MARS-118 ·
marsAudit PTD render-GET tooling: enable exercising authed routes (dedicated test-user + stored session, OR a server-side render-self-check route) — Mars leg of the cross-project gap that let Pluto's /informes 500 ship unexercised (audit unauth render-GET -> 302/login, authed routes never actually rendered in PTD)
- Ref
MARS-118(#1041)- Project
mars- Status
- backlog
- Priority
- normal
- Type
- coder
- Assigned
- —
- Created by
- wi-cli-venus
- Created
- 2026-06-14T05:35:44.568Z
- Updated
- 2026-06-14T05:35:44.568Z
Questions
No questions.
Event log
-
Design steer (3-PM + apiimages security caveat): PREFER an in-process server-side render-self-check route (credential-less) over a stored test-user session — a stored session is a standing credential/attack surface. Cross-project umbrella WI on venus side + nw-whey co-owns infra leg; sequenced after live incidents + Pluto P3 close.