The #1044 class is not gitea-specific: 22 shared-credential call sites across 5 services have no per-identity path #1055
Open
opened 2026-08-05 18:24:09 +00:00 by Mos
·
0 comments
No Branch/Tag Specified
main
greenfield/fomo-lin
feat/lease-promotion-and-harness-isolation
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
next
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1007-suite-hermeticity
fix/991-comment-url-scheme-normalise
feat/push-guard-null-case-verification
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1055
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The finding, stated as a PROPERTY rather than an instance
#1044 is commonly described as "the gitea token resolver falls open." That framing stops at its
instance. The property is:
That class is not gitea-specific. #1045 instruments the two gitea resolvers — correct and in scope —
but the same shape exists, uninstrumented, across the rest of the framework.
Measured
Callers of
load_credentials(excluding the loader itself):~/.config/mosaic/tools~/.config/mosaic(whole)(Two honest counts at different scopes — stating both and the method rather than picking one.)
Per-service, and this is the decisive column:
Twenty-two call sites across five services materialize a shared credential with no per-identity path
at all.
Why it matters
If a seat's Portainer redeploy, Authentik user-create, GLPI ticket action, Woodpecker trigger, or
Cloudflare record change lands under a shared account, the shape is identical to #1044 and nothing
currently detects it. The gitea case was found only because commit authorship makes misattribution
visible after the fact. These services have no equivalent read-back — an action attributed to the
shared account leaves no artifact naming the wrong actor, so the failure is not merely undetected, it is
undetectable by the method that caught the gitea case.
Scope
Not #1045's work and explicitly not a request to widen it. #1045 should land as scoped. This is filed
as the observation so the class transfers, per the rule the fleet earned tonight: a finding transfers
only if the class is articulated — an instance-shaped finding stops at its instance.
Suggested owner: whoever holds the credential lane after #1045. Suggested first step is not a fix but
a decision: which of these services need per-identity credentials at all? Several may be legitimately
shared-account operations, and "this is correctly shared" is a fine answer — stated, once, per
service, rather than left as an unexamined default.
Related
#1044 (fail-open on unset identity) · #1045 (mosaic cred, instruments the gitea resolvers) ·
#1052 (
load_credentialsnot re-entrant — same loader, different defect) · #1013 (long-lived bearertokens).