Read-only status
Product contour status
Проверочная страница показывает внешние границы продукта без раскрытия приватных ключей и без операций записи.
Public boundary summary
Публичная санитарная карта: какие контуры доступны и какие классы операций закрыты.
Operational readiness
Единая карта текущего состояния: customer cabinet, offline/online license, heartbeat, updates and integrity.
Event and audit map
Что должно попадать в журнал, чтобы было понятно кто, когда и какой контур задел.
| Event | Source | Purpose |
|---|---|---|
| customer_user_created | Staff cabinet | Customer account provisioning |
| customer_user_active / customer_user_suspended | Staff cabinet | Customer access lifecycle |
| license_draft_created / license_approved | Staff cabinet | License request and approval trail |
| signing_request_sent / offline_activation_sent | Product cabinet | Authority handoff audit |
| offline_license_issued | License Authority flow | Signed offline license received by cabinet |
| customer_offline_license_downloaded | Customer account | Customer signed license retrieval |
| heartbeat / integrity events | Installed portal | Product state, tamper and license monitoring |
| update check / package state | Update server | Admin-visible update availability |
Read-only API
External checks are available without mutation requests.
License authority
Available
https://lic001.cint.kz/api/license/v1/admin/summary
Update server
Available
https://upd001.cint.kz/api/updates/v1/admin/summary
/api/product/v1/contour
Public API guard map
Подробные staff-only действия скрыты за cabinet, но публичная страница показывает принцип разделения.
| Guard | State | Scope |
|---|---|---|
| CSRF | required | staff/customer POST forms |
| Bearer token | required | license authority mutation endpoints |
| Private signing keys | authority only | not present in product cabinet |
| Update apply | locked | installed portal only after dry-run/staging |
| Rate limiting | edge required | public login/API and authority write endpoints |
| Tenant boundary | required | customer account routes filter by customer_id |
| Secret files | denied | .env/composer/backups are not public |