Skip to content

fix(security): secure recovery authorization and deployment defaults - #270

Merged
pranavjain97 merged 5 commits into
masterfrom
wcn-1929-secure-recovery-compose
Sep 29, 2026
Merged

pranavjain97 merged 5 commits into
masterfrom
wcn-1929-secure-recovery-compose

Conversation

@ralph-bitgo

@ralph-bitgo ralph-bitgo Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

What

  • Harden the reference Compose deployment with mTLS, private networking, no published service ports, recovery disabled by default, and isolated credential mounts.
  • Require explicit X-Recovery-Token authorization for recovery routes on both MBE and AWM, independent of transport authentication.
  • Validate recovery configuration at startup and forward the configured authorization token across recovery signing calls.
  • Enforce the recovery-mode boundary for MPCv2 recovery before it performs coin or KMS work.
  • Centralize disabled-recovery enforcement in shared middleware for all recovery APIs.
  • Add local certificate bootstrap, credential build-context exclusions, recovery documentation, and regression coverage.

Why

Recovery endpoints perform signing operations and were previously reachable under unsafe network and authentication defaults. This change makes the reference deployment secure by default and requires explicit operator authorization whenever recovery is enabled. It also restores the recovery-mode gate for MPCv2 recovery before it reaches coin or KMS operations.

Tickets: WCN-1929, WCN-1931

@ralph-bitgo
ralph-bitgo Bot force-pushed the wcn-1929-secure-recovery-compose branch from d020565 to 6163b8d Compare September 24, 2026 15:18
@linear-code

linear-code Bot commented Sep 24, 2026

Copy link
Copy Markdown

WCN-1929

Require a recovery token on both services and reject unsafe non-local
HTTP recovery. Switch the reference compose to private mTLS links with
a certificate bootstrap so deployments cannot expose signed sweeps.

Ticket: WCN-1929
Session-Id: b6e61b98-333e-49ec-81c7-f5dc6d5ab18f
Task-Id: f204d240-69cb-41c8-b61d-680a4cb321ba
Keep generated deployment credentials out of Docker build layers,
verify rejected requests never reach the KMS, and authenticate split
recovery fixtures so the security guard covers every route.

Ticket: WCN-1929
Session-Id: b6e61b98-333e-49ec-81c7-f5dc6d5ab18f
Task-Id: f204d240-69cb-41c8-b61d-680a4cb321ba
@ralph-bitgo
ralph-bitgo Bot force-pushed the wcn-1929-secure-recovery-compose branch from 6163b8d to 4849d1a Compare September 24, 2026 15:20
@ralph-bitgo ralph-bitgo Bot changed the title fix(recovery): secure reference deployment and require recovery authorization fix(mbe): require recovery authorization and secure compose defaults Sep 24, 2026
@ralph-bitgo
ralph-bitgo Bot force-pushed the wcn-1929-secure-recovery-compose branch from 4849d1a to 6a1eab4 Compare September 24, 2026 15:21
@pranavjain97 pranavjain97 changed the title fix(mbe): require recovery authorization and secure compose defaults fix(security): secure recovery authorization and deployment defaults Sep 24, 2026
@pranavjain97
pranavjain97 marked this pull request as ready for review September 24, 2026 16:49
@pranavjain97
pranavjain97 requested review from a team as code owners September 24, 2026 16:49
s84krish
s84krish previously approved these changes Sep 25, 2026
Comment thread src/masterBitgoExpress/clients/advancedWalletManagerClient.ts
@pranavjain97
pranavjain97 merged commit c300b8a into master Sep 29, 2026
23 checks passed
@pranavjain97
pranavjain97 deleted the wcn-1929-secure-recovery-compose branch September 29, 2026 20:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants