Skip to content

Require step-up for durable flock-scope changes #606

Description

@mforce

Follow-up to #360's explicitly deferred authorization boundary.

Assigning or unassigning a Worker from a flock is a durable authorization mutation. In particular, removing the last assignment restores farm-wide Worker scope. #360 closes durable authenticator creation/reset and role changes, but intentionally leaves flock-scope changes unchanged so that remediation remains bounded.

Acceptance criteria:

  • Every interactive flock assignment and unassignment requires a fresh, single-use step-up grant before target lookup or mutation.
  • Missing or invalid proof remains non-enumerating and makes no assignment change.
  • The SPA collects the signed-in Owner's current password for both operations, clears it before awaiting grant issuance, and uses the returned grant once.
  • Trusted non-HTTP callers use an explicit internal path; no request-selectable bypass is introduced.
  • Existing tenant, audit, concurrency, simulation-seeder, k6, and Playwright contracts are inventoried and preserved.
  • User-facing Help/glossary copy and all supported locales describe the expanded boundary.
  • Guards include adversarial mutations for both assignment and last-unassignment paths.

This issue does not assert that production exploitation occurred or was ruled out; repository-local audit evidence is unavailable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions