{"workflow":null,"planning":null,"id":"0860e448-e960-43af-9a1c-5eed9019ef04","state":"completed","template":"skill:research-report","objective":"IMD Ember World - fifth technical Report on R4/AUD4 and Member M1 (World only)\n\nReview World/Auth/M1 security/correctness/privacy/availability: unofficial TypeScript Cloudflare Worker/React SIWE, NO Solidity. M1 writes public profiles. No financial/token-market research.\n\nPIN: https://github.com/tungweb3/imd-ember-world-review at 357668f37c75317f79ff2266795636597a707c04; actual parent 6e307dea76e763936fc4ac86e54c9f5d558f58c4. Published baseline: 6e307dea76e763936fc4ac86e54c9f5d558f58c4. Use immutable commit, not branch head. Private repair 54410b2f8dece71bdb2fd999c94feea6454ecfcd; private history withheld, provenance is a team claim.\n\nRead README, R5/TEST_RESULTS.md, R5/BUILD_EVIDENCE.md; source/docs/security/AUD4_REMEDIATION.md, AUD4_MEMBER_POLICY.md, AUD4_DISCOVERY.md. Old docs remain historical. Prior: R5/PRIOR_AUDIT_f3e7cfc7.md (job f3e7cfc7-0b43-473a-9c0f-6931cf278c56) and R5/PRIOR_REPORT_1dbe2282.md (job 1dbe2282-d61a-42a8-9823-2b24e48d29c1). Eight Audit findings plus Report-only M1-R2 = nine unique fixes; M1-R1 overlaps Audit #5. M1-R2 MUST have a separate verdict.\n\nTEAM/LOCAL: private 1087/1087, tsc/frontend build pass. Fresh local Wrangler D1 final 0008: five accepted, sixth trigger refused, recheck five; not production concurrency proof. Public tests (run/pass/fail): no-stub 239/235/4; FIRST with-stub 419/414/5. Failures: withheld geometry/preview/history plus first-run presence timing; timing-only 1/1 rerun does not erase first failure. Public tsc: 16 diagnostics/exit 2; no full frontend build. Focused R3/AUD3/ADV 83/83, N 42/42, Enter 3/3, Member+AUD4 including M1-R2 111/111. Public/private Worker identical 309594 bytes; hash in R5/BUILD_EVIDENCE.md. Source 100 = 16 masked + 84 exact against 54410b2; 3D/textures/scenes/WorldApp/interiors/history withheld. No full UI/browser proof; stubs are fixtures.\n\nTEAM deployment: Worker e491cb71-60ec-4cfe-9db7-b88e52d78ce9 (100% traffic checked); deployed source 54410b2f8dece71bdb2fd999c94feea6454ecfcd; record R5/BUILD_EVIDENCE.md (record 20261003T174551Z-54410b2); production migration status 0001-0006+0008 applied; six schema SQL definitions read back/matched; no 0007 (R5/PRODUCTION_D1.md); live comparison five GETs 200; four static hashes/24 headers match; anonymous signedIn:false/no-store; no Set-Cookie. Live UTC 2026-10-03T17:49:09.683Z-17:49:14.844Z; URLs/hashes/headers in record. Old acdbb2bd/ddb10e2 records do not prove this repair deployed.\n\nPrimary: source/local tests. Optional live: <=5 anonymous GETs, >=5s apart: https://imdember.com/, three record-listed static URLs, /api/auth/session. Curl/browser User-Agent; no cookies; stop on denial/no bypass. Record UTC/hash/headers. No live writes/login/wallets/signatures/transactions/approvals, DB changes, scans/fuzz/flood/deploy. GETs do not prove repaired routes or full browser.\n\nNINE RETESTS; add independent probes:\n1. R4-01/AUD4-01/Audit #1: display A/shared cookie B logout-all must 409 ACCOUNT_CONTEXT_CHANGED before revoking either. Reread without false all-device success; matching/absent/forged/expired cookies retain session authority. expectedAddress is consistency, not authority.