Files
git.stella-ops.org/docs/implplan/SPRINT_216_web_v.md
master ae69b1a8a1 feat: Add documentation and task tracking for Sprints 508 to 514 in Ops & Offline
- Created detailed markdown files for Sprints 508 (Ops Offline Kit), 509 (Samples), 510 (AirGap), 511 (Api), 512 (Bench), 513 (Provenance), and 514 (Sovereign Crypto Enablement) outlining tasks, dependencies, and owners.
- Introduced a comprehensive Reachability Evidence Delivery Guide to streamline the reachability signal process.
- Implemented unit tests for Advisory AI to block known injection patterns and redact secrets.
- Added AuthoritySenderConstraintHelper to manage sender constraints in OpenIddict transactions.
2025-11-08 23:18:28 +02:00

4.0 KiB

Sprint 216 - Experience & SDKs · 180.F) Web.V

Active items only. Completed/historic work now resides in docs/implplan/archived_sprints_tasks.md (updated 2025-11-08).

[Experience & SDKs] 180.F) Web.V Depends on: Sprint 180.F - Web.IV Summary: Experience & SDKs focus on Web (phase V).

Task ID State Task description Owners (Source)
WEB-RISK-66-001 Risk API routing TODO Expose risk profile/results endpoints through gateway with tenant scoping, pagination, and rate limiting. BE-Base Platform Guild, Policy Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-RISK-66-002 Explainability downloads TODO Add signed URL handling for explanation blobs and enforce scope checks. Dependencies: WEB-RISK-66-001. BE-Base Platform Guild, Risk Engine Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-RISK-67-001 Risk status endpoint TODO Provide aggregated risk stats (/risk/status) for Console dashboards (counts per severity, last computation). Dependencies: WEB-RISK-66-002. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-RISK-68-001 Notification hooks TODO Emit events on severity transitions via gateway to notifier bus with trace metadata. Dependencies: WEB-RISK-67-001. BE-Base Platform Guild, Notifications Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-SIG-26-001 Signals proxy endpoints TODO Surface /signals/callgraphs, /signals/facts read/write endpoints with pagination, ETags, and RBAC. BE-Base Platform Guild, Signals Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-SIG-26-002 Reachability joins TODO Extend /policy/effective and /vuln/explorer responses to include reachability scores/states and allow filtering. Dependencies: WEB-SIG-26-001. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-SIG-26-003 Simulation hooks TODO Add reachability override parameters to /policy/simulate and related APIs for what-if analysis. Dependencies: WEB-SIG-26-002. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-TEN-47-001 Auth middleware TODO Implement JWT verification, tenant activation from headers, scope matching, and decision audit emission for all API endpoints. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-TEN-48-001 Tenant context propagation TODO Set DB session stella.tenant_id, enforce tenant/project checks on persistence, prefix object storage paths, and stamp audit metadata. Dependencies: WEB-TEN-47-001. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-TEN-49-001 ABAC & audit API TODO Integrate optional ABAC overlay with Policy Engine, expose /audit/decisions API, and support service token minting endpoints. Dependencies: WEB-TEN-48-001. BE-Base Platform Guild, Policy Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-VEX-30-007 VEX consensus routing TODO Route /vex/consensus APIs with tenant RBAC/ABAC, caching, and streaming; surface telemetry and trace IDs without gateway-side overlay logic. BE-Base Platform Guild, VEX Lens Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-VULN-29-001 Vuln API routing TODO Expose /vuln/* endpoints via gateway with tenant scoping, RBAC/ABAC enforcement, anti-forgery headers, and request logging. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-VULN-29-002 Ledger proxy headers TODO Forward workflow actions to Findings Ledger with idempotency headers and correlation IDs; handle retries/backoff. Dependencies: WEB-VULN-29-001. BE-Base Platform Guild, Findings Ledger Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-VULN-29-003 Simulation + export routing TODO Provide simulation and export orchestration routes with SSE/progress headers, signed download links, and request budgeting. Dependencies: WEB-VULN-29-002. BE-Base Platform Guild (src/Web/StellaOps.Web/TASKS.md)
WEB-VULN-29-004 Telemetry aggregation TODO Emit gateway metrics/logs (latency, error rates, export duration), propagate query hashes for analytics dashboards. Dependencies: WEB-VULN-29-003. BE-Base Platform Guild, Observability Guild (src/Web/StellaOps.Web/TASKS.md)