Single-witness audit fields remain unverifiable even when correctly frozen, dev finds
A software developer acknowledged a critical gap in their audit logging framework after reader feedback revealed that correctly captured and frozen fields can still be unverifiable if no second party holds a comparable value. Two real-world examples were cited: timing fields logged before an acceptance event that should have been impossible, and verdict events where all 1,482 entries shared a single signing key, leaving no basis for contradiction. The developer's own codebase, aine-control-plane, was found to contain a requested_by field that was never compared against the authenticated context, meaning any caller could name their own requester undetected for roughly a month after the repo was open-sourced on August 31. A second contributor pointed out that simply reversing field precedence was insufficient, since any code path that omits context population would still allow the request body to set the actor. The fix, merged as PR #7, records both the payload-supplied and context-supplied values in separately named fields and explicitly avoids merging them.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in