# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## AFETCH — Constrain a server-side document fetcher

A fictional knowledge service imports documents from customer-entered URLs. The importer follows redirects and trusts response metadata too broadly.

**Field:** Security. **Suggested stack:** TypeScript, HTTP client, Object storage.

**Engineer value:** Practice defensive URL handling and bounded untrusted-input processing.

**Company value:** Review whether integrations can import content without expanding infrastructure access.

**Delivery agreement:** Ten scoped tickets across three phases. Build a synthetic local service or select a ticket after recreating its prerequisites; estimates exclude setup.

### Setup prerequisites

- Build a local fetch adapter and controlled HTTP test servers.

- Use synthetic documents and deny network access outside the test allowlist.

### Define fetch authority

Constrain URLs, identity and network destinations.

#### AFETCH-101 — Accept only explicitly supported document URL schemes

**Task · Medium priority · Foundational**

noCV practice brief v5 · AFETCH-101 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define fetch authority. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 75 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 70% · API design 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A customer enters a non-HTTP URI that the generic import library attempts to interpret as a local resource.

Acceptance criteria

- Allow HTTPS under an explicit destination policy.

- Reject embedded credentials and unsupported schemes.

- Normalize once and retain a safe display URL.

Implementation constraints

- Use a standard URL parser; do not build one with string prefixes.

Verification

- Accept an approved synthetic HTTPS URL.

- Reject file, data and credential-bearing URLs before network calls.

Deliverables

- URL input policy and parser tests

Rollout and recovery: Enforce validation before import dispatch; quarantine existing unsupported requests.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-102 — Bind document import requests to tenant-owned destination policies

**Task · Medium priority · Intermediate**

noCV practice brief v5 · AFETCH-102 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define fetch authority. Depends on: AFETCH-101.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Backend 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

One tenant configures an approved host and another tenant unexpectedly inherits permission to fetch from it.

Acceptance criteria

- Resolve allowlists within the requesting tenant.

- Require authorization before creating a fetch job.

- Reject unknown policy references without disclosing other tenants' hosts.

Implementation constraints

- Store policy version with the import request.

Verification

- Import through the tenant's approved synthetic host.

- Reuse another tenant's policy ID and verify zero fetch calls.

Deliverables

- Scoped destination-policy service

Rollout and recovery: Deploy tenant resolution before enabling saved policies; disable import on ambiguous ownership.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-103 — Reject private and special-use destination addresses before connection

**Bug · Urgent priority · Advanced**

noCV practice brief v5 · AFETCH-103 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define fetch authority. Depends on: AFETCH-101, AFETCH-102.

Difficulty: Advanced. Estimated focused work: 240 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Networking 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A public-looking hostname resolves to an internal address during import and reaches a service unavailable to the user.

Acceptance criteria

- Apply destination-address policy to every resolved connection target.

- Reject loopback, private and special-use addresses outside explicit local tests.

- Prevent resolver results from changing unchecked before connection.

Implementation constraints

- Use an injected resolver and connection adapter; tests never contact internal services.

Verification

- Resolve an allowed synthetic public address through the fixture adapter.

- Return loopback or changed resolution and verify no connection is opened.

Deliverables

- Resolver-to-connection policy and fixture tests

Rollout and recovery: Run policy checks before enabling network fetches; deny unresolved or ambiguous destinations.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Bound remote work

Apply limits through redirects and response streaming.

#### AFETCH-104 — Revalidate every document redirect before following it

**Bug · High priority · Advanced**

noCV practice brief v5 · AFETCH-104 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bound remote work. Depends on: AFETCH-103.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Networking 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

An approved download host redirects to an unapproved internal URL after the first request passes validation.

Acceptance criteria

- Limit redirect count and validate each target independently.

- Do not forward credentials across origins.

- Reject redirect loops with a stable reason code.

Implementation constraints

- Use local controlled redirect fixtures only.

Verification

- Follow one permitted same-policy redirect.

- Redirect toward an internal fixture address and assert it is blocked before connection.

Deliverables

- Redirect policy and credential-stripping regression

Rollout and recovery: Enable bounded redirect handling; disable redirect support if a client bypasses target validation.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-105 — Enforce byte and time limits while streaming imported documents

**Task · Medium priority · Advanced**

noCV practice brief v5 · AFETCH-105 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bound remote work. Depends on: AFETCH-104.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Performance engineering 40% · Security 30% · Networking 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A response declares a small Content-Length but streams indefinitely, occupying a worker slot.

Acceptance criteria

- Bound actual streamed bytes regardless of headers.

- Enforce connect, idle and overall deadlines.

- Cancel the upstream stream and remove incomplete staging objects on failure.

Implementation constraints

- Choose explicit local test budgets and an injectable clock.

Verification

- Import a document within the declared byte and deadline limits.

- Stream beyond the byte cap or stall and verify cancellation plus cleanup.

