01 / Attack path
How the boundary is crossed
A document-matching child replaces its read-only parent reference with a payment-capable parent in a request payload.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Resolve grants from an integrity-protected store, verify the signed or trusted parent-child relationship and recompute the effective intersection.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
The policy engine trusts caller-supplied ancestry and permits payment outside the real delegation chain.
Keep actual and presented edge identifiers, integrity result, decision and denied payment attempt.
04 / Canonical scope
Why this reference stands alone
Forgery invents an artifact; chain tampering rewires relationships among otherwise real principals or grants.
Protocol or attack trace
Rewired parent edge
Read-only child changes parentGrant pointer to a payment-capable grant belonging to another agent.
Verify issuer-signed parent-child relationship; reject even when both referenced grants exist.
Primary references