#101 FTX-101: audit harness mints a platform key per run and never revokes it — 10 active platform-admin keys on prod

closed high bug Created 2026-07-31 19:22 · Updated 2026-07-31 19:32

Description

Edit
EARS SPEC: - When the audit harness finishes, it shall revoke every credential it created. - Futex shall provide an operator command that revokes stale platform API keys while preserving a designated key. - If a revocation command is run without an explicit key to preserve, then it shall refuse to revoke any platform key. - When a stale key is revoked, Futex shall record it in the audit trail. CAUSE: audit/evaluations/setup_harness.py calls scripts/bootstrap_platform_key.py on every run, prints the raw key to stdout, creates a tenant plus three tenant keys, and revokes none of it. Nine runs on 2026-07-30 between 01:13 and 01:52 left nine full-privilege platform-admin keys active on production, plus 17 'Audit Key' and 28 'probe' tenant keys.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...