T0-E1 independent verdict¶
Verdict¶
E1-C — T0-E1 FAILED — MATERIAL SECURITY REGRESSION OR FALSE-GREEN REMAINS
T0-E1 does not independently close the targeted set. T0F-001, T0F-005, T0F-006, T0F-007, T0F-008, T0F-015 and T0F-003 remain S0. T0F-009 is only partially fixed; T0F-014 remains open. T0F-002 and T0F-013 are the only targeted findings independently closed. T0F-004 is only partially fixed because the enabled-entitlement and alternate-RPC proof is incomplete.
Final adversarial answers¶
- Yes. Inactive platform role/group membership widens authority; live cross-tenant reset succeeded.
- Mutation: denied in the tested dataset path. However must-change/read authority still bypasses through
/web/dataset. - Yes. Native
res.partner.search_readreturned a real GT-T2 partner to a GT-T1 actor; Scola student API alone was narrower. - API probes: denied. Full closure is not proven for enabled entitlements or alternate RPC/model paths; answer is not safely “no”.
- Yes. GT-T1 active school-admin session with inactive platform role reset GT-T2 credentials through canonical reset scope bypass.
- Yes. School-unit admin creation accepts
admin_password; student/parent generation returns plaintext credentials; provisioning/demo defaults remain. - Yes.
/apiis gated, but normal/web/datasetreads are allowed while must-change is set. - Yes. Reset form is blocked, but native signup remains enabled/reachable with a valid signup token path.
- One success only in the independent concurrent consume test; issuance race remains untested and unprotected.
- Yes, by code. Session store unavailable returns zero and audit persistence exceptions are swallowed; no failure-injection proof exists.
- No for the tested public-prefix child. Exact child matching now protected
/api/SPMB/registers/list; route checker/CI passed. - Yes. The default validator cannot run without a manifest, does not inspect required case completeness or served BE identity, and mutation tests do not cover those omissions.
- Yes. The inactive platform group fallback is a new/remaining authorization bypass exposed by the E1 conflict test.
- No. Served FE/BE SHAs are known, but no E1 runtime manifest binds them to the 19-case evidence, database/module state, and served backend identity.
Scope note¶
This verdict does not declare full T0 closed and does not assess T0F-010, T0F-011, or T0F-012. Those remain intentionally open for T0-E2. W01/W02/W05, T1, and optional business workflow certification are outside this verification.