Commit Graph

3 Commits (85adbb553a90f19de27c03b2ab2f7d97ab2fa731)

Author SHA1 Message Date
Thomas Joise ea0bc146bb docs(security): SEC-A5 — /bills/offline commits bills with no authentication
Automated review (CRITICAL): route registered above requireAuth, identity
fields trusted from the body. Two fix options specified; must land before
any pilot. Companion to SEC-C6.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2 weeks ago
Thomas Joise 507eec67f3 docs(security): SEC-C6 — override approval is client-asserted, audit forgery hole
Automated review flagged POST /api/bills trusting overrides[].approvedByUserId
from the client; verify-pin result never bound to the commit. Server-side
approval-token fix specified; must land before any pilot (Phase 1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2 weeks ago
Thomas Joise cb5df2f0d6 docs: HQ ops console spec (D15) + roadmap/decisions updates
New docs/14-SPEC-HQ-CONSOLE.md: internal ops console (apps/hq) for the
~300 Classic clients - quotations/proforma/invoices in minutes with Gmail
send, recurring billing + reminders, AMC, per-client AWS cost, interaction
log; replaces the internal Oracle APEX app. Doc-11 HQ Console started early.

Also: HQ workstream in 04-ROADMAP, D15 in 06-DECISIONS, cross-refs in
doc 11 + STATUS. First commit of the docs baseline (00-17).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2 weeks ago