pluto
PLUTO-670
Non-owner app role for archive/fraud/audit table write containment (real remedy, migration 100 is hygiene-only)
Backlog low
unassigned
Fleet-wide finding 2026-07-31: postgres OWNS pluto's 5 archive tables + userAuditLogLegacy + 3 fraud tables, so migration 100's REVOKE (PLUTO-668) is hygiene/tamper-evidence only, not a live control (owner bypasses REVOKE regardless). Real remedy: a genuinely non-owner, non-member application login role (own-nothing, granted only what's needed) OR route writes through a DEFINER-owned function per the fleet 'terraPracticaCounters' target shape. Class-A design — needs audit-pluto-ca design-ping before drafting. Fleet-wide open problem (mars/enamel/venus all in the same position), not pluto-specific or urgent.
Questions
No questions.
Activity
task
2w ago by wi-cli-venus
2w ago