# reinhardt-admin Security Policy
## System and Scope
This policy inherits the repository [Security Policy](../../SECURITY.md) and
the framework-crate [Security Policy](../SECURITY.md). Policies compose from
the repository root to this crate; this closest policy wins on conflict.
`reinhardt-admin` serves a privileged administrative UI and its server
functions, generated clients, static assets, import/export facilities, and
WASM SPA. Admin routes, form values, record identifiers, files, and browser
state are attacker-controlled until the server validates them.
## Security Invariants
- Every privileged read, mutation, bulk action, import, export, and custom
action enforces server-side model and operation permission. Applications
requiring object or tenant isolation provide object filters through
`ModelAdmin`; detail and mutation queries combine those filters with the
record identifier in one database predicate. Missing filters fail closed for
non-superusers. Client, WASM, and generated-client state is display state only.
- Admin detail and list responses project row maps through the selected
`ModelAdmin::fields` and `list_display` policy before serialization.
- List response row identifiers are carried separately in `object_ids` solely
as routing metadata for authorized detail and mutation operations; they are
never added to the projected row map unless explicitly listed.
Exports require the same explicit field policy before returning records.
- Cookie-authenticated mutations preserve CSRF protection. Security-sensitive
identifiers, ownership, tenant, role, permission, credential, and read-only
fields cannot be changed through forms, inline edits, or alternate requests
unless the server explicitly authorizes that operation.
- Import and export validate formats and data, bound work, preserve the
caller's authorized scope, and must neutralize spreadsheet formula prefixes
before CSV/TSV values are opened by spreadsheet software. Protected
applications must also apply the selected `ModelAdmin` field allowlist,
read-only, ownership, and tenant checks to every imported record. The
server-function import path applies the same create-field validation and
sanitization to each record before insertion. It deserializes its complete
request body before calling `import_data`, so its file-size check does not
bound request-body buffering or JSON parsing; callers must enforce a body
limit before server-function deserialization. `CsvExporter` and `TsvExporter`
forward cell text without formula neutralization; RFC 4180 quoting and TSV
delimiter escaping alone do not prevent formula interpretation. Rendered
values use context-appropriate escaping.
- Static, uploaded, generated, and vendor asset paths remain confined to their
configured asset roots. Deployments enabling remote executable or render-
active vendor assets must provide verified integrity values before download
or serving; an empty integrity value is an explicitly unverified bootstrap,
not a trusted update.
- Native, WASM, generated-client, and direct server-function paths enforce
equivalent permissions and never let a client-side route or UI check replace
server authorization.
## Reportable Findings
Report admin authorization or CSRF bypass, protected-field mass assignment,
unsafe import/export or rendered values, asset confinement escape, unverified
remote active vendor assets, or weaker native/WASM/generated-client behavior.