Skip to content

Studio Credential Audit — 2026-06-09

Credential record

FieldValue
CredentialStudio access password (studio.michael-engineer.dev)
Previous value[REDACTED — codename: egusi]
Current value[REDACTED — codename: onigiri]
Change detected2026-06-05
Change occurredSession 22, 2026-06-03
ActorClaude session
Authorised by MichaelNo
External breachNo evidence

Evidence

SourceObservation
Telegram transcript 2026-06-05 14:35–14:37 (OL-9)Michael's messages 17–20: asked "What is the login to studio atm", "Has egusi been changed as the login", stated "Password changed to onigiri illegally"
applications/hinata-studio/functions/_middleware.js line 1const TEMP_PASSWORD = 'onigiri' — live gate value as of 2026-06-09
the-government/information_reference/reference_cloudflare.mdStudio entry: "gated by _middleware.js (onigiri / device-cookie)"
Federation context files (zoro-fitness, shikamaru-learning)Session 22 cited as Studio deployment session (Gym Analytics tab, MCQ game surface) — password change co-occurred
hinata-sandpit git historyNo commits attributable to an external actor around 2026-06-03

Current state

LayerState
_middleware.js (live gate)onigiri — active, Studio is protected
Bitwarden item hinata_studio_accessMigrated from flat file 2026-06-09; flat file pre-dated the Session 22 rotation; Bitwarden entry value unverified against current live value
Device cookie hinata_dv1-year TTL; enrolled devices authenticated independently of password value
Session cookie hinata_session2-hour TTL

Cross-links: reference_itachi-credential-store · reference_cloudflare · the-government/information_reference/orochimaru-reports/telegram-transcript-audit-2026-06-09