Menu ▾ ▴

#34 fix(security+design): connector hardening, TLS, secret enforcement, =EPM client parity (#23–#31)

closed
nobody
None
2026-06-19
2026-06-12
Anonymous
No

Originally created by: pyy3

Fixes the konsolidat security + design findings raised in review (#23–#31).

Security / infra

  • #23 dbt profiles.yml: env-driven TLS (CLICKHOUSE_SECURE/VERIFY) + a prod target that defaults to secure; dev stays plaintext loopback.
  • #24 docker-compose.yml: weak :- password defaults → required :? vars (ADMIN / DB_ROOT / CLICKHOUSE); ClickHouse ports bound to loopback by default (CLICKHOUSE_BIND); deploy.sh no longer echoes the admin password to stdout (it's already saved to a chmod-600 .credentials). .env.example updated.
  • #25 security-architecture.md: reconcile the isolation claims with what the bundled compose actually ships (new Deployment profiles section) + add a source-connector security section.
  • #26 D365 connector: incremental $filter cursor rendered via odata_filter_literal so a tampered state value can't inject OData syntax.
  • #27 connector auth: generic check_connection messages (pure auth_error_message); raw server body only at debug level.

Connector design

  • #30 retry 429/5xx with Retry-After-aware backoff.
  • #31 cross_company is configurable (spec.yaml, default true).
  • spec.yaml: mark tenant_id / client_id airbyte_secret (defence in depth).

=EPM client + semantic layer

  • #28 fixed a real taskpane.js ↔ epm_batch contract drift (it wrapped the body in {queries}, used fiscal_year, and read message as an array). Now: bare array, year key, reads message.values. Added docs/reference/epm-formula-protocol.md (contract SoT) + tests/test_epm_client_parity.py.
  • #29 Cube retained as the core read-scaling layer (needed for the 50–500 user target). Added docs/reference/semantic-layer.md; updated the stale "remove-cube" tests to assert the intended architecture.

Tests

Connector unit tests: 43 passed (28 baseline + 15 new, no monkeypatching). Root doc/cleanup/parity: 24 passed (the 4 pre-existing cube-removal failures are now resolved per the keep-Cube decision).

Note: opened from a fork by an account with read-only access to grynn-in. The Office.js add-in change is contract-aligned but not runtime-tested (no Excel in the environment).

🤖 Generated with Claude Code


Closes [#23]. Closes [#24]. Closes [#25]. Closes [#26]. Closes [#27]. Closes [#29]. Closes [#30]. Closes [#31].

Related

Tickets: #23
Tickets: #24
Tickets: #25
Tickets: #26
Tickets: #27
Tickets: #29
Tickets: #30
Tickets: #31
Tickets: #35

Discussion

  • Anonymous

    Anonymous - 2026-06-12

    Originally posted by: pyy3

    Update (self-review): Restructured into two commits so the runtime-untested change is isolated:

    • 24b39d9 — security + design + docs (#23–#27, [#29]–#31, [#28] docs). Fully tested here (connector 43, root 22). Independently green — verified at this commit with taskpane.js untouched.
    • 4f08662 — the taskpane.js epm_batch contract fix + parity test (#28). The only change that couldn't be exercised without Excel — please smoke-test the add-in's budget refresh before merging this commit.

    Also fixed during review: profiles.yml TLS now uses literal-boolean dev/prod targets (the earlier Jinja == 'true' rendered to the string "False", which dbt-clickhouse would treat as truthy).

     

    Related

    Tickets: #28
    Tickets: #29

  • Anonymous

    Anonymous - 2026-06-12

    Originally posted by: pyy3

    Split update: [#28] (the =EPM() Office.js client fix + protocol doc + parity test) has been moved to its own PR [#35] — it's the one change that needs an Excel smoke-test. This PR (#34) no longer touches taskpane.js and is fully tested here (connector 43 + root 22). The two PRs are independent (no shared files).

     

    Related

    Tickets: #28
    Tickets: #35

  • Anonymous

    Anonymous - 2026-06-12

    Ticket changed by: grynn-in

    • status: open --> closed
     

Log in to post a comment.