\n2. R4-02/AUD4-06/Audit #6: verify cookie committed, body lost/truncated/malformed. Session unknown; readback before next personal_sign. Failed read stays unknown; confirmed absence permits new flow. Test switch/teardown and nonce/flow cleanup versus newer session AND pending challenge. Neither may be destroyed. Count prompts/sessions; late browser Set-Cookie remains a limit.\n3. R4-03/AUD4-02/Audit #2: only server EOA AND ECDSA permits persistent bootstrap/PUT/GET last_login writes. CONTRACT/ERC1271/unknown fail closed (write 403 CONTRACT_WRITE_NOT_ENABLED); login/existing reads without touch remain. Test arbitrary-accepting and legitimate smart-wallet sessions; temporary restriction has usability cost, not complete contract authority.\n4. R4-04/AUD4-05/Audit #5+M1-R1: 0008 trigger atomically caps five recorded attempts/member/rolling minute. Test 6/12/20 races under natural/controlled scheduling: success, reserved-name refusal, cooldown, stale/locked, no-op. Outcome/mutation roll back together; fallback refusal recording returns 429/503 on quota/storage failure. Same-ID/same-payload retry at full quota adds no record/version/history/cooldown; changed payload conflicts. New no-op consumes one attempt, no mutation, guarded against parallel rename/moderation. Separate recorded attempts from all HTTP/early-invalid/IP costs.\n5. R4-05/AUD4-04/Audit #4: expired refusal rows cleaned without later rename. Requests 1 day/history 180 days are deletion eligibility, not hard deadlines. Indexed cron 200/table, write prune 10/table. Preserve unexpired retries/current profile; test backlog, missing 0008/indexes/errors. Probe cron bounded independently of M1 readiness.\n6. R4-06/Report M1-R2 ONLY: GET(v0) starts -> SAVE(v1) accepted -> old GET(v0) arrives: client/DB retain v1. Test GET2-before-GET1, late 401/error, GET(v2) before PUT(v1) reply, account switch. Sequence/generation/highest accepted version prevent regression. Separate mandatory verdict; stale UI is not DB rollback.\n7. R4-07/AUD4-07/Audit #7: committed PUT, lost/invalid/endless body. Fetch+body 15s deadline; retry once exact original ID/body. Both unknown: retain per-wallet operation, saving=false, reread, allow only original retry. Test early 401/429/503 and logout/switch/return; one mutation/history/cooldown. Refusal before outcome lookup does not prove original failure.\n8. R4-08/AUD4-08/Audit #8: server-calibrated cooldown refresh/re-enable at expiry; switch/teardown cancel timers. Browser clock cannot bypass server.\n9. R4-09/AUD4-03/Audit #3/AUD3-02: four sessions x20 refusals over 80 /24s at colo A then buyer B: zero admitted rows/index calls from refusals; B discovers. Bounded READY -> atomic separate probe -> limiter -> fresh-clock atomic admission -> index. Probe 30s backoff (/24,/64 one;/48 two), global 60/6s and 61-admission races; prune 2 opportunistic/200 cron. Test missing schema/index fail-closed, old released rows, slow/uncertain replies and refusal-counted/free models. Probes do not pollute admitted cap; no global probe-storage ceiling. Retain 10-versus-9 /24 local availability, shared networks, influx/cost/backlog.\n\nRecheck R3-R1/AUD3-01..09, N/ADV, Enter/Home; stored SIWE equality, nonce/session/cookies/logout. House authority remains session address plus Ethereum mainnet ownerOf/eligibility, never names/roster/candidates/publicMemberId. Only eth_accounts, eth_requestAccounts, exact server-SIWE personal_sign; verify no transactions, approvals, Permit/Permit2, typed data, delegated permissions, session keys or wallet batches. Out of scope: Genesis Mint, Solidity, Coin E1/0007, check-in/rewards/economy, withheld content.