T0-E1.2 Self-Audit — Gap Closure Review (historical)¶
| Item | Value |
|---|---|
| Mode | Server /home/scola/odoo |
| Nature | Implementation self-audit (not independent audit) |
| When | After first E1.2 freeze claim was found over-broad |
| Current superseding freeze | T0-E1.2-20260809T221606Z / BE a44b5d26… — see T0-E1.2-result.md |
Why this file exists¶
An earlier claim of T0-E1.2 IMPLEMENTATION COMPLETE was withdrawn because:
- Exit gate #2 (authority-capable fallbacks) was not met — HIGH
group_scola_admin/ fees_role_codeswideners remained after inventory-only Phase 2. - Live probe: active
teachersuccessfullyPOST /api/v1/calendar/admin/events/save. - T0F-015 evidence only covered one
res.partner.search_readby id.
Closure that followed¶
| Gap | Fix |
|---|---|
| Authority wideners | scola_core/services/active_role_authz.py + strip product group_scola_admin AUTHORIZATION ORs; fees active-role-only; calendar/portal/CBT/LMS/student_activity/report_card/HR proxy hardened |
| T0F-001 residual | Finding obs: teacher + admin group → calendar save access_denied |
| T0F-015 depth | search_read + name_search + res.users + relation read all denied/filtered |
| Re-freeze | Run T0-E1.2-20260809T221606Z — 29/29, validator PASS |
Current label¶
T0-E1.2 IMPLEMENTATION COMPLETE — PENDING INDEPENDENT AUDIT
Do not declare T0 closed. Do not treat this self-audit as independent closure.