fix(auth): drop closed #158 persist landing and loaded names - #225
Conversation
Record the opened successor so architecture views do not leave the command-auth honesty slice labeled as closed #159. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
There was a problem hiding this comment.
Verdict
Unique honesty claim is SOUND. Prefer this head over #159, #144, #135, #118, #104, and #86.
Unique claim checked
- Closed #158 is restore-reconcile (
feat(identity): rebuild current projections after restore), superseded by #178, notassessment_participantpersist/reload. Naming it as the persist landing was a buyer-facing false green. - #147 / #133 / #114 / #124 are correctly forbidden as current persist landings.
- Persist/reload of
assessment_participantremains Target on this head. There is still no open persist/reload vehicle. - Append-only identity-link history persist remains open #52 (
feat/identity-link-persistence-20260813@a99a900). That is a different slice. - Command tests and locals say
supplied, not_loaded_. authorize_anonymous_session_command/apply_anonymous_session_commandcompare the verified actor to suppliedParticipantRecord+AssessmentSession. They do not accept a caller-builtResourceScope. They do not prove store load. Authorization failure leaves the session unmutated. Tenant is classified before ownership.
Local exact-head verification on f2774fe:
anonymous_resource_authorization: 7 passedanonymous_session_command_authorization: 15 passeddocumentation_architecture_contract: 10 passedtraceability_active_pr_contract: 1 passed
Residual (not this slice)
- TRACEABILITY on this head and on
origin/mainstill names merged #76 as Active PR / not protected-main truth.migrations/0018_data_rights_processing_start.sqlandsrc/postgres_data_rights_processing.rsare already on protected main. Repair that pointer on a docs/rebaseline vehicle, not here. - Competing open #159 still names #158 as the persist landing. Do not merge #159.
AssessmentSessionhas no tenant field; the command gate can only classify tenant from the supplied participant. That stays honest until persist/reload exists.
Merge gates
Independent non-author approval and required checks on the unchanged exact head remain merge gates. This review is COMMENT because GitHub rejects APPROVE on cursor[bot] PRs. Do not self-approve.
Operator next action
Review the Target persist pointer and supplied-record names. After this lands, keep identity-link history on #52. Do not start HTTP or assessment_participant persist on this branch. Open a dedicated persist/reload vehicle from protected main. Do not merge #159.
Sent by Cursor Automation: Fix Issues
|
Pushed the #81 recovery fixture: processing restore rows now seed |
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
a92c42e to
e5d6cd7
Compare
Record the opened successor so architecture views do not leave the command-auth honesty slice labeled as closed #159. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
seonghobae
left a comment
There was a problem hiding this comment.
Independent last-push review of exact head e5d6cd78.
Honesty slice is sound: command authorization compares the verified actor to supplied ParticipantRecord + AssessmentSession, does not accept a caller-built ResourceScope, and does not claim store load. Tenant is classified before ownership. Closed #158/#147/#133/#114/#124 are correctly forbidden as persist landings. Persist/reload remains Target; identity-link history stays on #52.
Runtime CI, line/branch coverage, coverage-evidence, Semgrep, Trivy, OSV, Scorecard, SBOM are SUCCESS. Residual: required noema-review failed with an installation-token exit (infra, not a product defect) and CodeQL Analyze (python) failed on this head. Merge only after those required checks go green. Prefer this head over #159.