\n\nDELIVER Traditional Chinese report.md and evidence. Nine-row verdict matrix, M1-R1 overlap and separate M1-R2. Classify fixed locally/partly/open/unknown; Each finding: severity/blocking, pinned file:line, prior ID, preconditions, impact, reproduction/argument. Show event order/time, DB rows/version/history/outcomes, client state, prompts and sessions/cookies created/live/revoked (N/A with reason). Record tests/failures/skips; separate measured facts, inferences, team claims and unknowns. Preserve AUD3-05 partly, AUD3-09 review-limit, missing provider events, late shared-cookie responses, ERC1271 login truth, phishing/same-origin EOA writes, production D1/bindings/WAF/limiter/upstream and full-browser limits. Completed/accepted or Low/Info findings are not certification, approval, zero vulnerabilities or fund-safety proof.","blockedReason":null,"createdAt":"2026-10-03T18:27:09.332Z","updatedAt":"2026-10-03T18:45:29.974Z","paidBy":"0x9f2c2846b5edeeb0f46affd6d86161a053bbd985","parentJobId":null,"project":{"id":"0860e448-e960-43af-9a1c-5eed9019ef04","head":"0860e448-e960-43af-9a1c-5eed9019ef04","running":null,"versions":[{"jobId":"0860e448-e960-43af-9a1c-5eed9019ef04","workflowId":null,"objective":"IMD Ember World - fifth technical Report on R4/AUD4 and Member M1 (World only)\n\nReview World/Auth/M1 security/correctness/privacy/availability: unofficial TypeScript Cloudflare Worker/React SIWE, NO Solidity. M1 writes public profiles. No financial/token-market research.\n\nPIN: https://github.com/tungweb3/imd-ember-world-review at 357668f37c75317f79ff2266795636597a707c04; actual parent 6e307dea76e763936fc4ac86e54c9f5d558f58c4. Published baseline: 6e307dea76e763936fc4ac86e54c9f5d558f58c4. Use immutable commit, not branch head. Private repair 54410b2f8dece71bdb2fd999c94feea6454ecfcd; private history withheld, provenance is a team claim.\n\nRead README, R5/TEST_RESULTS.md, R5/BUILD_EVIDENCE.md; source/docs/security/AUD4_REMEDIATION.md, AUD4_MEMBER_POLICY.md, AUD4_DISCOVERY.md. Old docs remain historical. Prior: R5/PRIOR_AUDIT_f3e7cfc7.md (job f3e7cfc7-0b43-473a-9c0f-6931cf278c56) and R5/PRIOR_REPORT_1dbe2282.md (job 1dbe2282-d61a-42a8-9823-2b24e48d29c1). Eight Audit findings plus Report-only M1-R2 = nine unique fixes; M1-R1 overlaps Audit #5. M1-R2 MUST have a separate verdict.\n\nTEAM/LOCAL: private 1087/1087, tsc/frontend build pass. Fresh local Wrangler D1 final 0008: five accepted, sixth trigger refused, recheck five; not production concurrency proof. Public tests (run/pass/fail): no-stub 239/235/4; FIRST with-stub 419/414/5. Failures: withheld geometry/preview/history plus first-run presence timing; timing-only 1/1 rerun does not erase first failure. Public tsc: 16 diagnostics/exit 2; no full frontend build. Focused R3/AUD3/ADV 83/83, N 42/42, Enter 3/3, Member+AUD4 including M1-R2 111/111. Public/private Worker identical 309594 bytes; hash in R5/BUILD_EVIDENCE.md. Source 100 = 16 masked + 84 exact against 54410b2; 3D/textures/scenes/WorldApp/interiors/history withheld. No full UI/browser proof; stubs are fixtures.