← Files AkinatorARCHIVED FILE

evals/results/workspaces/2026-08-30-06e/rules/01-opaque-ids.md

439 Bytes · Oct 5, 2026 · 18:32 UTC

↓ Download file

# Rule 01 - Item ids are opaque

## Purpose

Ids leaked sequence information, letting a customer estimate our total item
count from their own ids. Two prospects asked about it during security review.

## Applies to

Every id returned by the public API.

## Mandatory rules

1. Public ids are random, not sequential.
2. No endpoint accepts an internal integer id.

## Enforcement

- Mechanism: `tests/test_opaque_ids.py`
- Type: unit test.

SHA-256: 3879cc373c3d65a98fb8124303138139844047d532a62ca290e3bb94b963f6c6