PHI_ACCESS_ALERT canonical template

Featurekamo-shared-library
Shipped
August 4, 2026 at 4:19 AM UTC
Author
Kamo
Commit
19cc558

SecurityService's hourly review of phi_access_log needs somewhere to send what it finds. Rather than invent a channel it uses the existing transactional-email rail, which means a canonical key: absent from CANONICAL_KEYS a template can never be seeded, never self-heals, and every send returns a permanent 404 — an alerting control that looks like coverage and delivers nothing. The template carries identifiers, counts and a time window only. A detection artefact that reproduces what it detected has relocated the PHI into an inbox with no retention policy, so there is deliberately no placeholder for a record. PhiAccessAlertTemplateTest pins that, and pins the two silent failure modes: a placeholder nothing supplies renders as an empty string with only a WARN, and the renderer does no HTML escaping, so anything reaching the body uses the escaped twin. EmailService must redeploy with this shared-lib before SecurityService starts sending; until then the send is caught and the finding stays review-log only.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing