Evidence Grading for OAuth Credential Exposure and Containment: A Retrospective Study of GENESIS Incident 38

Closing an OAuth credential exposure requires several distinct judgments: whether credentials entered source control, whether a refresh path still works, whether application authentication remains available, and whether repository containment has removed exposed values from a specified tree. This retrospective study examines GENESIS incident #38 using local Git objects, a contemporaneous governance record, verifier source, and current provider documentation. The record reports application deletion attested by the founder, rejection of the old refresh path with ACCESS_DENIED, and closure as PROVIDER-NEUTRALIZED and CONTAINMENT-VERIFIED. Repository inspection corroborates removal of three exporter literals and removal of a tracked token file at the containment revision. Direct rejection of the historical access token remains NOT-COVERED. The study also identifies limitations in the historical verifier: its decision logic can accept simulated transport failures as rejection, and its repository scan passes search values in subprocess arguments. These findings constrain the assurance attributable to its terminal verdict without establishing that the recorded provider response was false. The contribution is a claim-specific evidence taxonomy and a bounded verification method that keeps source inspection, reported observation, operator attestation, inference, and non-coverage separate. The case supports a disciplined account of incident closure, not a proof of universal credential invalidation or historical erasure. This is a preprint and has not undergone peer review. The supplement contains sanitized evidence summaries and editable manuscript files; it does not contain raw provider records or the private repository. Author: Christopher Musyoki, GENESIS. This work was self-funded. The author reports no known competing financial or personal interests and discloses affiliation with GENESIS, whose incident is examined. AI assistance is described in the manuscript.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-03
DOI
https://doi.org/10.5281/zenodo.23122759
Primary Topic
Scientific Computing and Data Management
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Evidence Grading for OAuth Credential Exposure and Containment: A Retrospective Study of GENESIS Incident 38

Christopher Musyoki
Zenodo (CERN European Organization for Nuclear Research)
Scientific Computing and Data Management
preprint

Evidence Grading for OAuth Credential Exposure and Containment: A Retrospective Study of GENESIS Incident 38

Christopher Musyoki
preprint en

Abstract

Closing an OAuth credential exposure requires several distinct judgments: whether credentials entered source control, whether a refresh path still works, whether application authentication remains available, and whether repository containment has removed exposed values from a specified tree. This retrospective study examines GENESIS incident #38 using local Git objects, a contemporaneous governance record, verifier source, and current provider documentation. The record reports application deletion attested by the founder, rejection of the old refresh path with ACCESS_DENIED, and closure as PROVIDER-NEUTRALIZED and CONTAINMENT-VERIFIED. Repository inspection corroborates removal of three exporter literals and removal of a tracked token file at the containment revision. Direct rejection of the historical access token remains NOT-COVERED. The study also identifies limitations in the historical verifier: its decision logic can accept simulated transport failures as rejection, and its repository scan passes search values in subprocess arguments. These findings constrain the assurance attributable to its terminal verdict without establishing that the recorded provider response was false. The contribution is a claim-specific evidence taxonomy and a bounded verification method that keeps source inspection, reported observation, operator attestation, inference, and non-coverage separate. The case supports a disciplined account of incident closure, not a proof of universal credential invalidation or historical erasure. This is a preprint and has not undergone peer review. The supplement contains sanitized evidence summaries and editable manuscript files; it does not contain raw provider records or the private repository. Author: Christopher Musyoki, GENESIS. This work was self-funded. The author reports no known competing financial or personal interests and discloses affiliation with GENESIS, whose incident is examined. AI assistance is described in the manuscript.

Zenodo (CERN European Organization for Nuclear Research)
Scientific Computing and Data Management
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Evidence Grading for OAuth Credential Exposure and Containment: A Retrospective Study of GENESIS Incident 38 — Christopher Musyoki · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS