Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md); WO-44..49 added 2026-09-08 from the source-verified review v1.1 (docs/reports/MIZOKI_ACQUISITION_ECONOMICS_REVIEW_v1.1_2026-09-06.md, verified on main 635318712). Findings are hypotheses until reproduced on current main (WO-00).

Finding (confirmed on main 635318712; OPEN_ITEMS S3-4): services/service-decision-control-plane/main.py:504-508 get_decision returns any DecisionProof by id to any allow-listed caller — STORE.get("decision_proofs", decision_id) with no resolve_tenant call, while the sibling list_decisions (line 526) and decisions_summary (549) do resolve tenant against the caller. mcp-server checks the stored tenant_id itself, but the upstream route must too; passport assembly (S3-3) reads through this route. Files: services/service-decision-control-plane/main.py; its tests. Fix: resolve the caller's tenant and refuse (404, never 403 that confirms existence) when doc["tenant_id"] does not match; same rule on /decision/{id}/chain and the passport GET. Pairs with WO-03 (passport binding) and WO-05 (approver identity). Acceptance: negative test over HTTP: tenant B caller requesting tenant A's decision id gets 404 and no body fields; positive test unchanged; the same test against /chain and /passport/{id}. Depends on: WO-00. Owning prompt: CC-1 (services/service-decision-control-plane/**).

← All docsView source on GitHub →