S01] Anonymous preference identity (#123) ## Intent Generate the anonymous identity token from at least 256 bits of cryptographically secure randomness. ## Acceptance criteria - The token is generated from at least 256 bits of secure randomness. - The raw token is sent only to the browser, never stored verbatim. - Token generation uses the platform CSPRNG. ## Explicitly out of scope - Lazy creation, hashing, expiration, cookie contents and corrupt-token handling (sibling tasks T01, T03-T06). ## Test plan - Assert the token source provides at least 256 bits of entropy. - Assert the raw token is not persisted server-side. ## Rollback note - Revert the commit. No data changes. ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 5 milestone 2026-08-27 08:05:46 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 08:05:46 +00:00
Sign in to join this conversation.