elsa-core/specs/013-user-tasks/checklists/security.md
Sipke Schoorstra ffff359756
feat(user-tasks): add identity-neutral workflow-bound human tasks (#7955)
Adds durable, identity-neutral, workflow-bound human tasks, and reconciles the
REST surface with the approved Studio contract.

- Flat summary/detail DTOs, a global capability descriptor, and workflow context
  captured at activation.
- Scope is part of the list authorization predicate; manager decisions require
  manage:user-tasks; a denied command answers 404 so it cannot prove a task exists.
- Guest sessions are task-scoped, action-allowlisted, and revoked when the task
  closes. Invitations resolve by token hash through the repository, wait in a
  Data Protection encrypted outbox, and are rate limited per caller.
- Masked form values are disclosed only through an audited reveal command.
- Store-specific concurrency failures are translated into a single
  UserTaskRevisionConflictException, so a concurrent edit returns the documented
  revision-conflict result behind any provider instead of a 500.

EF Core (SQLite, SQL Server, PostgreSQL, MySQL, Oracle) and VNext persistence,
hosted due/reconciliation/delivery workers, docs, and 49 tests.

Note: this branch also carries two commits inherited from its branch point that
are not part of User Tasks and are squashed in here — the revert-version
allocation change from #7917 (WorkflowDefinitionPublisher.RevertVersionAsync now
allocates from the last version rather than the latest) and an NU1903 package
pin. Merged deliberately rather than rebased out.
2026-08-25 00:09:06 +02:00

924 B

Security Checklist

  • SEC001 Authentication is host-owned and identity storage is decoupled.
  • SEC002 Permission and task-relationship checks are both required.
  • SEC003 Tenant scope is part of participant identity and every query boundary.
  • SEC004 Candidate, released-user, terminal-history, and manager disclosure rules are specified.
  • SEC005 Exclusions and manager override reason/audit behavior are specified.
  • SEC006 Protected payloads are bounded, excluded from search/audit, and purged consistently.
  • SEC007 Invitation secrets are hashed, delivery retry material is encrypted and transient, and anonymous errors are generic/rate-limited.
  • SEC008 Guest sessions are task-scoped, revocable, capability-limited, and bounded.
  • SEC009 Mutation concurrency, operation idempotency, and terminal races are specified.
  • SEC010 List authorization prevents row and count leakage.