Skip to content

fix(research): drop public load by restricted linkage ref - #187

Draft
cursor[bot] wants to merge 9 commits into
mainfrom
cursor/bc-43b9a267-9080-4e46-94f4-38ee5dd2921b-db96
Draft

cursor[bot] wants to merge 9 commits into
mainfrom
cursor/bc-43b9a267-9080-4e46-94f4-38ee5dd2921b-db96

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Why

PR #175 added a program-scoped public_research_identity load, but load_public_research_release_projection still took a restricted linkage_ref and read research_identity_linkage. A buyer packaging a release who discovered that function was back on the #162 path and still needed SELECT on the restricted table.

TDD

RED required the public-release adapter to omit load_public_research_release_projection and to select only public_research_identity. GREEN deletes the hybrid loader. Authorized callers use load_restricted_identity_linkage plus RestrictedIdentityLinkage::public_release_projection().

Scope

Out of scope

  • Public/admin HTTP, release packaging, Keyverse subjects, actual linkage-key material
  • A PostgreSQL release-fixture role / GRANT boundary (ERD §9 still requires that later)
  • Session start, health transport, response-event persist, and other in-flight PRs
  • Claiming the research-release identifier risk is closed

Test plan

  • cargo test --test research_identity_linkage_contract --lib research_identity_linkage
  • cargo clippy --all-targets -- -D warnings
  • cargo test --test postgres_research_identity_linkage (needs TEST_DATABASE_URL)

Do not merge until exact-head checks and independent last-push approval are satisfied. Never self-approve.

Operator next action

Prefer this head over #175 and #162. Call persist_restricted_identity_linkage inside a READ COMMITTED transaction after minting a program-scoped research identity that is not the operational participant. Load the restricted mapping only for authorized research work. For a public release fixture, call load_public_research_identities_for_program or select public_research_identity. Do not look up a restricted linkage_ref to build a public fixture. Set a distinct research identity when the same person joins a second program.

Open in Web View Automation 

cursoragent and others added 7 commits August 16, 2026 16:02
Keep operational participants out of public research projections while
allowing one person to hold distinct program-scoped research identities.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Add PostgreSQL 18 storage for program-scoped research identities, a
public-release view that cannot carry operational or linkage-key fields,
and fail-closed exact-replay contracts. Record ISO/IEC 20889 and 27559
in doctoring.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Keep traceability, research governance, risk, and ERD pointing at the
opened persistence head instead of an unnamed branch.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A public-release fixture must select only public_research_identity
columns by program. Padded load identities now fail closed instead of
trimming into a restricted lookup.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Prefer the program-scoped public-view load head over #162.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A release fixture that called load_public_research_release_projection still needed SELECT on the restricted linkage table. Authorized callers already have load_restricted_identity_linkage plus public_release_projection(). Public packaging now has only the program-scoped view load.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Prefer this head over #175 and #162. Public packaging loads public_research_identity by program and cannot look up a restricted linkage identity.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review (head a41a91a)

Unique slice versus #175 (fe18dd4...a41a91a) is sound. Do not merge until exact-head required checks and an independent last-push approval land. Do not self-approve. Prefer this head over #175. #162 is closed.

What this head does

load_public_research_release_projection is gone. That function took a restricted linkage_ref and called load_restricted_identity_linkage, so a release fixture still needed SELECT on research_identity_linkage.

Public packaging now has only load_public_research_identities_for_program, which SELECTs research_participant_ref, research_program_ref FROM public_research_identity WHERE research_program_ref = $1. Authorized research still uses load_restricted_identity_linkage plus RestrictedIdentityLinkage::public_release_projection().

Repo-wide search finds no remaining caller of the deleted function. The contract test public_release_adapter_does_not_load_by_restricted_linkage_ref bans the old symbol and asserts the public load does not read research_identity_linkage, linkage_ref, or linkage_key_version.

Docs stay honest: RISK_REGISTER keeps the identifier risk implementation_in_progress. TRACEABILITY/ERD/RESEARCH_GOVERNANCE name Active PR #187 and do not claim the risk is closed.

Residual — keep off this PR

ERD §9 still needs a privilege-separated release-fixture ROLE/GRANT that can SELECT only public_research_identity. Same-owner CI/app connections can still read the restricted table. Do not add that GRANT here. Do not fold session HTTP, response-event persist, or scoring-worker work onto this branch.

Operator next action

Keep this Draft until required checks are green on this exact SHA. Review as seonghobae (already requested). Call persist_restricted_identity_linkage inside a READ COMMITTED transaction after minting a program-scoped research identity that is not the operational participant. For a public release fixture, call load_public_research_identities_for_program or SELECT public_research_identity. Do not look up a restricted linkage_ref to build a public fixture. Set a distinct research identity when the same person joins a second program.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

cursor Bot pushed a commit that referenced this pull request Aug 16, 2026
Keep traceability, risk, and UML pointing at the opened leakage-scan
head. Restricted-linkage persistence stays on #187.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@seonghobae
seonghobae marked this pull request as ready for review August 16, 2026 20:12
@cursor

cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@seonghobae

Copy link
Copy Markdown
Contributor

Hourly loop: exact-head rust failed clean_restore_preserves_provenance_deduplication_and_fencing_state because the processing recovery fixture omitted claim_deadline_at after #81. Merged protected main (ef4774df) onto this head so the fixture seeds clock_timestamp() + INTERVAL '1 hour'. Do not merge until exact-head checks and independent last-push approval succeed. Never self-approve.

Copy link
Copy Markdown
Contributor

Exact-head admission 감사: 1ea088a6c64fcd8c7472846378e9b2e6f280f573; blocker=661 behind/diverged + non-mergeable + terminal Runtime CI failure. Open 상태와 모든 유효 delta/review/thread를 보존한 채 Draft/Proposed로 교정합니다. Causal owner repair 또는 non-force reconciliation 후 fresh exact-head evidence로 재입장해야 합니다. Close·bypass·Force Push·synthetic evidence·review dismissal은 수행하지 않습니다.

@seonghobae
seonghobae marked this pull request as draft September 26, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants