#36 FTX-36: api_keys authn core + auth oracle client

closed critical Created 2026-07-23 15:08 · Updated 2026-07-23 15:26

Description

Edit
api_keys table (hashed futex_sk_* secrets, UNIQUE key_hash, tenant+principal binding, policy_allowlist); tenants.auth_namespace_key server-side secret; authenticate(): master-key-as-bearer rejection (UN-AUTH-1), Redis cache 60s, 401 invalid vs 503 oracle-down (UB-AUTH-4, AC-2), tenant active check (EV-TEN-1/2); delete app/auth.py split-token parsing + dead check_permission. Fixes tenant-wide impersonation. Phase 1.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...