WIP: stage all uncommitted work — sprints 46-221, graduation headers, specialist fleet, test steps 909-1988
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
20
tmp_eval_complex_specs_20260303/fs_003_python.md
Normal file
20
tmp_eval_complex_specs_20260303/fs_003_python.md
Normal file
@@ -0,0 +1,20 @@
|
||||
# AuthZ Policy Propagation (fs_003)
|
||||
|
||||
## Objective
|
||||
Introduce deny-by-default RBAC policy and propagate through backend auth middleware, endpoint guards, frontend route guards, and admin policy editor.
|
||||
|
||||
## Language & Library Constraints
|
||||
- Primary language: python
|
||||
- Available libraries: fastapi, pydantic, sqlalchemy
|
||||
- Prefer explicit use of selected library APIs in task execution contracts.
|
||||
|
||||
## Required Artifacts
|
||||
- server/auth/*.py
|
||||
- server/routes/*.py
|
||||
- web/src/guards/*
|
||||
- web/src/admin/policy/*
|
||||
- security_test_plan.md
|
||||
|
||||
## Acceptance
|
||||
- Generate deterministic taskitems with strict execution contracts.
|
||||
- Include selected library and preferred APIs per task where applicable.
|
||||
Reference in New Issue
Block a user