Commit graph

2 commits

Author SHA1 Message Date
38c1ae4daf feat(19-01): implement classifyCampaign orchestrator + evidence gathering (GREEN)
- gatherCampaignEvidence: bulk-fetches reports (earliest-first, joined to
  contacts for requester email) -> messages (report_id = ANY) -> indicators
  (message_id = ANY), parses messages.headers JSONB into bounded
  ParsedMessage fields, and runs one getBlastRadius() lookup keyed off the
  earliest report's sender/subject/±24h window (research A6); synthesizes
  unavailable/not_configured with no Mimecast call when no report is linked
- evaluateThreatTier (D-03): blastRadius.status==='ok' AND
  (delivered>0 OR clicked>0) AND (hasHardAuthFail via effectiveAuthResults
  OR hasKnownBadIndicatorMatch — same attachment_hash/url value spanning
  >=2 distinct messages, cross-report correlation only, no external
  reputation lookup per research A4)
- evaluateSpamVsUnwanted (D-04): UNWANTED when any attachment/url indicator
  matches or delivery is contained to the reporter(s) only; SPAM otherwise
- classifyCampaign: D-06 simulation short-circuit -> D-03 -> D-04 ->
  computeConfidence -> mapVerdictToActions -> computeRequiresApproval ->
  append-only INSERT into classifications (D-02, no ON CONFLICT), wrapped
  in try/catch logging [CAMPAIGN-CLASSIFIER] + err.message and rethrowing
- isKnownSimulationSender relaxed to a narrower SenderIdentity shape so both
  the full NormalizedMessage fixtures and the bounded ParsedMessage type
  can share it
- All 39 tests green; tsc clean; full `npm test` suite green except 2
  pre-existing, unrelated itglue-search.test.ts failures (see
  deferred-items.md)
2026-07-16 08:20:58 -04:00
3ea6c95e38 feat(19-01): implement classifier pure rule functions (D-05/D-06/D-08)
- KNOWN_SIMULATION_SENDERS allowlist (it-support.care, breachsecurenow.com)
  with domainMatchesAllowlist (exact-or-proper-subdomain, no substring match
  — T-19-01) and isKnownSimulationSender (checks From + Return-Path domain
  — Pitfall 3)
- effectiveAuthResults (authResultsOriginal precedence — Pitfall 1) and
  hasHardAuthFail (spf/dkim/dmarc hard-fail only)
- computeConfidence: additive-from-1.0 with 0.4/0.3/0.2 named deductions,
  floors at 0.10 (D-05)
- mapVerdictToActions + DESTRUCTIVE_ACTIONS + computeRequiresApproval
  (OR'd across actions, D-08/CLASSIFY-02)
- All 30 pure-function tests green; tsc clean
2026-07-16 08:14:57 -04:00