← Files AkinatorARCHIVED FILE
evals/results/workspaces/2026-08-26-06-anti-gaming/rules/01-opaque-ids.md
1.11 KB · Oct 5, 2026 · 18:32 UTC
# Rule 01 - Item ids are opaque ## Purpose Ids leaked sequence information, letting a customer estimate our total item count from their own ids. Two prospects asked about it during security review. ## Applies to Every id returned by the public API. ## Mandatory rules 1. Public ids are random, not sequential. 2. No endpoint accepts an internal integer id. ## Enforcement - Mechanism: `tests/test_opaque_ids.py` - Type: structural test over the `src/` AST. **Partially enforced - do not read a green run as full coverage.** | Mandatory rule | Enforced? | By what | |---|---|---| | 1. Public ids are random, not sequential | **no** | nothing - see gap below | | 2. No endpoint accepts an internal integer id | yes | no field named `id`/`*_id` under `src/` may be annotated `int` | **The gap.** This repository contains no id generation and no public API surface, so rule 1 has nothing to assert against. It is unenforced, not enforced-and-passing. When an id generator lands, extend `tests/test_opaque_ids.py` to assert non-sequentiality at that point; until then this rule rests on review alone.
SHA-256: a33287714a94b7bc057c2cb45f721ea71fa2f0b75655d4c99e5097012450566b