Skip to content

Broker dispatch: payload published verbatim, and the leg writes no trace step at all #2141

Description

@rjzondervan

Surfaced by the security re-review of #1983 (review 5289004003), re-verified at 85e5de84. Two related observations about the same leg.

1. The payload goes to the broker verbatim

EventService.php (~:1804):

$messageData = $message->getObject();
$cloudEvent  = ($messageData['payload'] ?? []);
...
$result = $transport->publish(
    publication: $this->brokerPublication(cloudEvent: $cloudEvent, ...),
    configuration: $this->brokerSettings(subscriptionData: $subscriptionData)
);

No bound, no redaction, no declared shape. For a Dutch government product a CloudEvent data block can carry a BSN.

To be fair to the design: delivering the payload is the point of a broker, so redacting the delivered body would break the feature. This is a data-minimisation and documentation gap, not a leak — but it is one that should be answered deliberately rather than by default. Either:

  • bound what may appear in data for broker-dispatched subscriptions, or
  • document the position explicitly — "the broker is a trusted processor, the operator is responsible for what they subscribe" — somewhere an implementer will find it.

2. The broker leg writes no trace at all

Checked while verifying the above: the only addStep in EventService is at :629, on the webhook/call leg, and that one already redacts both input and output through SensitiveFieldRegistry (:615, :622).

The broker leg records none. It calls recordConfigurationError() and logs on throw, but a successful broker dispatch leaves no trace step.

So the asymmetry is not "webhook redacts, broker leaks" — it is "webhook is auditable, broker is not". For a government product that is its own problem: a dispatch that delivered personal data to an external system with no trace entry cannot be answered for afterwards.

  • Record a trace step for broker dispatch, redacted the same way the call leg is.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

triageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions