{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"0860e448-e960-43af-9a1c-5eed9019ef04","kind":"skill:research-report","nodes":[{"acceptedSubmissionHash":"738e85538801fb0b25f5ebac255d9315555c5ecda66c54970577b5af6716f542","dependsOn":[],"execution":{"network":true,"profile":"none","requires":["network"],"skillHash":"3ddca93330036359dd721585e58e67820336a0398b7927b3c89369d6134f30f6","skillId":"research-report","tools":[]},"key":"research_report","kind":"code","role":"implement","skillHash":"3ddca93330036359dd721585e58e67820336a0398b7927b3c89369d6134f30f6","skillId":"research-report","state":"accepted"}],"objective":"IMD Ember World - fifth technical Report on R4/AUD4 and Member M1 (World only)\n\nReview World/Auth/M1 security/correctness/privacy/availability: unofficial TypeScript Cloudflare Worker/React SIWE, NO Solidity. M1 writes public profiles. No financial/token-market research.\n\nPIN: https://github.com/tungweb3/imd-ember-world-review at 357668f37c75317f79ff2266795636597a707c04; actual parent 6e307dea76e763936fc4ac86e54c9f5d558f58c4. Published baseline: 6e307dea76e763936fc4ac86e54c9f5d558f58c4. Use immutable commit, not branch head. Private repair 54410b2f8dece71bdb2fd999c94feea6454ecfcd; private history withheld, provenance is a team claim.\n\nRead README, R5/TEST_RESULTS.md, R5/BUILD_EVIDENCE.md; source/docs/security/AUD4_REMEDIATION.md, AUD4_MEMBER_POLICY.md, AUD4_DISCOVERY.md. Old docs remain historical. Prior: R5/PRIOR_AUDIT_f3e7cfc7.md (job f3e7cfc7-0b43-473a-9c0f-6931cf278c56) and R5/PRIOR_REPORT_1dbe2282.md (job 1dbe2282-d61a-42a8-9823-2b24e48d29c1). Eight Audit findings plus Report-only M1-R2 = nine unique fixes; M1-R1 overlaps Audit #5. M1-R2 MUST have a separate verdict.\n\nTEAM/LOCAL: private 1087/1087, tsc/frontend build pass. Fresh local Wrangler D1 final 0008: five accepted, sixth trigger refused, recheck five; not production concurrency proof. Public tests (run/pass/fail): no-stub 239/235/4; FIRST with-stub 419/414/5. Failures: withheld geometry/preview/history plus first-run presence timing; timing-only 1/1 rerun does not erase first failure. Public tsc: 16 diagnostics/exit 2; no full frontend build. Focused R3/AUD3/ADV 83/83, N 42/42, Enter 3/3, Member+AUD4 including M1-R2 111/111. Public/private Worker identical 309594 bytes; hash in R5/BUILD_EVIDENCE.md. Source 100 = 16 masked + 84 exact against 54410b2; 3D/textures/scenes/WorldApp/interiors/history withheld. No full UI/browser proof; stubs are fixtures.\n\nTEAM deployment: Worker e491cb71-60ec-4cfe-9db7-b88e52d78ce9 (100% traffic checked); deployed source 54410b2f8dece71bdb2fd999c94feea6454ecfcd; record R5/BUILD_EVIDENCE.md (record 20261003T174551Z-54410b2); production migration status 0001-0006+0008 applied; six schema SQL definitions read back/matched; no 0007 (R5/PRODUCTION_D1.md); live comparison five GETs 200; four static hashes/24 headers match; anonymous signedIn:false/no-store; no Set-Cookie. Live UTC 2026-10-03T17:49:09.683Z-17:49:14.844Z; URLs/hashes/headers in record. Old acdbb2bd/ddb10e2 records do not prove this repair deployed.\n\nPrimary: source/local tests. Optional live: <=5 anonymous GETs, >=5s apart: https://imdember.com/, three record-listed static URLs, /api/auth/session. Curl/browser User-Agent; no cookies; stop on denial/no bypass. Record UTC/hash/headers. No live writes/login/wallets/signatures/transactions/approvals, DB changes, scans/fuzz/flood/deploy. GETs do not prove repaired routes or full browser.\n\nNINE RETESTS; add independent probes:\n1. R4-01/AUD4-01/Audit #1: display A/shared cookie B logout-all must 409 ACCOUNT_CONTEXT_CHANGED before revoking either. Reread without false all-device success; matching/absent/forged/expired cookies retain session authority. expectedAddress is consistency, not authority.\n2. R4-02/AUD4-06/Audit #6: verify cookie committed, body lost/truncated/malformed. Session unknown; readback before next personal_sign. Failed read stays unknown; confirmed absence permits new flow. Test switch/teardown and nonce/flow cleanup versus newer session AND pending challenge. Neither may be destroyed. Count prompts/sessions; late browser Set-Cookie remains a limit.\n3. R4-03/AUD4-02/Audit #2: only server EOA AND ECDSA permits persistent bootstrap/PUT/GET last_login writes. CONTRACT/ERC1271/unknown fail closed (write 403 CONTRACT_WRITE_NOT_ENABLED); login/existing reads without touch remain. Test arbitrary-accepting and legitimate smart-wallet sessions; temporary restriction has usability cost, not complete contract authority.\n4. R4-04/AUD4-05/Audit #5+M1-R1: 0008 trigger atomically caps five recorded attempts/member/rolling minute. Test 6/12/20 races under natural/controlled scheduling: success, reserved-name refusal, cooldown, stale/locked, no-op. Outcome/mutation roll back together; fallback refusal recording returns 429/503 on quota/storage failure. Same-ID/same-payload retry at full quota adds no record/version/history/cooldown; changed payload conflicts. New no-op consumes one attempt, no mutation, guarded against parallel rename/moderation. Separate recorded attempts from all HTTP/early-invalid/IP costs.