Lewati ke isi

T0-E1 independent verdict

Verdict

E1-C — T0-E1 FAILED — MATERIAL SECURITY REGRESSION OR FALSE-GREEN REMAINS

T0-E1 does not independently close the targeted set. T0F-001, T0F-005, T0F-006, T0F-007, T0F-008, T0F-015 and T0F-003 remain S0. T0F-009 is only partially fixed; T0F-014 remains open. T0F-002 and T0F-013 are the only targeted findings independently closed. T0F-004 is only partially fixed because the enabled-entitlement and alternate-RPC proof is incomplete.

Final adversarial answers

  1. Yes. Inactive platform role/group membership widens authority; live cross-tenant reset succeeded.
  2. Mutation: denied in the tested dataset path. However must-change/read authority still bypasses through /web/dataset.
  3. Yes. Native res.partner.search_read returned a real GT-T2 partner to a GT-T1 actor; Scola student API alone was narrower.
  4. API probes: denied. Full closure is not proven for enabled entitlements or alternate RPC/model paths; answer is not safely “no”.
  5. Yes. GT-T1 active school-admin session with inactive platform role reset GT-T2 credentials through canonical reset scope bypass.
  6. Yes. School-unit admin creation accepts admin_password; student/parent generation returns plaintext credentials; provisioning/demo defaults remain.
  7. Yes. /api is gated, but normal /web/dataset reads are allowed while must-change is set.
  8. Yes. Reset form is blocked, but native signup remains enabled/reachable with a valid signup token path.
  9. One success only in the independent concurrent consume test; issuance race remains untested and unprotected.
  10. Yes, by code. Session store unavailable returns zero and audit persistence exceptions are swallowed; no failure-injection proof exists.
  11. No for the tested public-prefix child. Exact child matching now protected /api/SPMB/registers/list; route checker/CI passed.
  12. Yes. The default validator cannot run without a manifest, does not inspect required case completeness or served BE identity, and mutation tests do not cover those omissions.
  13. Yes. The inactive platform group fallback is a new/remaining authorization bypass exposed by the E1 conflict test.
  14. No. Served FE/BE SHAs are known, but no E1 runtime manifest binds them to the 19-case evidence, database/module state, and served backend identity.

Scope note

This verdict does not declare full T0 closed and does not assess T0F-010, T0F-011, or T0F-012. Those remain intentionally open for T0-E2. W01/W02/W05, T1, and optional business workflow certification are outside this verification.