Skip to content

[codex] Calibrate AdministratorAccess admin reachability#74

Merged
InfoSecHack merged 1 commit into
mainfrom
codex/admin-reachability-adminaccess-clean-witness
Jun 6, 2026
Merged

[codex] Calibrate AdministratorAccess admin reachability#74
InfoSecHack merged 1 commit into
mainfrom
codex/admin-reachability-adminaccess-clean-witness

Conversation

@InfoSecHack

Copy link
Copy Markdown
Owner

Summary: Treat exact AWS-managed AdministratorAccess as a clean admin-equivalence witness only when witness metadata is unambiguous; keep custom, spoofed, conditioned, and ambiguous wildcard admin-like policies conservative; add focused admin_reachability regressions, adjust one pipeline-shaped deny fixture, and refresh affected golden finding text. Validation: focused affected pytest suite 140 passed; scripts/check.sh passed; scripts/test_fast.sh 2059 passed; git diff --check passed; account/ARN hygiene scans clean; Terraform/raw artifact scan clean.

@InfoSecHack InfoSecHack marked this pull request as ready for review June 6, 2026 06:27
@InfoSecHack InfoSecHack merged commit dbc8241 into main Jun 6, 2026
6 checks passed
@InfoSecHack InfoSecHack deleted the codex/admin-reachability-adminaccess-clean-witness branch June 6, 2026 06:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant