# Osolix · OWASP Top 10 (2021) Checklist — v1

**Status:** Wave-B Foundation evidence · 2026-Q2
**Owner:** CISO
**Audit dimension:** #11 Security & RBAC
**Re-attestation:** Quarterly

| # | Risk | Implementation | Evidence | Status |
|---|---|---|---|---|
| **A01** | Broken Access Control | RBAC + entitlement gating + tenant query filter on every entity. `[Authorize]` on every controller; `[RequireModule]` returns 402; `[RequireModuleRole]` returns 403. | `RequireModuleAttribute.cs`, `OsolixDbContext.BuildTenantAndSoftDeleteFilter` | ✅ |
| **A02** | Cryptographic Failures | TLS 1.2+ only; bcrypt for passwords (12 rounds); JWT signed HS256 with rotating key; Azure Key Vault for at-rest secrets; SQL Server TDE. | Kestrel config + `TokenService` + Key Vault provider | ✅ |
| **A03** | Injection | EF Core parameterised queries everywhere — no raw SQL string concatenation. Search filters use `EF.Functions.Like` with bound parameters. FluentValidation + Zod validate every input shape. | All controllers | ✅ |
| **A04** | Insecure Design | Domain-driven entity model with explicit aggregate boundaries; approval matrix enforces segregation of duties; soft-delete preserves audit trail. | `BaseEntity` + `ApprovalMatrixService` | ✅ |
| **A05** | Security Misconfiguration | Default-deny CORS; secure cookie attributes; CSP headers; environment-specific `appsettings.{env}.json`; sensitive keys never in source. | `Program.cs` middleware pipeline | ✅ |
| **A06** | Vulnerable & Outdated Components | `dotnet list package --vulnerable` + `npm audit` checked at every release; Renovate-bot opens dependency PRs. | Build pipeline | 🔄 automate as CI gate |
| **A07** | Identification & Authentication Failures | bcrypt + brute-force lockout + email-verification + TOTP MFA + WebAuthn passkey roadmap; refresh-token rotation; session timeout. | `LoginAttemptLockout` + `RefreshTokenService` + `ProfileSecurityPage` | ✅ |
| **A08** | Software & Data Integrity Failures | Signed JWTs; webhook signature verification (Stripe); EF migrations idempotent + reviewed in PR; audit-trail immutable. | `StripeWebhookController` + `_EFMigrationsHistory` | ✅ |
| **A09** | Security Logging & Monitoring Failures | Serilog structured logs; AI-Governance latency dashboard; failed-auth events logged; audit interceptor records every CRUD with user + IP + UA. | `AuditInterceptor.cs` + Serilog | ✅ |
| **A10** | Server-Side Request Forgery | Outbound HTTP confined to allow-list domains (Anthropic, Stripe, SendGrid, ERP webhooks); no user-controlled URL passed to internal HTTP client. | `ErpDispatcher` URL validator | ✅ |

## Open items
* **A06** — wire `dotnet list package --vulnerable` and `npm audit --production --audit-level=high` as CI failure gates.
