fix(research): drop public load by restricted linkage ref - #187
cursor[bot] wants to merge 9 commits into
Conversation
Keep operational participants out of public research projections while allowing one person to hold distinct program-scoped research identities. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Add PostgreSQL 18 storage for program-scoped research identities, a public-release view that cannot carry operational or linkage-key fields, and fail-closed exact-replay contracts. Record ISO/IEC 20889 and 27559 in doctoring. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Keep traceability, research governance, risk, and ERD pointing at the opened persistence head instead of an unnamed branch. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A public-release fixture must select only public_research_identity columns by program. Padded load identities now fail closed instead of trimming into a restricted lookup. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Prefer the program-scoped public-view load head over #162. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A release fixture that called load_public_research_release_projection still needed SELECT on the restricted linkage table. Authorized callers already have load_restricted_identity_linkage plus public_release_projection(). Public packaging now has only the program-scoped view load. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
There was a problem hiding this comment.
Review (head a41a91a)
Unique slice versus #175 (fe18dd4...a41a91a) is sound. Do not merge until exact-head required checks and an independent last-push approval land. Do not self-approve. Prefer this head over #175. #162 is closed.
What this head does
load_public_research_release_projection is gone. That function took a restricted linkage_ref and called load_restricted_identity_linkage, so a release fixture still needed SELECT on research_identity_linkage.
Public packaging now has only load_public_research_identities_for_program, which SELECTs research_participant_ref, research_program_ref FROM public_research_identity WHERE research_program_ref = $1. Authorized research still uses load_restricted_identity_linkage plus RestrictedIdentityLinkage::public_release_projection().
Repo-wide search finds no remaining caller of the deleted function. The contract test public_release_adapter_does_not_load_by_restricted_linkage_ref bans the old symbol and asserts the public load does not read research_identity_linkage, linkage_ref, or linkage_key_version.
Docs stay honest: RISK_REGISTER keeps the identifier risk implementation_in_progress. TRACEABILITY/ERD/RESEARCH_GOVERNANCE name Active PR #187 and do not claim the risk is closed.
Residual — keep off this PR
ERD §9 still needs a privilege-separated release-fixture ROLE/GRANT that can SELECT only public_research_identity. Same-owner CI/app connections can still read the restricted table. Do not add that GRANT here. Do not fold session HTTP, response-event persist, or scoring-worker work onto this branch.
Operator next action
Keep this Draft until required checks are green on this exact SHA. Review as seonghobae (already requested). Call persist_restricted_identity_linkage inside a READ COMMITTED transaction after minting a program-scoped research identity that is not the operational participant. For a public release fixture, call load_public_research_identities_for_program or SELECT public_research_identity. Do not look up a restricted linkage_ref to build a public fixture. Set a distinct research identity when the same person joins a second program.
Sent by Cursor Automation: Fix Issues
Keep traceability, risk, and UML pointing at the opened leakage-scan head. Restricted-linkage persistence stays on #187. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
…80-4e46-94f4-38ee5dd2921b-db96
|
Hourly loop: exact-head rust failed |
|
Exact-head admission 감사: |


Why
PR #175 added a program-scoped
public_research_identityload, butload_public_research_release_projectionstill took a restrictedlinkage_refand readresearch_identity_linkage. A buyer packaging a release who discovered that function was back on the #162 path and still needed SELECT on the restricted table.TDD
RED required the public-release adapter to omit
load_public_research_release_projectionand to select onlypublic_research_identity. GREEN deletes the hybrid loader. Authorized callers useload_restricted_identity_linkageplusRestrictedIdentityLinkage::public_release_projection().Scope
load_public_research_identities_for_program.Out of scope
Test plan
cargo test --test research_identity_linkage_contract --lib research_identity_linkagecargo clippy --all-targets -- -D warningscargo test --test postgres_research_identity_linkage(needsTEST_DATABASE_URL)Do not merge until exact-head checks and independent last-push approval are satisfied. Never self-approve.
Operator next action
Prefer this head over #175 and #162. Call
persist_restricted_identity_linkageinside aREAD COMMITTEDtransaction after minting a program-scoped research identity that is not the operational participant. Load the restricted mapping only for authorized research work. For a public release fixture, callload_public_research_identities_for_programor selectpublic_research_identity. Do not look up a restrictedlinkage_refto build a public fixture. Set a distinct research identity when the same person joins a second program.