Skip to content

fix(auth): drop closed #158 persist landing and loaded names - #225

Merged
seonghobae merged 23 commits into
mainfrom
cursor/bc-baa48e1b-c52f-4ef5-b313-3b0acef7f4b6-7080
Aug 18, 2026
Merged

seonghobae merged 23 commits into
mainfrom
cursor/bc-baa48e1b-c52f-4ef5-b313-3b0acef7f4b6-7080

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Why

PR #159 froze closed restore-reconcile #158 as the current assessment_participant persist/reload landing and left loaded in command-test names. #158 is not participant persist. #147 / #133 / #114 / #124 are also closed. There is no open assessment_participant persist/reload vehicle.

What

  • Docs, rustdoc, CHANGELOG, and documentation_architecture_contract say persist/reload remains Target and forbid leftover #158 / #147 / #133 / #114 current-landing claims.
  • Command-test names and locals say supplied, not loaded.
  • TRACEABILITY names append-only identity-link history persist as Active PR feat(participant): persist append-only identity-link history #52, a different slice.

Architecture / scope

Successor to #159 on the anonymous command-authorization head. This PR does not add HTTP transport, assessment_participant persist, account-link write, or response_event persist.

Verification

  • cargo test --test documentation_architecture_contract --test anonymous_session_command_authorization --test anonymous_resource_authorization --test traceability_active_pr_contract
  • cargo clippy --all-targets -- -D warnings
  • cargo fmt --all -- --check

Independent non-author approval and required checks on the unchanged exact head remain merge gates. Never self-approve.

Prefer this head over #159, #144, #135, #118, and #104.

Operator next action

Review the Target persist pointer and supplied-record names. After this lands, keep identity-link history on #52. Do not start HTTP or assessment_participant persist on this branch.

Open in Web View Automation 

@cursor
cursor Bot requested a review from seonghobae August 16, 2026 16:49
cursor Bot pushed a commit that referenced this pull request Aug 16, 2026
Record the opened successor so architecture views do not leave the
command-auth honesty slice labeled as closed #159.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review August 16, 2026 16:50

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

Unique honesty claim is SOUND. Prefer this head over #159, #144, #135, #118, #104, and #86.

Unique claim checked

  • Closed #158 is restore-reconcile (feat(identity): rebuild current projections after restore), superseded by #178, not assessment_participant persist/reload. Naming it as the persist landing was a buyer-facing false green.
  • #147 / #133 / #114 / #124 are correctly forbidden as current persist landings.
  • Persist/reload of assessment_participant remains Target on this head. There is still no open persist/reload vehicle.
  • Append-only identity-link history persist remains open #52 (feat/identity-link-persistence-20260813 @ a99a900). That is a different slice.
  • Command tests and locals say supplied, not _loaded_.
  • authorize_anonymous_session_command / apply_anonymous_session_command compare the verified actor to supplied ParticipantRecord + AssessmentSession. They do not accept a caller-built ResourceScope. They do not prove store load. Authorization failure leaves the session unmutated. Tenant is classified before ownership.

Local exact-head verification on f2774fe:

  • anonymous_resource_authorization: 7 passed
  • anonymous_session_command_authorization: 15 passed
  • documentation_architecture_contract: 10 passed
  • traceability_active_pr_contract: 1 passed

Residual (not this slice)

  • TRACEABILITY on this head and on origin/main still names merged #76 as Active PR / not protected-main truth. migrations/0018_data_rights_processing_start.sql and src/postgres_data_rights_processing.rs are already on protected main. Repair that pointer on a docs/rebaseline vehicle, not here.
  • Competing open #159 still names #158 as the persist landing. Do not merge #159.
  • AssessmentSession has no tenant field; the command gate can only classify tenant from the supplied participant. That stays honest until persist/reload exists.

Merge gates

Independent non-author approval and required checks on the unchanged exact head remain merge gates. This review is COMMENT because GitHub rejects APPROVE on cursor[bot] PRs. Do not self-approve.

Operator next action

Review the Target persist pointer and supplied-record names. After this lands, keep identity-link history on #52. Do not start HTTP or assessment_participant persist on this branch. Open a dedicated persist/reload vehicle from protected main. Do not merge #159.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

@seonghobae

Copy link
Copy Markdown
Contributor

Pushed the #81 recovery fixture: processing restore rows now seed claim_deadline_at, and COPY must keep the exact source deadline. This unblocks integration_consumption_claim_deadline_shape. Do not merge until exact-head checks and independent last-push approval succeed. Never self-approve.

@cursor

cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@cursor
cursor Bot force-pushed the cursor/bc-baa48e1b-c52f-4ef5-b313-3b0acef7f4b6-7080 branch from a92c42e to e5d6cd7 Compare August 17, 2026 16:57
cursor Bot pushed a commit that referenced this pull request Aug 17, 2026
Record the opened successor so architecture views do not leave the
command-auth honesty slice labeled as closed #159.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
seonghobae
seonghobae previously approved these changes Aug 17, 2026

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent last-push review of exact head e5d6cd78.

Honesty slice is sound: command authorization compares the verified actor to supplied ParticipantRecord + AssessmentSession, does not accept a caller-built ResourceScope, and does not claim store load. Tenant is classified before ownership. Closed #158/#147/#133/#114/#124 are correctly forbidden as persist landings. Persist/reload remains Target; identity-link history stays on #52.

Runtime CI, line/branch coverage, coverage-evidence, Semgrep, Trivy, OSV, Scorecard, SBOM are SUCCESS. Residual: required noema-review failed with an installation-token exit (infra, not a product defect) and CodeQL Analyze (python) failed on this head. Merge only after those required checks go green. Prefer this head over #159.

