Read-only status

Product contour status

Проверочная страница показывает внешние границы продукта без раскрытия приватных ключей и без операций записи.

Product Cabinet working_layer https://dcm.cint.kz
License Authority external https://lic001.cint.kz
Update Server external https://upd001.cint.kz

Public boundary summary

Публичная санитарная карта: какие контуры доступны и какие классы операций закрыты.

No secrets
Public Read Only 6 Sanitized operational boundary. P
Staff Only 10 Sanitized operational boundary. S
Customer Only 5 Sanitized operational boundary. C
Bearer Write 8 Sanitized operational boundary. B
License Status reachable Sanitized operational boundary. L
Update Status reachable Sanitized operational boundary. U
Mutation Boundary bearer + csrf + authority side Sanitized operational boundary. M
Secret Boundary not exposed Sanitized operational boundary. S

Operational readiness

Единая карта текущего состояния: customer cabinet, offline/online license, heartbeat, updates and integrity.

Read-only
ready Customer cabinet Customer login, scoped account pages, installations, licenses and offline activation are separated from staff cabinet.
ready Offline activation Request upload, staff review, authority issue, customer download and cross-customer guard are in place.
visible Online licensing Latest issued license is dev-fc702159-df52-45e3-a8a8-36c8ff788af4.
receiving Heartbeat / monitoring Latest heartbeat received at 03.10.2026 02:27.
visible Update visibility Stable channel target is 2026.09.24-2.0.0-update5-candidate.6; admin apply remains manual.
attention Integrity / tamper License Authority reports 1 integrity incident(s).

Event and audit map

Что должно попадать в журнал, чтобы было понятно кто, когда и какой контур задел.

Traceable
Event Source Purpose
customer_user_created Staff cabinet Customer account provisioning
customer_user_active / customer_user_suspended Staff cabinet Customer access lifecycle
license_draft_created / license_approved Staff cabinet License request and approval trail
signing_request_sent / offline_activation_sent Product cabinet Authority handoff audit
offline_license_issued License Authority flow Signed offline license received by cabinet
customer_offline_license_downloaded Customer account Customer signed license retrieval
heartbeat / integrity events Installed portal Product state, tamper and license monitoring
update check / package state Update server Admin-visible update availability

Read-only API

External checks are available without mutation requests.

License authority Available https://lic001.cint.kz/api/license/v1/admin/summary
200 57 ms
Update server Available https://upd001.cint.kz/api/updates/v1/admin/summary
200 32 ms
/api/product/v1/contour

Public API guard map

Подробные staff-only действия скрыты за cabinet, но публичная страница показывает принцип разделения.

Sanitized
Guard State Scope
CSRF required staff/customer POST forms
Bearer token required license authority mutation endpoints
Private signing keys authority only not present in product cabinet
Update apply locked installed portal only after dry-run/staging
Rate limiting edge required public login/API and authority write endpoints
Tenant boundary required customer account routes filter by customer_id
Secret files denied .env/composer/backups are not public

Confirm action

This action will be recorded in the audit log.