fix(privacy): mask the BSN recorded as the document audit Actor (RB-04)
DocumentStore wrote one audit row per upload and per user delete carrying the
acting citizen's raw BSN as AuditEntry.Actor, persisted to SQLite — on a
store whose own doc comment says it holds metadata only, never file content
"or other PII". Same shape as RB-02, in a second store.
Masked at the two citizen call sites rather than inside Audit, because the
third actor is the literal "admin" and MaskTail("admin", 3) is "**min";
masking centrally would mean guessing which actors are BSNs and which are
role names. Audit's doc comment now states that actors arrive redacted.
StoredDocument.Owner is untouched: it is the authorization key that
DeleteOwned, ForeignIds and RB-01's content check all compare against, so the
BSN stays where it is load-bearing and leaves the trail where it was only
decoration. No endpoint exposes AuditLog, so no response shape changes.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -2,13 +2,16 @@ using System.Net;
|
||||
using System.Net.Http.Headers;
|
||||
using System.Net.Http.Json;
|
||||
using BigRegister.Api.Contracts;
|
||||
using BigRegister.Api.Data;
|
||||
using Microsoft.AspNetCore.Mvc.Testing;
|
||||
|
||||
namespace BigRegister.Tests;
|
||||
|
||||
/// RB-01/BIO-004: GET /uploads/{id}/content and /uploads/status used to take no
|
||||
/// HttpContext at all — a diploma or identity scan was protected by GUID
|
||||
/// unguessability alone, while DELETE on the same resource was owner-scoped.
|
||||
/// Who may see what about an upload. RB-01/BIO-004: GET /uploads/{id}/content and
|
||||
/// /uploads/status used to take no HttpContext at all — a diploma or identity scan was
|
||||
/// protected by GUID unguessability alone, while DELETE on the same resource was
|
||||
/// owner-scoped. RB-04/BIO-005: the document audit trail recorded the raw owner BSN as
|
||||
/// its Actor, on a store whose own doc comment says it holds no PII.
|
||||
public class UploadAccessTests(TestWebApplicationFactory factory) : IClassFixture<TestWebApplicationFactory>
|
||||
{
|
||||
private readonly HttpClient _client = factory.CreateClient();
|
||||
@@ -69,6 +72,19 @@ public class UploadAccessTests(TestWebApplicationFactory factory) : IClassFixtur
|
||||
("X-Medewerker", "medewerker-1"), ("X-Rollen", "geen"))).StatusCode);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task The_document_audit_trail_records_a_masked_actor()
|
||||
{
|
||||
var id = await UploadAsOwner();
|
||||
(await _client.DeleteAsync($"/api/v1/uploads/{id}")).EnsureSuccessStatusCode();
|
||||
|
||||
var rows = DocumentStore.AuditLog.Where(e => e.DocumentId == id).ToList();
|
||||
Assert.Equal(new[] { "upload", "delete-user" }, rows.Select(e => e.Action));
|
||||
Assert.All(rows, e => Assert.Equal("******782", e.Actor));
|
||||
// The unmasked BSN stays where it is load-bearing — the ownership key, not the trail.
|
||||
Assert.All(rows, e => Assert.DoesNotContain(DocumentStore.DemoOwner, e.Actor));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Status_reports_another_citizens_localId_as_unknown()
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user