e5d6cd7 to
3495145
Compare
Record the opened successor so architecture views do not leave the command-auth honesty slice labeled as closed #159. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
After rebasing onto 0c695b9, exclusive outbox leases, observation clocks/membership, and claim-next scoring-job poll are protected-main truth. Keep #225 as the Active PR for supplied-record anonymous command authorization. Persist/reload of assessment_participant remains Target. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
|
Rebased onto current protected main Docs/module-list conflicts kept Previous exact-head approval and checks on |
Derive the assessment-session resource from the stored participant tenant and the loaded session so a transport cannot invent a matching scope and then command a different session. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Keep the loaded session unchanged when the proof is expired or names a different session, and still fail closed on illegal lifecycle transitions. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Compare the verified actor to the loaded participant tenant and session instead of rebuilding a ResourceScope. Tenant mismatch is reported before ownership so a foreign-tenant inconsistent pair cannot hide as OwnerMismatch. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Store tenant, participant reference, anonymous status, and creation time so command authorization can load the participant instead of rebuilding it from the proof. Exact replay is idempotent; tenant or time rebinding fails closed; linked participants stay out of this slice. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Record the opened successor so architecture views do not leave the assessment-participant slice unlabeled. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
history on migration 0021. This successor keeps the #104 command-auth contract fix and does not open a colliding anonymous-only persist slice. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Command authorization compares the verified actor to supplied participant and session values. It does not accept a ResourceScope and does not claim those aggregates were store-loaded. Align rustdoc, ADR-0003, SECURITY_AND_DATA, UML Activate, TRACEABILITY, and CHANGELOG. Use a session created after publication and before exclusive proof expiry. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Backtick the publication and exclusive-expiry instants in the command authorization fixtures, and name honesty successor #135 in TRACEABILITY. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Point command-authorization honesty at the opened successor so reviewers do not treat #135 as the landing head. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
The command gate still compares supplied records. Docs and the architecture contract now name Active PR #147 for persist/reload, forbid the leftover #133 pointer, and stop saying the gate authorized from loaded records. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Name persist/reload as Target, forbid the closed pointer, and call command-test records supplied. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Record the opened successor so architecture views do not leave the command-auth honesty slice labeled as closed #159. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Preserve account-link and anonymous-credential modules beside the session-command authorization entry point so this honesty head stays mergeable without claiming participant persist on this branch. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
After rebasing onto 0c695b9, exclusive outbox leases, observation clocks/membership, and claim-next scoring-job poll are protected-main truth. Keep #225 as the Active PR for supplied-record anonymous command authorization. Persist/reload of assessment_participant remains Target. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
3495145 to
60bc5fc
Compare
seonghobae
left a comment
There was a problem hiding this comment.
Independent last-push review of exact head 60bc5fc1644d2ba4425ea800e6d504776caea8f3 after rebase onto db9b3075.
Honesty slice holds: command authorization compares the verified actor to supplied ParticipantRecord + AssessmentSession, does not accept a caller-built ResourceScope, and does not claim store load. Closed #158/#147/#133/#114/#124 stay forbidden as persist landings. Persist/reload remains Target; identity-link history stays on #52.
Product CI on this SHA is green: format/lint/test/rustdoc, line+branch coverage, coverage-evidence, Strix, Semgrep, Trivy, OSV, Scorecard, Noema. Prefer this head over #159.
Protected main moved to 5dd52d4 after #225. Record item-delivery, result/response snapshots, narrative fallback, credential, supplied-record command authorization, outbox-lease persist, observation clocks/membership, claim-next scoring-job poll, and persist-backed session HTTP as shipped. Persist/reload of assessment_participant remains Target. Remaining persist and operator-health HTTP slices stay Active PR. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Rebase onto 5dd52d4 must not keep claim-next, observation-time ingest, persist-backed session HTTP, or supplied-record anonymous command authorization as Active PR work. Keep #242 append-only audit evidence explicitly segregated. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>


Why
PR #159 froze closed restore-reconcile #158 as the current
assessment_participantpersist/reload landing and leftloadedin command-test names. #158 is not participant persist. #147 / #133 / #114 / #124 are also closed. There is no openassessment_participantpersist/reload vehicle.What
documentation_architecture_contractsay persist/reload remains Target and forbid leftover#158/#147/#133/#114current-landing claims.supplied, notloaded.Architecture / scope
Successor to #159 on the anonymous command-authorization head. This PR does not add HTTP transport,
assessment_participantpersist, account-link write, orresponse_eventpersist.Verification
cargo test --test documentation_architecture_contract --test anonymous_session_command_authorization --test anonymous_resource_authorization --test traceability_active_pr_contractcargo clippy --all-targets -- -D warningscargo fmt --all -- --checkIndependent non-author approval and required checks on the unchanged exact head remain merge gates. Never self-approve.
Prefer this head over #159, #144, #135, #118, and #104.
Operator next action
Review the Target persist pointer and supplied-record names. After this lands, keep identity-link history on #52. Do not start HTTP or
assessment_participantpersist on this branch.