Three security boundaries#
- Authenticate identity
- Check capability permission
- Approve exact request
Authentication establishes identity. RBAC controls capabilities and scopes. Approval authorizes one bound execution; it is not a replacement for either identity or permission checks.
Sessions and CSRF#
Web sessions persist with expiry. Cookies use HttpOnly and SameSite=lax; secure behavior depends on configuration/HTTPS. Authenticated mutations require a session-matched X-CSRF-Token. The web API does not have a verified bearer API-key authentication scheme.
Local and AD authentication#
Local hashing uses salted PBKDF2-SHA256 with constant-time verification. AD uses a configured provider/worker and canonical identity mapping. Redacted credential lines limit exact end-to-end reconstruction. Local recovery administrator protections prevent lockout.
RBAC and tools#
Permissions are checked before provider execution and again for approved actions. Deny takes precedence; approval effects can strengthen policy. Dynamic MCP tools follow the same runtime gate. User-specific hiding of denied tools in catalogs is not verified.
Approval and audit#
Approval fingerprints prevent changed-request/replay reuse. Pending state is in memory; audit/history persistence is separate. Security audit masking targets sensitive keys, but this is not a guarantee of comprehensive secret removal or an audit certification.
HTTPS and certificates#
Local CA/server certificate/key generation and certificate download/help exist. HTTPS is not universal across every launch mode. Public-CA issuance, automatic rotation and external trust installation are not verified.
Secrets#
Production protected settings use Windows CurrentUser DPAPI with a protected envelope. Personal MCP records are keyed by owner/server; Codex credentials use a protector. The plaintext protector is a testing helper, not a production fallback.
External integrations and packages#
MCP profiles use configured credentials/transports. Personal credentials fail closed instead of falling back to a shared bearer. read_only metadata is an operator assertion, not a remote behavior audit.
Module validation checks archive and manifest/import contracts but imports arbitrary Python. Ordinary module ZIP signatures and process sandboxing are not verified. Update packages have separate integrity/signature checks.
Rate limiting and errors#
Failed-login throttling defaults to five failures in 300 seconds and is held in memory. Missing authentication returns 401; authorization/CSRF denial returns 403; throttled login can return 429. A distributed/global web API limiter is not verified. Action1 has separate outbound pacing/retry handling.