Steward WRITE proxies — record feedback, publish pull-through policy, trigger pricing run

FeatureSecurityService
Shipped
July 3, 2026 at 4:25 AM UTC
Author
Kamo
Commit
d915793

Write discipline, applied identically on all three POSTs: - downstream body built server-side from a WHITELIST of browser fields; - organizationId + actor member id ALWAYS session-stamped (new actorMemberId() prefers SUDO_MEMBER_ID so enter-as attributes to the human, not the System User); - org-blind target ids ownership-verified FIRST via the new MLOS org-resolution reads (decision-org / lender-profile-org / scenario-org), 404 on unknown or foreign — fail closed, no cross-org existence oracle; - steward-feedback pins isTestLoan=false (HMDA/test partition is not browser-controllable); pricing clamps purpose to SHOPPING|WHAT_IF and pins pricedAsOf (no backdating) + ausGate (resolver-authoritative); - clients gain a postJson twin that relays downstream 4xx/5xx status+body verbatim; only transport failures bubble to 502.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing