canary: guard both forgery shapes now that real verification is live
All checks were successful
check / gate (push) Successful in 20s
All checks were successful
check / gate (push) Successful in 20s
The EPT-shaped forgery is the one that matters after G3.2 — it is what signature verification actually guards. The JWT-shaped one still exercises the human gate. Both must_refuse; a 2xx on either pages. Verified live: forged EPT -> 401 ept_invalid, forged JWT -> 503, genuine EPT -> 200. Co-Authored-By: Claude (Fable 5) <noreply@anthropic.com>
This commit is contained in:
@@ -144,16 +144,29 @@ def build_checks() -> list[Check]:
|
|||||||
# SECURITY REGRESSION GUARD. A forged, unsigned token naming a real passport
|
# SECURITY REGRESSION GUARD. A forged, unsigned token naming a real passport
|
||||||
# must be refused. On 2026-08-13 this returned HTTP 200 (full agent
|
# must be refused. On 2026-08-13 this returned HTTP 200 (full agent
|
||||||
# impersonation). If it ever returns 2xx again, the bypass is back.
|
# impersonation). If it ever returns 2xx again, the bypass is back.
|
||||||
_forged = (
|
import base64 as _b64
|
||||||
"eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0"
|
import json as _j
|
||||||
".eyJwYXNzcG9ydCI6IkVUMjYtMUVGOS1WSkFOIn0.x"
|
|
||||||
|
def _seg(d: dict) -> str:
|
||||||
|
return _b64.urlsafe_b64encode(_j.dumps(d).encode()).rstrip(b"=").decode()
|
||||||
|
|
||||||
|
# Two shapes, because they exercise two different gates. The EPT-shaped one
|
||||||
|
# is the important one now: it is what real signature verification guards.
|
||||||
|
for _label, _hdr in (
|
||||||
|
("security.forged_agent_token", {"alg": "none", "typ": "JWT"}),
|
||||||
|
("security.forged_ept", {"alg": "none", "typ": "EPT"}),
|
||||||
|
):
|
||||||
|
_tok = (
|
||||||
|
f"{_seg(_hdr)}."
|
||||||
|
f"{_seg({'sub': 'ET26-1EF9-VJAN', 'passport': 'ET26-1EF9-VJAN', 'iss': 'eternitas.ai', 'exp': 9999999999})}"
|
||||||
|
".not-a-real-signature"
|
||||||
)
|
)
|
||||||
checks.append(
|
checks.append(
|
||||||
Check(
|
Check(
|
||||||
"security.forged_agent_token",
|
_label,
|
||||||
"https://api.windygit.com/api/v1/repos",
|
"https://api.windygit.com/api/v1/repos",
|
||||||
"an unsigned token cannot impersonate an agent",
|
"an unsigned token cannot impersonate an agent",
|
||||||
headers={"Authorization": f"Bearer {_forged}"},
|
headers={"Authorization": f"Bearer {_tok}"},
|
||||||
must_refuse=True,
|
must_refuse=True,
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
|||||||
Reference in New Issue
Block a user