Skip to content

Identity data: an admin reading a KYC record or a partner profile is audit-logged, as opening the ID document already is (D612) #1312

Description

@guillaumelauzier

S1: Reading a member's KYC record is not logged, though opening their ID document is. Decision D612. No migration. Found by #1165's audit (area 7, kycAdminGet and adminGetProfile).

What is true on main

  • Opening the ID document is logged. GET /api/kyc/admin/:userId/document writes kyc_document_access to activity_logs on every view (cloudflare-worker/src/routes/kyc.ts), with the actor hashed.
  • Reading the record is not. GET /api/kyc/admin/:userId returns the record and logs nothing. The record holds legal name, date of birth, nationality, address, ID type and number, and phone.
  • The queue. The admin KYC queue (/admin?tab=kyc) reads rows that already carry the same kyc_data. Check whether that read is logged.
  • Partner profiles. GET /api/profiling/admin/:email (routes/profiling.ts) returns a partner profile's EIN and onboarding transcript, unlogged.

The work

  1. Log each read of identity data the way kyc_document_access is logged: the actor hashed with hashEmail, the member's id, and no field values. The actions:
    • kyc_record_access, for the record;
    • kyc_queue_access, for a queue read: one row per read, with the count, not one per member;
    • partner_profile_access, for the profile read.
  2. Trim the queue. If the queue's rows carry full kyc_data only to fill the review window, return them without the identity fields, and let the window read the record (now logged). Say in D612 which you did and why.
  3. D612 records what is logged, that values never reach the log, and the queue change.

Files this task owns

  • cloudflare-worker/src/routes/kyc.ts
  • cloudflare-worker/src/routes/profiling.ts (the admin read only)
  • the KYC review window in frontend/src/pages/AdminPage.jsx, only if step 2 changes what it reads
  • new tests
  • documentation/architecture/decisions/D612.md

Do not build masking in the review windows. Its design is requested on #1165 (area 7, item 6).

Done when

  • Tests cover:
    • each read writes one log row, with the actor hashed and no identity value in details;
    • a 404 logs nothing;
    • the queue's shape after step 2.
  • Every new assertion is mutation-checked.

Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    slot:S16Work queue of slot S16state:readyReady for its slot to claim

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions