Skip to content

hardening(docs): mint script uses the resolver's pepper rule - #23

Merged
SaulBuilds merged 1 commit into
mainfrom
fix/pba-r2-docs-mint-pepper
Sep 25, 2026
Merged

SaulBuilds merged 1 commit into
mainfrom
fix/pba-r2-docs-mint-pepper

Conversation

@SaulBuilds

Copy link
Copy Markdown
Contributor

Summary

Small hardening follow-up to #22.

  • Shared rule. The MCP pepper rule moves to lib/auth/mcp-pepper.ts, which has no server-only or alias imports. lib/auth/mcp-keys.ts re-exports it.
  • Mint script. scripts/mint-mcp-key.mjs now applies the same rule, so it refuses any pepper the resolver would refuse and never mints a key that can't resolve.
  • Build check. check:mcp-keys loads the shared module.
  • Tests. A parity test mints under a table of peppers (low variety, whitespace, padded, short, borderline, valid). It asserts a key is minted exactly when the resolver accepts the pepper, and that the key then resolves. Reverting the mint check to length-only turns 5 cases red. Details are in the private audit record.

Tests and commands: main: 101 passed / 4 skipped. This PR: 109 / 4. The run used node 22.21.1 and npm 10.9.4: npm ci, audit --audit-level=high, typecheck, test, build, verify:bundle, content-lint --strict, sbom. All green.

🤖 Generated with Claude Code

https://claude.ai/code/session_012cD3fDq5vhh2YWZPU2SV6H

The pepper rule moves to lib/auth/mcp-pepper.ts (no server-only or alias
imports). lib/auth/mcp-keys.ts re-exports it, and scripts/mint-mcp-key.mjs
uses it, so the script refuses any pepper the resolver would refuse and never
mints a key that can't resolve. check:mcp-keys loads the shared module. A
parity test mints under a table of peppers and asserts that a key is minted
exactly when the resolver accepts the pepper, and that it then resolves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012cD3fDq5vhh2YWZPU2SV6H
@SaulBuilds
SaulBuilds merged commit e5f1209 into main Sep 25, 2026
9 checks passed
@SaulBuilds
SaulBuilds deleted the fix/pba-r2-docs-mint-pepper branch September 25, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants