From 95859660d6ed82439c8d131935ed23a9fe5f6831 Mon Sep 17 00:00:00 2001 From: lorentz Date: Wed, 15 Jul 2026 19:34:50 -0400 Subject: [PATCH] docs(phase-18): update tracking after wave 2 --- .planning/ROADMAP.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index 32b3bae..d8f5cae 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -358,7 +358,7 @@ summarizes classification, blast radius, and recommended/approved remediation st - [x] **Phase 15: Data Model, Detection & Ticket Evidence** — New phishing schema (migration 097) + idempotent Autotask ticket scanner + base ticket evidence capture (completed 2026-07-15) - [x] **Phase 16: EML/MIME Evidence Parser** — Pure RFC822/MIME parser: `.eml` selection (`rfc.eml` over `OriginatingEmail.eml`), normalized headers/URLs/attachments, sanitized body preview, synthetic-fixture tests (completed 2026-07-15) - [x] **Phase 17: Mimecast Blast Radius Lookup** — Blast-radius abstraction with graceful `unavailable` degradation when Mimecast isn't configured (completed 2026-07-15) -- [ ] **Phase 18: Campaign Grouping & Phishing Analysis API** — Message-ID-first dedupe/grouping, on-demand single-ticket analysis, and the first `/api/phishing/*` routes with the ACCESS-01 auth convention +- [x] **Phase 18: Campaign Grouping & Phishing Analysis API** — Message-ID-first dedupe/grouping, on-demand single-ticket analysis, and the first `/api/phishing/*` routes with the ACCESS-01 auth convention (completed 2026-07-15) - [ ] **Phase 19: Classification Engine** — Deterministic SPAM/UNWANTED/THREAT rule classifier over bounded structured evidence, KnowBe4-simulation guard, (re-)trigger API - [ ] **Phase 20: Remediation, Approval & Audit Safety** — Proposed-only remediation actions, approve/remediate/mark-false-positive APIs, idempotent re-run, full audit trail - [ ] **Phase 21: Autotask Triage Note** — Sanitized internal triage note posted via existing safe note-write path, or returned via API if no such path exists @@ -420,8 +420,8 @@ summarizes classification, blast radius, and recommended/approved remediation st 5. Every `/api/phishing/*` route introduced in this phase calls `requireAuth()` (or `requirePermission()`) and rejects an unauthenticated/unauthorized request with 401/403 — establishing the auth convention every later phishing endpoint (Phases 19-21) must also follow **Plans**: 3 plans (2 waves) - [x] 18-01-PLAN.md — Campaign grouping service (tiered match + transactional find-or-create) + tests + phishing permission resource (CAMP-01, CAMP-02, ACCESS-01) -- [ ] 18-02-PLAN.md — POST /api/phishing/tickets/{id}/analyze + wire groupReportIntoCampaign into webhook + cron sweep automatic paths (DETECT-03, CAMP-01, CAMP-02, ACCESS-01) -- [ ] 18-03-PLAN.md — GET /api/phishing/campaigns list + GET /api/phishing/campaigns/{id} nested detail (CAMP-03, ACCESS-01) +- [x] 18-02-PLAN.md — POST /api/phishing/tickets/{id}/analyze + wire groupReportIntoCampaign into webhook + cron sweep automatic paths (DETECT-03, CAMP-01, CAMP-02, ACCESS-01) +- [x] 18-03-PLAN.md — GET /api/phishing/campaigns list + GET /api/phishing/campaigns/{id} nested detail (CAMP-03, ACCESS-01) **UI hint**: no ### Phase 19: Classification Engine @@ -487,7 +487,7 @@ Phases execute in numeric order. v1.0 (Phases 1-9.1) shipped 2026-07-10. v2.0 (P | 15. Data Model, Detection & Ticket Evidence | v3.0 | 3/3 | Complete | 2026-07-15 | | 16. EML/MIME Evidence Parser | v3.0 | 3/3 | Complete | 2026-07-15 | | 17. Mimecast Blast Radius Lookup | v3.0 | 1/1 | Complete | 2026-07-15 | -| 18. Campaign Grouping & Phishing Analysis API | v3.0 | 1/3 | In Progress| | +| 18. Campaign Grouping & Phishing Analysis API | v3.0 | 3/3 | Complete | 2026-07-15 | | 19. Classification Engine | v3.0 | 0/TBD | Not started | - | | 20. Remediation, Approval & Audit Safety | v3.0 | 0/TBD | Not started | - | | 21. Autotask Triage Note | v3.0 | 0/TBD | Not started | - |