\n\nTEAM deployment: Worker e491cb71-60ec-4cfe-9db7-b88e52d78ce9 (100% traffic checked); deployed source 54410b2f8dece71bdb2fd999c94feea6454ecfcd; record R5/BUILD_EVIDENCE.md (record 20261003T174551Z-54410b2); production migration status 0001-0006+0008 applied; six schema SQL definitions read back/matched; no 0007 (R5/PRODUCTION_D1.md); live comparison five GETs 200; four static hashes/24 headers match; anonymous signedIn:false/no-store; no Set-Cookie. Live UTC 2026-10-03T17:49:09.683Z-17:49:14.844Z; URLs/hashes/headers in record. Old acdbb2bd/ddb10e2 records do not prove this repair deployed.\n\nPrimary: source/local tests. Optional live: <=5 anonymous GETs, >=5s apart: https://imdember.com/, three record-listed static URLs, /api/auth/session. Curl/browser User-Agent; no cookies; stop on denial/no bypass. Record UTC/hash/headers. No live writes/login/wallets/signatures/transactions/approvals, DB changes, scans/fuzz/flood/deploy. GETs do not prove repaired routes or full browser.\n\nNINE RETESTS; add independent probes:\n1. R4-01/AUD4-01/Audit #1: display A/shared cookie B logout-all must 409 ACCOUNT_CONTEXT_CHANGED before revoking either. Reread without false all-device success; matching/absent/forged/expired cookies retain session authority. expectedAddress is consistency, not authority.\n2. R4-02/AUD4-06/Audit #6: verify cookie committed, body lost/truncated/malformed. Session unknown; readback before next personal_sign. Failed read stays unknown; confirmed absence permits new flow. Test switch/teardown and nonce/flow cleanup versus newer session AND pending challenge. Neither may be destroyed. Count prompts/sessions; late browser Set-Cookie remains a limit.\n3. R4-03/AUD4-02/Audit #2: only server EOA AND ECDSA permits persistent bootstrap/PUT/GET last_login writes. CONTRACT/ERC1271/unknown fail closed (write 403 CONTRACT_WRITE_NOT_ENABLED); login/existing reads without touch remain. Test arbitrary-accepting and legitimate smart-wallet sessions; temporary restriction has usability cost, not complete contract authority.\n4. R4-04/AUD4-05/Audit #5+M1-R1: 0008 trigger atomically caps five recorded attempts/member/rolling minute. Test 6/12/20 races under natural/controlled scheduling: success, reserved-name refusal, cooldown, stale/locked, no-op. Outcome/mutation roll back together; fallback refusal recording returns 429/503 on quota/storage failure. Same-ID/same-payload retry at full quota adds no record/version/history/cooldown; changed payload conflicts. New no-op consumes one attempt, no mutation, guarded against parallel rename/moderation. Separate recorded attempts from all HTTP/early-invalid/IP costs.\n5. R4-05/AUD4-04/Audit #4: expired refusal rows cleaned without later rename. Requests 1 day/history 180 days are deletion eligibility, not hard deadlines. Indexed cron 200/table, write prune 10/table. Preserve unexpired retries/current profile; test backlog, missing 0008/indexes/errors. Probe cron bounded independently of M1 readiness.\n6. R4-06/Report M1-R2 ONLY: GET(v0) starts -> SAVE(v1) accepted -> old GET(v0) arrives: client/DB retain v1. Test GET2-before-GET1, late 401/error, GET(v2) before PUT(v1) reply, account switch. Sequence/generation/highest accepted version prevent regression. Separate mandatory verdict; stale UI is not DB rollback.\n7. R4-07/AUD4-07/Audit #7: committed PUT, lost/invalid/endless body. Fetch+body 15s deadline; retry once exact original ID/body. Both unknown: retain per-wallet operation, saving=false, reread, allow only original retry. Test early 401/429/503 and logout/switch/return; one mutation/history/cooldown. Refusal before outcome lookup does not prove original failure.