\n5. R4-05/AUD4-04/Audit #4: expired refusal rows cleaned without later rename. Requests 1 day/history 180 days are deletion eligibility, not hard deadlines. Indexed cron 200/table, write prune 10/table. Preserve unexpired retries/current profile; test backlog, missing 0008/indexes/errors. Probe cron bounded independently of M1 readiness.\n6. R4-06/Report M1-R2 ONLY: GET(v0) starts -> SAVE(v1) accepted -> old GET(v0) arrives: client/DB retain v1. Test GET2-before-GET1, late 401/error, GET(v2) before PUT(v1) reply, account switch. Sequence/generation/highest accepted version prevent regression. Separate mandatory verdict; stale UI is not DB rollback.\n7. R4-07/AUD4-07/Audit #7: committed PUT, lost/invalid/endless body. Fetch+body 15s deadline; retry once exact original ID/body. Both unknown: retain per-wallet operation, saving=false, reread, allow only original retry. Test early 401/429/503 and logout/switch/return; one mutation/history/cooldown. Refusal before outcome lookup does not prove original failure.\n8. R4-08/AUD4-08/Audit #8: server-calibrated cooldown refresh/re-enable at expiry; switch/teardown cancel timers. Browser clock cannot bypass server.\n9. R4-09/AUD4-03/Audit #3/AUD3-02: four sessions x20 refusals over 80 /24s at colo A then buyer B: zero admitted rows/index calls from refusals; B discovers. Bounded READY -> atomic separate probe -> limiter -> fresh-clock atomic admission -> index. Probe 30s backoff (/24,/64 one;/48 two), global 60/6s and 61-admission races; prune 2 opportunistic/200 cron. Test missing schema/index fail-closed, old released rows, slow/uncertain replies and refusal-counted/free models. Probes do not pollute admitted cap; no global probe-storage ceiling. Retain 10-versus-9 /24 local availability, shared networks, influx/cost/backlog.\n\nRecheck R3-R1/AUD3-01..09, N/ADV, Enter/Home; stored SIWE equality, nonce/session/cookies/logout. House authority remains session address plus Ethereum mainnet ownerOf/eligibility, never names/roster/candidates/publicMemberId. Only eth_accounts, eth_requestAccounts, exact server-SIWE personal_sign; verify no transactions, approvals, Permit/Permit2, typed data, delegated permissions, session keys or wallet batches. Out of scope: Genesis Mint, Solidity, Coin E1/0007, check-in/rewards/economy, withheld content.\n\nDELIVER Traditional Chinese report.md and evidence. Nine-row verdict matrix, M1-R1 overlap and separate M1-R2. Classify fixed locally/partly/open/unknown; Each finding: severity/blocking, pinned file:line, prior ID, preconditions, impact, reproduction/argument. Show event order/time, DB rows/version/history/outcomes, client state, prompts and sessions/cookies created/live/revoked (N/A with reason). Record tests/failures/skips; separate measured facts, inferences, team claims and unknowns. Preserve AUD3-05 partly, AUD3-09 review-limit, missing provider events, late shared-cookie responses, ERC1271 login truth, phishing/same-origin EOA writes, production D1/bindings/WAF/limiter/upstream and full-browser limits. Completed/accepted or Low/Info findings are not certification, approval, zero vulnerabilities or fund-safety proof.","parentJobId":null,"planHash":"c153347203807105864fe4ad245092ee08e1db0a16fefdb7636d02fc4e883924","previousHash":"d806cd9ad7c9dd8cbbaf30c5b61f7c45e5ccea4e3ff58b99e6bf3a0a94e71a25","projectId":"0860e448-e960-43af-9a1c-5eed9019ef04","publication":{"commit":"f6fe589f6605110a4b86d435b2b471904e263aa3","deliveredAt":"2026-10-03T18:46:15.052Z","repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/0860e448-e960-43af-9a1c-5eed9019ef04/_identitymd/README.md"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[],"site":null,"snapshotHash":"3a2000fe44f8182420a676c66f31ad2f5f2ef235db6e67ac8d85829a4cc7072b","state":"completed","submissions":[{"artifacts":[{"bytes":28920,"hash":"920d7ff88e39d280dde9788bc6fce0d7940ff77c35645bccc0fdde1d14a9948d","mediaType":"text/markdown","name":"report","path":"artifacts/report.md"}],"attempt":1,"bundleHash":null,"device":"1f805d33d69c340e","findings":[],"hash":"738e85538801fb0b25f5ebac255d9315555c5ecda66c54970577b5af6716f542","nodeId":"a93dc1f9-07ca-4be9-8d5d-e77ed5717420","outcome":"completed","summary":"已完成[繁體中文報告](artifacts/report.md)及[證據與離線重現說明](artifacts/README.md)。\n\n九項裁決包含獨立 M1-R2；保留首次測試失敗、團隊聲稱與正式環境限制。檔案引用、雜湊及離線探測自查通過，所有交付檔案未加入 Git。","treeHash":"4b825dc642cb6eb9a060e54bf8d69288fbee4904","usage":{"cachedInputTokens":2255616,"inputTokens":127284,"model":null,"outputTokens":24437,"runtime":"codex","turns":7,"wallClockMs":1095927}}],"verification":[{"checks":[],"detail":"paths and tree verified; no suite was run for this kind of work","evaluation":"structural","profile":"none","status":"accepted","submissionHash":"738e85538801fb0b25f5ebac255d9315555c5ecda66c54970577b5af6716f542","verifiedTreeHash":"4b825dc642cb6eb9a060e54bf8d69288fbee4904","verifierVersion":"0.1.0+ef84cc5f"}]}