# SECURITY AUDIT 2026

## Scope
- Playbook critical/high findings from `PRODUCTION_READINESS_PLAYBOOK.md`
- Security-sensitive code paths in:
  - `packages/backend/convex/http.ts`
  - `packages/backend/convex/lib/mcpClient.ts`
  - `packages/backend/convex/private/*.ts`
  - `apps/web/app/api/oauth/*`
  - `packages/backend/convex/public/orgConnections.ts`

## Findings and patch status

### P0-1 Hardcoded credentials in source (`lib/mcpClient.ts`)
- **Risk:** credential leakage.
- **Status:** Patched.
- **Change:** removed hardcoded `CDATA_EMAIL` and `CDATA_PAT` fallbacks and now fail-fast when missing.

### P0-2 BOLA/IDOR via client-supplied `organizationId`
- **Risk:** cross-tenant data read/write.
- **Status:** Partially patched (in this iteration).
- **Change:** added `lib/auth.ts` and enforced org membership checks in:
  - `private/customApiTools.ts`
  - `private/socialChannels.ts`
  - `private/phoneNumbers.ts`
  - `private/conversations.ts` (`listByOrganization`)
  - `private/widgetSettings.ts` (`getByOrganizationId`)
- **Remaining:** full sweep of all public/private Convex entrypoints.

### P0-3 Marketplace admin actions missing auth
- **Risk:** unauthorized governance actions.
- **Status:** Patched.
- **Change:** added `requirePlatformAdmin` checks in `private/marketplace.ts` for queue/read/write/admin operations.

### P0-4 OAuth callback trust boundary
- **Risk:** token binding to wrong org/user.
- **Status:** Patched.
- **Change:**
  - Added signed state helper (`apps/web/lib/oauthState.ts`) with HMAC + nonce + TTL.
  - Enforced callback session-org/user checks in Google/GitHub/Microsoft callbacks.
  - Added callback shared-secret gate (`OAUTH_CALLBACK_TOKEN`) for `public/orgConnections.storeOAuthToken`.

### P0-5 Unauthenticated evaluation HTTP routes
- **Risk:** report/data poisoning.
- **Status:** Patched.
- **Change:** added bearer token auth guard (`EVALUATION_API_TOKEN`) to `/evaluation/*` endpoints in `http.ts`.

### P1-6 Missing webhook signature validation
- **Risk:** spoofed webhook writes.
- **Status:** Patched.
- **Change:** added HMAC verification with timing-safe compare for:
  - `/webhooks/vapi`
  - `/webhooks/vapi/tool-call`
  - `/webhooks/meta`
  - `/webhooks/whatsapp`

### P1-7 Secret handling shortcut in `private/secrets.ts`
- **Risk:** false success, secret not persisted.
- **Status:** Patched (behavior hard-failed when secrets backend unavailable).
- **Change:** replaced misleading success path with explicit failure if AWS Secrets Manager env is not configured.

### P1-8 Dangerous testing surface in production path
- **Risk:** destructive test APIs accessible in prod.
- **Status:** Patched.
- **Change:** `private/toolTesting.ts` now:
  - denies in production (`NODE_ENV=production`)
  - requires org admin/platform admin checks on test operations.

### P2-9 Abuse protection baseline
- **Status:** Partially patched.
- **Change:** auth/signature gates added to high-impact endpoints.
- **Remaining:** explicit rate-limit and anomaly controls.

### P2-10 Security hygiene baseline
- **Status:** Patched (CI baseline).
- **Change:** added `.gitlab-ci.yml` with lint/typecheck/manual deploy plus secret-scan and dependency-scan jobs.

## Verification notes
- Could not run full test suite in this environment because dependency install failed due private package registry access (`xlsx` download 403).
- Next step: run `pnpm install` with valid registry credentials, then run backend tests and web typecheck, and complete the remaining authz sweep.