Deliverables

- Bounded stream adapter and timeout fixtures

Rollout and recovery: Canary small imports; lower admitted limits while investigating failures.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-106 — Validate document type from bytes before publishing the import

**Task · Medium priority · Intermediate**

noCV practice brief v5 · AFETCH-106 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bound remote work. Depends on: AFETCH-105.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Backend 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A remote server labels an executable-looking payload as text and the importer publishes it under a trusted document type.

Acceptance criteria

- Allow a declared finite set of document formats.

- Check supported signatures and parser outcomes against claimed type.

- Keep mismatched or malformed content quarantined.

Implementation constraints

- Do not execute imported content or trust file extensions.

Verification

- Import valid synthetic text and supported document bytes.

- Mismatch content type and bytes and verify no published object.

Deliverables

- Format gate and mismatch cases

Rollout and recovery: Gate new imports before publication; retain quarantined bytes under restricted retention.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-107 — Make interrupted document fetch retries preserve one import identity

**Story · Medium priority · Expert**

noCV practice brief v5 · AFETCH-107 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bound remote work. Depends on: AFETCH-105, AFETCH-106.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 40% · Security 30% · Backend 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A response drops after storage completes; retry publishes a second document with a different identity.

Acceptance criteria

- Use a stable import command identity and staged object generation.

- Publish at most one completed object per command.

- Changed URL or policy version under the same key conflicts.

Implementation constraints

- Persist publication and completion state atomically.

Verification

- Drop the response after publication and retry to the same import.

- Interrupt a stream and verify its incomplete generation cannot be published.

Deliverables

- Idempotent import completion and fault probe

Rollout and recovery: Canary one synthetic tenant; stop completion and inspect staging generations on inconsistency.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Validate abuse resistance

Reproduce failures and preserve safe diagnostics.

#### AFETCH-108 — Remove query secrets from document-fetch error messages

**Bug · High priority · Foundational**

noCV practice brief v5 · AFETCH-108 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Validate abuse resistance. Depends on: AFETCH-104, AFETCH-107.

Difficulty: Foundational. Estimated focused work: 75 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 50% · Security 50%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A signed download URL appears in an operator error message after a timeout.

Acceptance criteria

- Log safe origin, import ID and failure code only.

- Strip query, fragment and user information from diagnostics.

- Keep provider errors from bypassing the safe projection.

Implementation constraints

- Use fabricated signed URLs in tests.

Verification

- Trace a timeout by import ID.

- Inject secret-like query values into redirect and timeout errors and assert absence.

Deliverables

- Fetch diagnostic sanitizer

Rollout and recovery: Deploy safe diagnostics before broad imports; restrict older error records.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-109 — Build a regression matrix for document-fetch trust-boundary failures

**Chore · Medium priority · Expert**

noCV practice brief v5 · AFETCH-109 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Validate abuse resistance. Depends on: AFETCH-103, AFETCH-104, AFETCH-105, AFETCH-106.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 50% · Quality engineering 30% · Networking 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The fetcher has individual guards, but a client upgrade could bypass a guard only when redirects, DNS and retries combine.

Acceptance criteria

- Cover composed resolver, redirect, size and cancellation cases.

- Assert forbidden connection attempts and publication calls remain zero.

- Record expected failure codes without claiming universal attack coverage.

Implementation constraints

- All network behavior runs through local controlled adapters.

Verification

- Run an allowed redirected import through the complete pipeline.

- Combine redirect with resolution change and oversized body; stop at the earliest applicable guard.

Deliverables

- Adversarial fixture matrix and regression command

Rollout and recovery: Require the matrix for client upgrades; pin the last passing client revision if failures appear.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AFETCH-110 — Document the exception process for a newly requested document host

**Task · Medium priority · Foundational**

noCV practice brief v5 · AFETCH-110 · Constrain a server-side document fetcher

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Validate abuse resistance. Depends on: AFETCH-102, AFETCH-109.

Difficulty: Foundational. Estimated focused work: 90 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Site reliability 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Support wants to unblock a customer's host quickly without permanently disabling destination checks.

Acceptance criteria

- Request a tenant-scoped host and purpose.

- Record policy version, reviewer and expiry for any exception.

- Retain all address, redirect and byte controls.

Implementation constraints

- Use a fictional host; no live allowlist modification is part of this ticket.

Verification

- Review a complete scoped exception example.

- Reject a wildcard destination request that bypasses address policy.

Deliverables

- Host exception template and worked review

Rollout and recovery: Use the template for policy proposals; expire exceptions rather than widening global defaults.

Project prerequisites: Build a local fetch adapter and controlled HTTP test servers. Use synthetic documents and deny network access outside the test allowlist.

Engineer value: Practice defensive URL handling and bounded untrusted-input processing.

Company value: Review whether integrations can import content without expanding infrastructure access.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
