main
md 27 lines 1.48 KB
Rendered Raw
1 # Broker Security
2
3 Broker integrations are read-only in Phase 2B. The platform must not store broker usernames, passwords, OTP values, CAPTCHA answers, MFA answers, or raw access tokens in source, logs, Kafka messages, frontend bundles, or Docker images.
4
5 ## Secret Boundary
6
7 - `SecretProvider` reads secrets from the environment in DEV.
8 - `AzureKeyVaultSecretProvider` is a production boundary only and is not required for local development.
9 - `BrokerTokenStore` stores token references and session state, not broker passwords or OTP values.
10 - Token storage is intentionally abstracted so production storage can become encrypted or Key Vault backed without changing broker callers.
11
12 ## Authentication Boundary
13
14 Provider authentication can only be implemented from official provider documentation. If a provider requires OAuth, gateway software, a callback, local service, user approval, or a session refresh endpoint, the adapter must model those operational prerequisites exactly.
15
16 ## Audit Boundary
17
18 Broker operation audit logging records provider, operation, timestamp-derived duration, success or failure, correlation ID, and status code strings. It must not log request or response payloads that may contain tokens, account details, OTP values, or credentials.
19
20 ## Prohibited
21
22 - Browser automation against broker login pages.
23 - Scraping OTP, CAPTCHA, or MFA screens.
24 - Persisting raw broker credentials.
25 - Exposing auth values to frontend code.
26 - Retrying authentication aggressively.
27 - Executing trades.