Skip to main content

MAZENG-FT-56 · Isolated Terraform workspace ingestion and cleanup

Feature intent

CLI users need to upload a bounded Terraform workspace without allowing one user's paths or cleanup actions to affect another workspace or the server.

Why it matters

CLI users need to upload a bounded Terraform workspace without allowing one user's paths or cleanup actions to affect another workspace or the server.

Expected outcome

Terraform files retain intended structure inside an owner-isolated workspace with safe, idempotent cleanup.

In scope

  • Validation of supported files, counts, sizes, and normalized relative paths.
  • Isolation by authenticated user and opaque server workspace ID.
  • Ownership-checked, idempotent cleanup through a mutating HTTP method.
Delivery status
IN_BACKLOG
Owner
RootAtSkic (product lead)
Parent Epic
MAZENG-EP-15
Solution approval
PENDING

Acceptance

Acceptance outcomes

  1. 01

    Supported files, counts, sizes, and normalized relative paths are validated before storage.

  2. 02

    Every workspace is isolated by authenticated user and opaque server ID.

  3. 03

    Cleanup is idempotent, ownership-checked, and uses an appropriate mutating HTTP method.

  4. 04

    Traversal and out-of-workspace access are rejected.

Dependencies and risks

Dependencies

None recorded.

Risks

  • Legacy trusts caller-provided original paths and joins them beneath a shared temporary directory.
  • Legacy exposes recursive deletion through GET with attacker-controlled path input.
  • Extension checks do not prevent traversal or malicious Terraform content.

Authoritative Architecture tasks

No authoritative Architecture tasks are linked.

Original source