GDPR batch A+B: SECURITY.md, /privacy, rate limit, temp-file fix, Delete All Data - #36
Conversation
|
Added 🤖 Generated with Claude Code |
/generate and /prefill together allow 100 fills per user per rolling hour, counted over the existing usage log (the flyfun_common.auth.rate_limit strategy: no counter rows). Over the limit is a 429 with Retry-After, checked before any template is filled. Closes SECURITY_AUDIT.md §17. SECURITY.md adds the private reporting channel and the UK GDPR Art. 33-34 breach runbook, adapted from weather's, with the breach scenarios that apply to a server holding no manifest data and the processor duty to tell pilot-controllers. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The apps need a privacy link, and the forms backend served no pages. /privacy renders the repo's PRIVACY.md (baked into the image), so there is one source; repo-relative links point at GitHub. Public, no auth. The passenger note links /privacy#passengers, which a test guards. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Settings gains a Privacy card (policy link to /privacy, and a share-sheet note a pilot can hand passengers, GDPR Art. 14) and a Delete all data action: Room clearAllTables (tombstones and passenger links included, then VACUUM), the forms/export cache folder, and web-form WebView storage. It never signs out. Delete Account now says what it deletes and that the on-phone records stay. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… All Data Filled forms (passport data) were left in tmp since QuickLook's cleanup went with QuickLook in 6d5d0cc. GeneratedFormFiles now owns their lifetime under tmp/forms/: iOS deletes on share-sheet close and once the mail composer has the attachment; macOS deletes on Done/close/Save and keeps the file only while Open/Reveal/Mail/sharing services still read it, relying on a 15-minute sweep before the next form and a clear at launch. Settings gains Privacy (policy link, passenger note share, GDPR Art. 14) and Delete All Data: every AppSchema model deleted record by record so CloudKit syncs it, then the UI is rebuilt; the account and Keychain are untouched. Delete Account now says the on-device records stay. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rasure PRIVACY.md (now also served at /privacy) gains Android storage, passport scanning with the ML Kit metrics disclosure Google's terms require, a Passengers section (the #passengers anchor the in-app note links), and Deleting Your Data; temp-file wording matches the new behaviour. SECURITY_AUDIT.md §16 records the regression and re-fix, §17 the rate limit. legal/GDPR.md marks §1, §7, §9, §15 resolved and adds §6a for the Android client. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ML Kit sends Google usage metrics once running, with no opt-out, and its MlKitInitProvider started it at every launch. The manifest now removes the provider, and both scan paths - the camera (MrzScanner) and photo/PDF (ImageMrzReader) - call startMlKit() first, so a pilot who never scans never runs ML Kit. startMlKit() guards MlKit.initialize() to once per process: it is not idempotent and throws "already initialized" on a second call, which would crash the second scan. MlKitLazyInitTest asserts ML Kit is uninitialised after app start, started by a scan, and survives each path twice; it fails with the provider restored, so a dependency bump that re-adds it is caught. PRIVACY.md and GDPR.md §6a narrow the disclosure to pilots who scan. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
9f4a238 to
c522f93
Compare
|
Rebased onto main (6 new Android commits from PR 35). Two things came out of it:
The ML Kit commit was amended to include both fixes (force-pushed). Checks after the rebase: Android build, JVM tests, instrumented scan 1/1 and data 23/23, Python 211 passed. 🤖 Generated with Claude Code |
Code ReviewReviewed the full diff (Python API, iOS/macOS, Android) against Checked closely:
No bugs, CLAUDE.md violations (none present in repo), or design-doc deviations found with high confidence. Design docs ( Approving. 🤖 Generated with Claude Code |
Works through Batches A and B of the outstanding items in
legal/GDPR.md.Backend
/generate+/prefillshare a limit of 100 fills per user per rolling hour, counted over the existingusagelog (the same approach asflyfun_common.auth.rate_limit). Over the limit:429+Retry-After. Skipped in dev mode. ClosesSECURITY_AUDIT.md§17.GET /privacy: public HTML rendered from the repo'sPRIVACY.md(now copied into the image; newmarkdowndependency). Repo-relative links are rewritten to GitHub; a test guards the#passengersanchor that the in-app note links to.SECURITY.md: private reporting channel + UK GDPR Art. 33–34 breach runbook. GitHub private vulnerability reporting has been enabled on the repo.iOS / macOS
SECURITY_AUDIT.md§16 had wrongly said FIXED since6d5d0cc):GeneratedFormFilesownstmp/forms/. iOS deletes the file on share-sheet close, or once the mail composer has the attachment. macOS keeps it after Open/Reveal/Mail/sharing services, then deletes it in the 15-minute sweep or at launch.AppSchemamodel is deleted record by record, so CloudKit syncs the deletion (the confirmation says so); then the UI is rebuilt. Doesn't sign out.needs_review.Android
clearAllTables+ the forms/export cache + WebView storage.Docs
PRIVACY.md: Android storage, passport scanning with the ML Kit metrics disclosure (Google's terms require it and document no opt-out), Passengers, and Deleting Your Data.legal/GDPR.md: new §6a for Android; §1/§7/§9/§15 resolved.designs/api.mdanddesigns/ios-app.mdupdated.Verification
Before release
PRIVACY.mdin the image). Deploy before the app releases, since they link/privacy.🤖 Generated with Claude Code