KB-7BA1

FIX4 Audit 10 Public Directus

1 min read Revision 1
codexauditqt001publicdirectus

10 - Public / Directus Route-to-2.6B Audit

Verdict: BYPASS_RISK_FAIL.

Current risks are visible and readiness-blocking: PUBLIC Execute open=35, writer/builder open=4, Directus owner-role DML open on 13 control tables. The no-bypass rows use (NOT guard.pass) IS NOT NULL, true for either boolean value. PUBLIC can execute builder and refresh, which mutate control-plane state without in-body authority checks. directus owns functions/views/tables. Current writer is blocked, but authority separation and no-bypass proof are invalid.

Back to Knowledge Hub knowledge/dev/reports/architecture/codex-stage2-6a-fix4-qt001-authoritative-path-no-legacy-bypass-audit-2026-06-07/10-public-directus-route-2-6b-audit.md