Audit ledger
Verify the chain from live /api/audit/*. Tamper POST exists only on the demo profile; the app role still cannot UPDATE audit.audit_entry.
Tamper beat: boot with
--spring.profiles.active=demo. Default boot 404s POST /api/audit/demo/tamper/{seq}. Tamper asks for confirmation, then the next verify should fail.Reading ledger head…
Head seq
-
Checkpoint
-
CHAIN INTACT
TAMPER DETECTED
Hash predecessor no longer matches. Every later sequence is untrusted until this range verifies.