\n8. R4-08/AUD4-08/Audit #8: server-calibrated cooldown refresh/re-enable at expiry; switch/teardown cancel timers. Browser clock cannot bypass server.\n9. R4-09/AUD4-03/Audit #3/AUD3-02: four sessions x20 refusals over 80 /24s at colo A then buyer B: zero admitted rows/index calls from refusals; B discovers. Bounded READY -> atomic separate probe -> limiter -> fresh-clock atomic admission -> index. Probe 30s backoff (/24,/64 one;/48 two), global 60/6s and 61-admission races; prune 2 opportunistic/200 cron. Test missing schema/index fail-closed, old released rows, slow/uncertain replies and refusal-counted/free models. Probes do not pollute admitted cap; no global probe-storage ceiling. Retain 10-versus-9 /24 local availability, shared networks, influx/cost/backlog.\n\nRecheck R3-R1/AUD3-01..09, N/ADV, Enter/Home; stored SIWE equality, nonce/session/cookies/logout. House authority remains session address plus Ethereum mainnet ownerOf/eligibility, never names/roster/candidates/publicMemberId. Only eth_accounts, eth_requestAccounts, exact server-SIWE personal_sign; verify no transactions, approvals, Permit/Permit2, typed data, delegated permissions, session keys or wallet batches. Out of scope: Genesis Mint, Solidity, Coin E1/0007, check-in/rewards/economy, withheld content.\n\nDELIVER Traditional Chinese report.md and evidence. Nine-row verdict matrix, M1-R1 overlap and separate M1-R2. Classify fixed locally/partly/open/unknown; Each finding: severity/blocking, pinned file:line, prior ID, preconditions, impact, reproduction/argument. Show event order/time, DB rows/version/history/outcomes, client state, prompts and sessions/cookies created/live/revoked (N/A with reason). Record tests/failures/skips; separate measured facts, inferences, team claims and unknowns. Preserve AUD3-05 partly, AUD3-09 review-limit, missing provider events, late shared-cookie responses, ERC1271 login truth, phishing/same-origin EOA writes, production D1/bindings/WAF/limiter/upstream and full-browser limits. Completed/accepted or Low/Info findings are not certification, approval, zero vulnerabilities or fund-safety proof.","baseCommit":"0243d7da4a4337ae8b16bcdf15bb4ead736fd68f","state":"completed","createdAt":"2026-10-03T18:27:09.332Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/0860e448-e960-43af-9a1c-5eed9019ef04/_identitymd/README.md","pullRequestUrl":null,"commit":"f6fe589f6605110a4b86d435b2b471904e263aa3","deliveredAt":"2026-10-03T18:46:15.052Z","media":null},"media":null,"nodes":[{"key":"research_report","role":"implement","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-03T18:45:29.974Z","verdict":{"status":"accepted","profile":"none","evaluation":"structural","rejectionCode":null,"detail":"paths and tree verified; no suite was run for this kind of work","verifierVersion":"0.1.0+ef84cc5f","verifiedTreeHash":"4b825dc642cb6eb9a060e54bf8d69288fbee4904","at":"2026-10-03T18:45:29.974Z","failedChecks":[]},"seat":{"tokenId":"1433","agentId":"50990"},"live":null}],"reviews":[{"status":"sent","chainId":1,"txHash":"0x0214dd63e9672191bb9208fe8682feefc6690a43d6e76dd1f5283f3460fff31d","blockNumber":26116388,"sentAt":"2026-10-04T03:46:27.995Z","entries":[]},{"status":"sent","chainId":1,"txHash":"0x90773dc686b537886ed6a333585e3d9cbbef779cf70f3d4f10d6dcae831c904f","blockNumber":26115111,"sentAt":"2026-10-03T23:30:13.347Z","entries":[{"nodeKey":"research_report","agentId":"50990","value":1,"role":"verification:structural"}]}]}