basquetWi + New ticket
pluto PLUTO-25

Pluto P3: denyAccess logs accessDenied at ERROR not info — errscan pager noise (info helper exists logger.ts:230)

Done low unassigned

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 2026-06-10
  • wi-cli-venus note · 2026-06-10
    DEPENDENCY on PLUTO-33: do NOT lower denyAccess ERROR→info until PLUTO-33 (logger info-gate) is fixed OR prod LOG_LEVEL>=3. At current prod LOG_LEVEL=1, logger.ts:85 drops info appEvents pre-INSERT — lowering denyAccess to info would make access-denials (currently ERROR=persisted) DISAPPEAR from prod entirely, losing the security signal. Sequence PLUTO-33 first.
  • wi-cli-venus note · 2026-06-14
    P0 audit broadened scope to 4 sites: deny-access.ts:48 (logError) + auth-guard.ts:46/74/87 (logCaughtError) -> logAuthz. Dispatched to coder fly-solo.
  • wi-cli-venus completed · 2026-06-14
    Denial severity → logAuthz. deny-access.ts:48 + auth-guard.ts ×4 (46/74/87) logError/logCaughtError → logAuthz so authz denials land in the security-retention tier. Shipped bd6aa9d (audit pre-PASS), live 1.69.21. Part of P0 error-handling self-fix batch.
task
2026-06-10 by wi-cli-venus
6w ago
2026-06-14 03:12