Run the no-PII log audit and caps-enforcement pass #59

Closed
opened 2026-07-05 19:21:32 +01:00 by TimCane · 0 comments
TimCane commented 2026-07-05 19:21:32 +01:00 (Migrated from github.com)

Goal

Audit that logs carry ids/states only (never names/emails/image bytes) and SMTP failures log type + status only; confirm the 20 / 100 / 30-char / 1-99 caps are enforced at every surface.

References

Done when

  • Advances M7 A5.

Part of M7: Hardening.

## Goal Audit that logs carry ids/states only (never names/emails/image bytes) and SMTP failures log type + status only; confirm the 20 / 100 / 30-char / 1-99 caps are enforced at every surface. ## References - [docs/10-security-privacy.md#ephemerality-guarantees](https://github.com/TimCane/bill-splitter/blob/main/docs/10-security-privacy.md#ephemerality-guarantees) - [docs/10-security-privacy.md#session-level-nuisance-controls](https://github.com/TimCane/bill-splitter/blob/main/docs/10-security-privacy.md#session-level-nuisance-controls) ## Done when - Advances M7 A5. --- Part of **M7: Hardening**.
Sign in to join this conversation.
No description provided.