[BLOCKER] Add authentication to coordinator integration endpoints #184
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
All 6 coordinator integration endpoints are completely unauthenticated, allowing external systems to create, modify, and fail jobs without any authorization.
Vulnerable Endpoints
Location
apps/api/src/coordinator-integration/coordinator-integration.controller.ts
Attack Vectors
Impact
Acceptance Criteria
Implementation Notes
References
M4.2-Infrastructure verification report (2026-02-02)
Security review agent ID: a1b8b3f