Skip to content

feat(anonymous): mint session context from current credential - #108

Closed
cursor[bot] wants to merge 15 commits into
mainfrom
cursor/bc-5ada1092-d769-4a00-b2b9-5789caa32c38-b71f
Closed

cursor[bot] wants to merge 15 commits into
mainfrom
cursor/bc-5ada1092-d769-4a00-b2b9-5789caa32c38-b71f

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Why

PR #84 stores short-lived anonymous credential evidence, and PR #86 authorizes an already-built AnonymousSessionContext against one assessment-session resource. A transport could still invent that context without proving the presented digest currently authorizes the stored credential. Buyers cannot start an anonymous session until the hashed proof becomes the exact session context those later checks consume.

What

  • Add AnonymousCredential::session_context so a current exact digest mints only the bound anonymous-session context.
  • Name this credential as authorization evidence and expire the context at the earlier of credential expiry or recorded revocation.
  • Return a stable Unauthorized error that tells the caller to present a current exact digest for this tenant, participant, and session.
  • Cover success, expiry, wrong digest, wrong tenant, revocation-before-now, and revocation-at-expiry.

Scope / architecture

This continues the existing ADR-0003 anonymous-participation contract. It does not issue bearer secrets, add HTTP, persist credentials, or change Keyverse ownership. It stacks on #84 (AnonymousCredential) and is the domain input to #86 (authorize_anonymous_session). Canonical documentation remains in the separate reconciliation lane; this implementation is not yet protected-main truth.

Verification

  • cargo test --test anonymous_credential_session_context --test anonymous_credential_lifecycle
  • cargo clippy --all-targets -- -D warnings
  • cargo doc --no-deps --document-private-items
  • TDD history: failing contract-test commit, then the implementation commit.

Do not merge before #84. Independent non-author approval and required CI on the unchanged exact head still apply.

Open in Web View Automation 

seonghobae and others added 11 commits August 16, 2026 07:54
Exercise mixed hex in canonical_sha256_digest and both sides of
constant_time_equal so Linux line/branch coverage reaches 100%.
Keep the credential adapter beside the landed account-link module.
A current exact digest must produce the bound anonymous-session context,
and expired, wrong, or revoked proofs must stay unauthorized.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Authorized credentials now return the exact AnonymousSessionContext they
currently bind, expiring at the earlier of credential expiry or revocation.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Processing consumption rows now require claim_deadline_at after #81.
Seed the wall-clock deadline and prove binary restore preserves it.
@seonghobae
seonghobae marked this pull request as ready for review August 16, 2026 22:12
@cursor

cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent last-push review of exact head e47376e2 (opencode-agent merge of protected main). Required checks opencode-review, noema-review, and coverage-evidence are SUCCESS.

Copy link
Copy Markdown
Contributor

@cursor Please perform an independent blocking-defects review of unchanged exact head e47376e273245ee5fa0bd91c5e8b9f161a9a237f. All 33 exact-head checks are terminal-success and there are no unresolved threads. The live last-push rule requires approval from an identity other than seonghobae; do not modify the branch unless you find a real defect.

@cursor

cursor Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

You need to increase your spend limit or enable usage-based billing to run background agents. Go to Cursor

Copy link
Copy Markdown
Contributor

@opencode-agent Please perform an independent blocking-defects review of unchanged exact head e47376e273245ee5fa0bd91c5e8b9f161a9a237f and submit a formal review outcome on that exact head. All required exact-head checks are terminal-success and all review threads are resolved. Do not change the branch unless you find a real defect; if clean, approve it as the independent non-author reviewer required by the live last-push rule.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was abandoned, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was abandoned, so required test/docstring evidence was not proven for current head e47376e273245ee5fa0bd91c5e8b9f161a9a237f.

  • Head SHA: e47376e273245ee5fa0bd91c5e8b9f161a9a237f

  • Workflow run: 32040162859

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test (2 files)"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test (2 files)"]
  R2 --> V2["targeted test run"]
Loading

@opencode-agent

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: e47376e273245ee5fa0bd91c5e8b9f161a9a237f
  • Workflow run: 32040162859
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was abandoned, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was abandoned, so required test/docstring evidence was not proven for current head e47376e273245ee5fa0bd91c5e8b9f161a9a237f.

  • Head SHA: e47376e273245ee5fa0bd91c5e8b9f161a9a237f

  • Workflow run: 32040162859

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test (2 files)"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test (2 files)"]
  R2 --> V2["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor

@opencode-agent Re-evaluate exact unchanged head e47376e273245ee5fa0bd91c5e8b9f161a9a237f against protected main aac99d0b523b8f765846fc6edad834e5cf903ca8. The latest CHANGES_REQUESTED cites an abandoned coverage-evidence invocation, while this exact head has successful coverage-evidence and opencode-review check-runs plus an exact-head independent approval. Treat the abandoned invocation as non-passing but not as proof that the successful exact-head evidence vanished; approve only if current live policy and all findings are satisfied.

Copy link
Copy Markdown
Contributor

Superseded by exact-current-main reconciliation #253 at head 94f620729182baf7afd5138b0e75156d352417ef against protected main 0c695b98f38369db8c80d4f8a54ab1fdb3022716.

#253 carries the same credential-bound anonymous-session authority on the current tree, and its unchanged exact head has completed Runtime CI including exact line/branch coverage, plus Security Scan, SAST Semgrep, SPDX SBOM, and supply-chain provenance successfully. Those checks do not transfer to this stale head, and #253 remains independently review-gated before merge.

Closing this stale predecessor rather than rebasing/force-pushing it avoids competing histories. Do not merge #108.

@seonghobae seonghobae closed this Aug 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants