Skip to content

fix(security): sanitize observability endpoints and enforce content-free contract (#1051) - #1079

Merged
sbharatjoshi merged 2 commits into
mainfrom
feat/1051-content-free-observability
Oct 9, 2026
Merged

sbharatjoshi merged 2 commits into
mainfrom
feat/1051-content-free-observability

Conversation

@forgespectrayan

Copy link
Copy Markdown
Collaborator

Summary

Fixes #1051. Enforces the content-free contract for all observability, system telemetry, and admin-reachable endpoints per ADR-0083. Under no circumstances should memory content (text, label, tags, raw vector, or unvetted metadata) be retrievable via observability or admin routes.

Changes

  • Observability Timeline (/api/v1/observability/timeline):
    • Replaced ad-hoc Map<String, Object> response with typed TimelineResponse / TimelineEventDto.
    • Removed text and metadata from timeline events (retaining only cognitive identifiers: memoryId, namespace, timestamp, tier, importance, valence, recallCount).
  • Traced Recall (/api/v1/observability/traced-recall):
    • Replaced ad-hoc response with typed TracedRecallResponse / TracedRecallItemDto.
    • Stripped memory text from candidate trace entries; exposed only candidate ID, cognitive metrics, and algorithmic ScoreBreakdownDto.
  • Vector Space 3D Projection:
    • Removed label field from ProjectedPoint record in nucleus/spector-events (EmbeddingProjectionTelemetry.java).
    • Removed memory text population from VectorSpaceProjectionService.java in both PCA and deterministic layout projections.
    • Updated Cortex Angular UI (cortex-events.ts, vector-space.component.ts) to remove label and display point ID.
    • Updated docs/openapi.yaml removing label from ProjectedPoint.
  • Architectural & Integration Testing (ContentFreeObservabilityContractTest.java):
    • Added ArchUnit bytecode structural rules ensuring DTOs in com.spectrayan.spector.synapse.observability.dto and ProjectedPoint never declare content fields (text, content, payload, vector, label, metadata, tags).
    • Added ArchUnit rule ensuring observability controller public methods do not expose content-bearing domain models (CognitiveRecord, CognitiveResult).
    • Added canary integration contract tests verifying canary text and tags are strictly rejected from all observability payloads (/timeline, /traced-recall, /stats, /metrics/live, /age-distribution, /memory/vector-space/projection).

Verification

  • mvn test -pl synapse/spector-synapse -Dtest=ContentFreeObservabilityContractTest (9/9 passed)
  • mvn test -pl synapse/spector-synapse -Dtest=ConfigAndObservabilityTest,VectorSpaceProjectionServiceTest (11/11 passed)
  • mvn test -pl nucleus/spector-events (44/44 passed)
  • mvn license:check (100% compliant across all 29 modules)

— Forge (Maintainer)

…ree contract (#1051)

- Remove memory text and raw metadata from /api/v1/observability/timeline
- Remove memory text from /api/v1/observability/traced-recall
- Strip label from ProjectedPoint in EmbeddingProjectionTelemetry, VectorSpaceProjectionService, and OpenAPI spec
- Introduce strongly-typed content-free DTOs in com.spectrayan.spector.synapse.observability.dto
- Add ArchUnit bytecode rules and canary content integration tests in ContentFreeObservabilityContractTest

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@forgespectrayan
forgespectrayan requested review from a team as code owners October 8, 2026 23:02
)

- In pushEmbeddingProjection, map ProjectedPointDto id to point label after label property removal from DTO
- Fixes Angular build failure in CI

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@sbharatjoshi
sbharatjoshi merged commit 082db81 into main Oct 9, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(security): /observability/timeline returns memory text; audit admin-reachable DTOs for content

2 participants