feat(anonymous): mint session context from current credential - #108
cursor[bot] wants to merge 15 commits into
Conversation
Exercise mixed hex in canonical_sha256_digest and both sides of constant_time_equal so Linux line/branch coverage reaches 100%.
Keep the credential adapter beside the landed account-link module.
A current exact digest must produce the bound anonymous-session context, and expired, wrong, or revoked proofs must stay unauthorized. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Authorized credentials now return the exact AnonymousSessionContext they currently bind, expiring at the earlier of credential expiry or revocation. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Processing consumption rows now require claim_deadline_at after #81. Seed the wall-clock deadline and prove binary restore preserves it.
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
seonghobae
left a comment
There was a problem hiding this comment.
Independent last-push review of exact head e47376e2 (opencode-agent merge of protected main). Required checks opencode-review, noema-review, and coverage-evidence are SUCCESS.
|
@cursor Please perform an independent blocking-defects review of unchanged exact head |
|
You need to increase your spend limit or enable usage-based billing to run background agents. Go to Cursor |
|
@opencode-agent Please perform an independent blocking-defects review of unchanged exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
abandoned, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
abandoned, so required test/docstring evidence was not proven for current heade47376e273245ee5fa0bd91c5e8b9f161a9a237f. -
Head SHA:
e47376e273245ee5fa0bd91c5e8b9f161a9a237f -
Workflow run: 32040162859
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (2 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (2 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Test (2 files)"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test (2 files)"]
R2 --> V2["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage evidence job did not run or did not publish coverage evidence. Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (2 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (2 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Test (2 files)"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test (2 files)"]
R2 --> V2["targeted test run"]
|
|
@opencode-agent Re-evaluate exact unchanged head |
|
Superseded by exact-current-main reconciliation #253 at head #253 carries the same credential-bound anonymous-session authority on the current tree, and its unchanged exact head has completed Runtime CI including exact line/branch coverage, plus Security Scan, SAST Semgrep, SPDX SBOM, and supply-chain provenance successfully. Those checks do not transfer to this stale head, and #253 remains independently review-gated before merge. Closing this stale predecessor rather than rebasing/force-pushing it avoids competing histories. Do not merge #108. |
Why
PR #84 stores short-lived anonymous credential evidence, and PR #86 authorizes an already-built
AnonymousSessionContextagainst one assessment-session resource. A transport could still invent that context without proving the presented digest currently authorizes the stored credential. Buyers cannot start an anonymous session until the hashed proof becomes the exact session context those later checks consume.What
AnonymousCredential::session_contextso a current exact digest mints only the bound anonymous-session context.Unauthorizederror that tells the caller to present a current exact digest for this tenant, participant, and session.Scope / architecture
This continues the existing ADR-0003 anonymous-participation contract. It does not issue bearer secrets, add HTTP, persist credentials, or change Keyverse ownership. It stacks on #84 (
AnonymousCredential) and is the domain input to #86 (authorize_anonymous_session). Canonical documentation remains in the separate reconciliation lane; this implementation is not yet protected-main truth.Verification
cargo test --test anonymous_credential_session_context --test anonymous_credential_lifecyclecargo clippy --all-targets -- -D warningscargo doc --no-deps --document-private-itemsDo not merge before #84. Independent non-author approval and required CI on the unchanged exact head still apply.