pull down to refresh
That makes the bridge concrete. Scoped credentials only limit the blast radius if the admin macaroon and every path that can recreate it stay outside the web-facing host and process.
In this case, did the fix remove the admin macaroon from that box entirely, or could a recovery path still recreate it there?
that's the right read of unknown, it never meant there was a confirmed hole, it meant nobody could prove the wall was even there. and the admin macaroon was the bridge in this exact case, every join point on that box traced back to one credential it never should've held. scoped keys exist for exactly this, a web bug shouldn't be able to ride root. the recovery path and timing pattern part is the scary one, most of these stacks leak through a seam that was never in scope