Private Docs

Security Uplift — รอบ review ก่อน deploy: อะไรเปลี่ยนบ้าง แยกเป็น 3 กลุ่ม

สรุปขอบเขตจริงของ security uplift บน UserService + SupApp_util_lib (81 ไฟล์ +5,536/−177) แบ่งเป็น refactor / ของใหม่หลัง flag / เปลี่ยนพฤติกรรมทันที — review แค่กลุ่ม 3 ก็พอ พร้อม 4 ข้อที่ต้องตัดสินใจก่อน deploy

อัปเดต: 2026-08-31

เอกสารชุดนี้แยกเป็น 5 หน้า เพื่อส่งต่อให้ dev คนละเรื่องได้ 1. ภาพรวม (หน้านี้) · 2. endpoint ที่ auth เปลี่ยน · 3. ของใหม่หลัง flag · 4. เส้นทาง deploy

5. คู่มือติดตั้งใน service ของคุณ ← สำหรับ dev ที่จะเอาไปทำต่อ

ต้นทาง: Atlas/docs/security/security-uplift-meeting-plan/20260831/REVIEW_USERSERVICE_SECURITY_UPLIFT.md ตัวเลขทุกตัวรันจาก working tree วันที่ 31/08 ไม่ได้อ้างรายงานของ session

ขอบเขตจริง

90 commit ฟังดูเยอะ แต่ net diff เทียบ origin/development เท่านี้

repobranch / tipdiff
Backend_UserServicepoc/security-uplift a36f9ce81 ไฟล์ · +5,536 / −177
Backend_Packagefeature/pkg-lift-jwks-clientkeys 7456a5218 ไฟล์ · +1,524 / −10 (= 10.16.0)
Backend_SentinelGatewayServicepoc/security-uplift 78cae0d5 ไฟล์ · +95 / −3 (spike พักไว้ ยังไม่ทำงาน)

แบ่ง diff เป็น 3 กลุ่ม

กลุ่ม 1 — refactor ล้วน ไม่เปลี่ยนพฤติกรรม

  • Program.cs จัดกลุ่มใหม่
  • AddInfrastructure 630 บรรทัดในเมธอดเดียว → chain 8 บรรทัดเรียก Register* 8 กลุ่ม
  • DependencyInjection.cs 956 → 772 บรรทัด
  • CORS / at-rest cipher / JWKS ย้ายจาก UserService เข้า SupApp_util_lib

หลักฐาน: lib test fail 0 ทุก TFM (net9/net10 1514 · net8 1308 · net462 687) · UserService Failed 2 / Total 2641 ซึ่งเป็น baseline เดิม (PipelineSelfWarmTest, ProgramStartupTest fail อยู่ก่อนแล้ว) · boot จริง /health Healthy · DI error 0

ผลของการยกเข้า lib: service อื่นเรียก 4 บรรทัดจบ ไม่ต้องก๊อปโค้ด

services.AddAtRestFieldEncryption(configuration, AtRestEnabledKey);
services.AddAtRestFieldEncryption(configuration, RedisEnabledKey, RedisFieldCipherServiceKey);
services.AddAtRestFieldEncryption(configuration, StepDataEnabledKey, StepDataFieldCipherServiceKey);
services.AddJwksKeyMaterial(configuration);

กลุ่ม 2 — ของใหม่ที่อยู่หลัง flag ที่ปิดทุก env

client-signature middleware · at-rest field encryption + value converter · JWKS + /client-keys endpoint · backfill

flag ปิด = พฤติกรรมเดิมทุกประการ ตรวจหลักฐาน 3 จุดแล้วที่ หน้า 3

กลุ่ม 3 — เปลี่ยนพฤติกรรมทันที ไม่มี flag คุม

[Authorize] ที่เพิ่มเข้าไป ทำให้ 70 endpoint เดิมเปลี่ยนจาก “เรียกได้โดยไม่ login” เป็น 401

นี่คือกลุ่มเดียวที่ต้องไล่ approve ทีละบรรทัด → หน้า 2

4 ข้อที่ต้องตัดสินใจ

  1. approve/ไม่ approve การ flip 70 endpoint — โดยเฉพาะ POST /users, GET /users/{oid}/roles, /employees/* ที่อาจมี caller เป็น service อื่นไม่ใช่เบราว์เซอร์
  2. 21 endpoint ที่ไม่มี auth attribute เลย (anonymous-by-omission) — ปล่อยตามเดิม หรือปิดในรอบนี้
  3. สั่ง merge 3 PR ที่ค้าง — ถ้าไม่ merge deploy พรุ่งนี้ไม่ผ่าน ดู หน้า 4
  4. ไฟเขียว push 90 commit ของ UserService + 1 ของ lib

ยังไม่ push ยังไม่แตะ Sentinel ยังไม่รัน test phase — รอ approve