@cursor
cursor Bot force-pushed the cursor/bc-baa48e1b-c52f-4ef5-b313-3b0acef7f4b6-7080 branch from e5d6cd7 to 3495145 Compare August 17, 2026 23:18
cursor Bot pushed a commit that referenced this pull request Aug 17, 2026
Record the opened successor so architecture views do not leave the
command-auth honesty slice labeled as closed #159.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
cursor Bot pushed a commit that referenced this pull request Aug 17, 2026
After rebasing onto 0c695b9, exclusive outbox leases, observation
clocks/membership, and claim-next scoring-job poll are protected-main
truth. Keep #225 as the Active PR for supplied-record anonymous
command authorization. Persist/reload of assessment_participant
remains Target.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@seonghobae

Copy link
Copy Markdown
Contributor

Rebased onto current protected main 0c695b98f38369db8c80d4f8a54ab1fdb3022716 after #228. New head: 34951456680ef09620a0636c3342c01b82292d25.

Docs/module-list conflicts kept #228/#235 as shipped and left persist/reload as Target. No product-logic change to bypass Noema installation-token or CodeQL Python infra.

Previous exact-head approval and checks on e5d6cd78 do not transfer. Exact-head CI plus independent last-push approval are still required. Never self-approve.

seonghobae and others added 14 commits August 18, 2026 00:08
Derive the assessment-session resource from the stored participant tenant
and the loaded session so a transport cannot invent a matching scope and
then command a different session.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Keep the loaded session unchanged when the proof is expired or names a
different session, and still fail closed on illegal lifecycle transitions.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Compare the verified actor to the loaded participant tenant and session
instead of rebuilding a ResourceScope. Tenant mismatch is reported before
ownership so a foreign-tenant inconsistent pair cannot hide as OwnerMismatch.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Store tenant, participant reference, anonymous status, and creation time
so command authorization can load the participant instead of rebuilding
it from the proof. Exact replay is idempotent; tenant or time rebinding
fails closed; linked participants stay out of this slice.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Record the opened successor so architecture views do not leave the
assessment-participant slice unlabeled.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
history on migration 0021. This successor keeps the #104 command-auth
contract fix and does not open a colliding anonymous-only persist slice.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Command authorization compares the verified actor to supplied
participant and session values. It does not accept a ResourceScope and
does not claim those aggregates were store-loaded. Align rustdoc, ADR-0003,
SECURITY_AND_DATA, UML Activate, TRACEABILITY, and CHANGELOG. Use a
session created after publication and before exclusive proof expiry.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Backtick the publication and exclusive-expiry instants in the command
authorization fixtures, and name honesty successor #135 in TRACEABILITY.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
cursoragent and others added 9 commits August 18, 2026 00:13
and named superseded #114 as the persist landing. The gate compares
supplied records only; persist/reload remains Active PR #133.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Point command-authorization honesty at the opened successor so
reviewers do not treat #135 as the landing head.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
The command gate still compares supplied records. Docs and the
architecture contract now name Active PR #147 for persist/reload,
forbid the leftover #133 pointer, and stop saying the gate authorized
from loaded records.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Identity persist/reload landing moved to #158. Keep the command gate
honest about supplied records and stop pinning the leftover #147 pointer.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Name persist/reload as Target, forbid the closed pointer, and call
command-test records supplied.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Record the opened successor so architecture views do not leave the
command-auth honesty slice labeled as closed #159.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Preserve account-link and anonymous-credential modules beside the
session-command authorization entry point so this honesty head stays
mergeable without claiming participant persist on this branch.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
After rebasing onto 0c695b9, exclusive outbox leases, observation
clocks/membership, and claim-next scoring-job poll are protected-main
truth. Keep #225 as the Active PR for supplied-record anonymous
command authorization. Persist/reload of assessment_participant
remains Target.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@cursor
cursor Bot force-pushed the cursor/bc-baa48e1b-c52f-4ef5-b313-3b0acef7f4b6-7080 branch from 3495145 to 60bc5fc Compare August 18, 2026 00:14

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent last-push review of exact head 60bc5fc1644d2ba4425ea800e6d504776caea8f3 after rebase onto db9b3075.

Honesty slice holds: command authorization compares the verified actor to supplied ParticipantRecord + AssessmentSession, does not accept a caller-built ResourceScope, and does not claim store load. Closed #158/#147/#133/#114/#124 stay forbidden as persist landings. Persist/reload remains Target; identity-link history stays on #52.

Product CI on this SHA is green: format/lint/test/rustdoc, line+branch coverage, coverage-evidence, Strix, Semgrep, Trivy, OSV, Scorecard, Noema. Prefer this head over #159.

@seonghobae
seonghobae merged commit 5dd52d4 into main Aug 18, 2026
33 checks passed
cursor Bot pushed a commit that referenced this pull request Aug 18, 2026
Protected main moved to 5dd52d4 after #225. Record item-delivery,
result/response snapshots, narrative fallback, credential,
supplied-record command authorization, outbox-lease persist,
observation clocks/membership, claim-next scoring-job poll, and
persist-backed session HTTP as shipped. Persist/reload of
assessment_participant remains Target. Remaining persist and
operator-health HTTP slices stay Active PR.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
cursor Bot pushed a commit that referenced this pull request Aug 18, 2026
Rebase onto 5dd52d4 must not keep claim-next, observation-time ingest,
persist-backed session HTTP, or supplied-record anonymous command
authorization as Active PR work. Keep #242 append-only audit evidence
explicitly segregated.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants