[E24-S01-T01] Threat model #349

Open
opened 2026-08-27 08:08:47 +00:00 by kpcto · 0 comments
Owner

Parent story: [E24-S01] Threat model (#147)

Intent

Write the threat model covering the listed attack surfaces.

Acceptance criteria

  • The threat model covers identity/session, CSRF, XSS, SSR, uploads, import/export, and migrations.
  • The threat model covers extension activation, extension settings, visitor cookies, and proxy headers.
  • Each listed surface has a documented threat entry.

Explicitly out of scope

  • Rate limits (E24-S02), CSP/security headers (E24-S03), and dependency response process (E24-S04).

Test plan

  • Review the threat model and confirm every listed surface has a documented entry.

Rollback note

  • Documentation only; no state change.

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E24-S01] Threat model (#147) ## Intent Write the threat model covering the listed attack surfaces. ## Acceptance criteria - The threat model covers identity/session, CSRF, XSS, SSR, uploads, import/export, and migrations. - The threat model covers extension activation, extension settings, visitor cookies, and proxy headers. - Each listed surface has a documented threat entry. ## Explicitly out of scope - Rate limits (E24-S02), CSP/security headers (E24-S03), and dependency response process (E24-S04). ## Test plan - Review the threat model and confirm every listed surface has a documented entry. ## Rollback note - Documentation only; no state change. ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 7 milestone 2026-08-27 08:08:47 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 08:08:47 +00:00
Sign in to join this conversation.