Files
document-haness/docs/clean-architecture-backend-template/tech-log-studio/security-policy-enforcement/case/case-messaging-admin-runtime-f08.md
T
DongHyeonkaandClaude Fable 5.1 b25357c48a docs(clean-architecture-backend-template): fold analysis into final and re-select one topic
- analysis/·source-index·state.json 을 final/document.md 제2부·제3부로 접었다. SSOT 는 하나다
- 파일럿 — commit-ambiguity-as-a-result 를 새 기준으로 재선별. 후보 14 → 글감 5
  (PROMOTE 5 · MERGE_INTO 3 · KEEP_IN_SSOT 4 · 보류 2). 기록 5건을 다시 썼고 그림 1개를
  techviz 로 만들었다
- 재선별이 잡은 것: 제1부 §6.2·§11.1 이 자기 §13.2 와 어긋나 있었다(레인을 안 돌렸다 vs
  돌렸다) — 정정. 이미 답이 나와 있던 Question 을 HEAD 재실행 질문으로 다시 세웠다.
  Concept 이 인용한 코드가 SSOT 에 없어 뺐다
- candidateScope·sourceRepository 기록. 나머지 43개 주제는 재선별 대기(PENDING 905)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-07 12:39:20 +09:00

2.8 KiB

kind, slug, title, topic, project, status, sourceRevision, rootTreeNode, evidenceCapturedOn, assets, evidence, source, module, priority
kind slug title topic project status sourceRevision rootTreeNode evidenceCapturedOn assets evidence source module priority
CASE messaging-admin-runtime-f08 격리 리플레이의 guard 우회가 dryRun 파라미터로 표현된다 security-policy-enforcement clean-architecture-backend-template 게시 전 21234e38cdb9a926cbc92bb97a2aee2e4a7d2916 case:messaging-admin-runtime-f08 2026-09-01
key file
messaging-admin-runtime-f08 ../../../final/evidence/rendered/messaging-admin-runtime-f08.svg
../../../final/evidence/raw/messaging-admin-runtime-f08.txt
원본 분석 절은 final/document.md#a19-messaging-admin-runtime#L948 이다.
messaging-admin-runtime P3

격리 리플레이의 guard 우회가 dryRun 파라미터로 표현된다

판단 자체는 근거가 있다. 다만 "승인이 필요 없다" 와 "실제로는 아무것도 하지 않는다" 가 guard 입장에서 구별되지 않는다.

문제

판단 자체는 근거가 있다.

다만 "승인이 필요 없다" 와 "실제로는 아무것도 하지 않는다" 가 guard 입장에서 구별되지 않는다.

결론

DestructiveOperationGuard 에 skipAuthorization 성격의 별도 경로를 두거나, 격리 리플레이는 애초에 guard 를 거치지 않는 편이 의도를 드러낸다.

검증 환경

OpenJDK : 21.0.12 java -version 으로 확인 Gradle : 9.0.0 src/gradle/wrapper/gradle-wrapper.properties 의 distributionUrl 로 확인 확인 방식 : DestructiveOperationGuard 참조 19건 검색과 guard 에 넘어가는 인자의 의미 대조 소스 수정 : x

재현 조건

원문은 final/document.md#a19-messaging-admin-runtime#L948 에 있다.

본문

guard 호출이 두 뜻을 한 인자로 합친다.

// ReplayService.java:58-64
guard.authorize(REPLAY, request.destination(), approval, request.dryRun() || !needsApproval, now);

DestructiveOperationGuard 참조 위치

:::evidence key="messaging-admin-runtime-f08" alt="코드베이스에서 DestructiveOperationGuard 를 검색한 출력 19줄. 이 기록이 세는 참조가 그 출력에 그대로 보인다." caption="DestructiveOperationGuard 코드베이스 검색 — 19줄 · exit 0" zoom="true" :::

판단 자체는 근거가 있다

다만 "승인이 필요 없다" 와 "실제로는 아무것도 하지 않는다" 가 guard 입장에서 구별되지 않는다. DestructiveOperationGuardskipAuthorization 성격의 별도 경로를 두거나, 격리 리플레이는 애초에 guard 를 거치지 않는 편이 의도를 드러낸다.

확인하지 못한 것

guard 를 실제로 호출해 두 경우가 구별되지 않는 것을 관측하지 않았다. 인자 하나가 두 뜻을 겸한다는 호출 형태로 판정했다.