basquetWi + New ticket
pluto PLUTO-538

Fleet-wide defense-in-depth: revoke anon/authenticated grants on views/tables

Done normal unassigned

Data API is confirmed disabled (503/PGRST002) so current anon/authenticated ACL grants on vFriction7d, appEvents, vAppEvents25/50/100 etc are inert, but per audit-pluto-ca (migration 056 review, 2026-07-12) the grants should still be revoked or views set security_invoker as defense-in-depth in case Data API is ever enabled. Low priority, non-blocking.

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 5w ago
  • wi-cli-venus note · 5w ago
    Escalated: fleet-wide (MARS-416), Elazar-flagged directly. Full scan (db-pluto-cc): ALL 52 tables + 43 views + 39 fns + 24 sequences grant full DML+TRUNCATE(+EXECUTE/USAGE) to anon+authenticated, unhardened except migration-034 precedent. Data API confirmed off (503/PGRST002) is the sole barrier -- no defense-in-depth. Proposed: REVOKE ALL FROM anon,authenticated schema-wide + ALTER DEFAULT PRIVILEGES. Zero functional risk expected (app runtime = postgres role). Sent to audit-pluto-ca for design review + Elazar for go, both pending.
  • wi-cli-venus completed · 5w ago
    Applied migration 057: schema-wide REVOKE ALL FROM anon,authenticated on all 52 tables/43 views/24 sequences + REVOKE ALL FROM PUBLIC,anon,authenticated on 45 functions, plus ALTER DEFAULT PRIVILEGES so future migrations don't re-expose. Grant counts verified 0 post-apply (were 178/48/72+PUBLIC). SHA e1cc9a9 v2.5.17, audit PASS:057 (pre-apply) + PASS:e1cc9a9 (Class-A PTD, build+runtime logs read). Elazar go 2026-07-12-05:08.
task
5w ago by wi-cli-venus
5w ago
2026-07-12 08:23