Project accepted visual-recon evidence through canonical StarIntel outbox #29

Closed
opened 2026-09-02 17:24:35 +00:00 by nsaspy · 0 comments
Owner

Outcome

Add only the Hackmode-side cyber-evidence projection needed for accepted screenshot/visual-recon records from #142 to reach StarIntel through the existing canonical outbox/API boundary.

Owning RAGE lane

Hackmode integration/database boundary as appropriate after #142; not StarIntel product development.

Fence

Do not redesign StarIntel runtime/storage/UI/actors. Do not write StarIntel directly from BrowserWorker. Do not treat publish as acceptance. Hackmode remains local-first and the existing durable outbox/ack semantics remain authoritative.

Dependencies

  • #140 visual recon epic
  • #142 canonical screenshot evidence persistence
  • existing Hackmode StarIntel projection/outbox contract

Projection

Map only accepted typed cyber evidence: operation/asset identity, screenshot evidence reference/digest, title/final URL/status, timing/profile/browser provenance, relevant HTTP exchange/capture references, and stable observation identity. Secret-bearing raw bodies/headers remain local evidence refs unless explicitly authorized by existing policy.

Required behavior

  • deterministic remote logical identity;
  • offline operation continues locally;
  • outage keeps projection durable in outbox;
  • retry/reconnect is idempotent;
  • acceptance/ack determines completion, not mere Rabbit/HTTP publish;
  • no duplicate logical screenshot findings/evidence on replay.

RED-first tests

Fake StarIntel sink for outage/reconnect, duplicate retry, acceptance failure, provenance retention, and secret non-projection.

Acceptance proof

Persist one canonical screenshot observation locally with StarIntel unavailable, prove it remains usable and queued, reconnect a fake canonical sink, accept it exactly once, and retain provenance back to the local visual and HTTP/capture evidence.

## Outcome Add only the Hackmode-side cyber-evidence projection needed for accepted screenshot/visual-recon records from #142 to reach StarIntel through the existing canonical outbox/API boundary. ## Owning RAGE lane Hackmode integration/database boundary as appropriate after #142; not StarIntel product development. ## Fence Do not redesign StarIntel runtime/storage/UI/actors. Do not write StarIntel directly from BrowserWorker. Do not treat publish as acceptance. Hackmode remains local-first and the existing durable outbox/ack semantics remain authoritative. ## Dependencies - #140 visual recon epic - #142 canonical screenshot evidence persistence - existing Hackmode StarIntel projection/outbox contract ## Projection Map only accepted typed cyber evidence: operation/asset identity, screenshot evidence reference/digest, title/final URL/status, timing/profile/browser provenance, relevant HTTP exchange/capture references, and stable observation identity. Secret-bearing raw bodies/headers remain local evidence refs unless explicitly authorized by existing policy. ## Required behavior - deterministic remote logical identity; - offline operation continues locally; - outage keeps projection durable in outbox; - retry/reconnect is idempotent; - acceptance/ack determines completion, not mere Rabbit/HTTP publish; - no duplicate logical screenshot findings/evidence on replay. ## RED-first tests Fake StarIntel sink for outage/reconnect, duplicate retry, acceptance failure, provenance retention, and secret non-projection. ## Acceptance proof Persist one canonical screenshot observation locally with StarIntel unavailable, prove it remains usable and queued, reconnect a fake canonical sink, accept it exactly once, and retain provenance back to the local visual and HTTP/capture evidence.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nsaspy/hackmode#29
No description provided.