Lanes
One lane at a time — the goal, the critical path, and the current wave of blockers.
Approve: Security & SecretsTo do · blockerNEEDS MATTHEW: audit every SECURITY DEFINER function for the PUBLIC execute grantTo do · blockerPer-account rate limiting on write endpointsDoneRate limit auth endpointsDoneAgent-run pre-launch security auditTo doRotate all credentials at production cut-overTo doEncrypt card connector tokens — currently plaintextTo doMake the cookie banner actually gate non-essential storageDoneNEEDS MATTHEW NOW: anon can delete any account — one REVOKE closes itDoneNEEDS MATTHEW: v_account_tier leaks the full customer roster to anon — confirmed liveDoneAdd in-product Report link on the public destination viewerTo doContact PATCH was wiping every card field — fixed, PR #164DoneNEEDS MATTHEW: GitHub Actions billing wall — all CI is blockedDoneEnable Supabase leaked-password protectionTo doPublish security.txt (vulnerability disclosure)DoneConfirm sandbox flag unset in productionDoneAdd CORS middleware to tactile-apiDoneAdd CSP header on web responsesDoneAdd HSTS headerDoneSAST scanning in CIDoneCookie consent bannerDoneAudit log table for sensitive opsDoneAdd abuse-report endpointDoneDocument secrets inventoryTo doDependency scanning in CIDoneAgent-harness escape strings were shipping in page source — stripped, PR #167Done
Wave
Security & Secrets
v1.0 security hardening + secrets discipline. Agent-run security audit before production cut-over (no third-party pen test for v1.0).
TacTile › Launch TacTile › Foundations › Security & Secrets
18/26 done8 open2 open blockers
Selected taskclear
Approve: Security & Secrets
To doOwner · met_0383f11cBlocker
Matthew's final sign-off gate for security.
Waiting on 18 · 6 still openAdd CORS middleware to tactile-apiAdd CSP header on web responsesAdd HSTS headerSAST scanning in CIPer-account rate limiting on write endpointsRate limit auth endpointsCookie consent bannerAudit log table for sensitive opsAdd abuse-report endpointDocument secrets inventoryDependency scanning in CIEnable Supabase leaked-password protectionPublish security.txt (vulnerability disclosure)Confirm sandbox flag unset in productionAgent-run pre-launch security auditRotate all credentials at production cut-overEncrypt card connector tokens — currently plaintextAdd in-product Report link on the public destination viewer
Show the prompt
To doIn progressDoneBlockedPick a wave on the left · tap a task to expand it