Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
77b3967
docs: refresh product gap baseline on current main
seonghobae Aug 28, 2026
58ad79d
docs: refresh response ledger gate evidence
seonghobae Aug 28, 2026
ea41929
docs: refresh current CEFR and response gate evidence
seonghobae Aug 28, 2026
19ae6ef
docs: record response coverage repair head
seonghobae Aug 28, 2026
d19a248
docs(gaps): refresh active PR heads
seonghobae Aug 28, 2026
088ca63
docs: refresh active PR gap baseline
seonghobae Aug 28, 2026
f76a042
docs: record exact active PR heads
seonghobae Aug 28, 2026
a646c7f
docs: track latest active PR heads
seonghobae Aug 28, 2026
f185469
docs: track session command transport lane
seonghobae Aug 28, 2026
8eaa8ad
docs: correct session command head
seonghobae Aug 28, 2026
fd39d9c
docs: track latest response ledger head
seonghobae Aug 28, 2026
5e685f1
docs: track item delivery policy head
seonghobae Aug 28, 2026
ec5e180
docs: refresh session command evidence
seonghobae Aug 28, 2026
72acd88
docs: refresh item delivery evidence
seonghobae Aug 28, 2026
8c888f8
docs: refresh response ledger evidence
seonghobae Aug 28, 2026
91acdef
docs: refresh malformed frame evidence
seonghobae Aug 28, 2026
f7e2fbe
docs: refresh scoring evidence
seonghobae Aug 28, 2026
dd011f7
docs: refresh response coverage evidence
seonghobae Aug 28, 2026
8211f75
docs: refresh item policy evidence
seonghobae Aug 28, 2026
15e44e3
docs: track current session command head
seonghobae Aug 28, 2026
257c7f8
docs: track current item-delivery head
seonghobae Aug 28, 2026
ba08c79
docs: track current response HTTP head
seonghobae Aug 28, 2026
710f9a8
docs: track current item-delivery head
seonghobae Aug 28, 2026
80638f4
docs: track current response HTTP head
seonghobae Aug 28, 2026
e1ed695
docs: track current transport heads
seonghobae Aug 28, 2026
d6dfe0f
docs(baseline): record current response transport heads
seonghobae Aug 28, 2026
134f1df
docs: track current response ledger head
seonghobae Aug 28, 2026
8a03ebb
docs: track current session command head
seonghobae Aug 28, 2026
2fd7a3f
docs: refresh active coverage heads
seonghobae Aug 28, 2026
09e296f
docs: refresh session transport head
seonghobae Aug 28, 2026
3787a16
docs: refresh response transport heads
seonghobae Aug 28, 2026
c7eb074
docs: refresh coverage gate baseline
seonghobae Aug 28, 2026
d778864
docs: record exact-head coverage results
seonghobae Aug 28, 2026
e5f2ec7
docs: refresh active PR gate snapshot
seonghobae Aug 28, 2026
e03fbbd
docs: reconcile shipped persistence evidence
seonghobae Aug 28, 2026
9523b31
docs: make identity repair a longitudinal prerequisite
seonghobae Aug 28, 2026
07f017c
docs: refresh session command head evidence
seonghobae Aug 28, 2026
66ec0e7
docs: record longitudinal identity repair head
seonghobae Aug 28, 2026
433b79b
docs: refresh repaired transport heads
seonghobae Aug 28, 2026
06b7309
docs: keep result export transport target-only
seonghobae Aug 28, 2026
565fe56
docs: reconcile protected-main traceability
seonghobae Aug 28, 2026
3cc75c8
docs: keep baseline lane ownership exclusive
seonghobae Aug 28, 2026
7a731d5
docs(baseline): track latest identity test head
seonghobae Aug 28, 2026
368f9e1
docs(baseline): track latest identity test repairs
seonghobae Aug 28, 2026
d2a9c16
docs(baseline): track latest identity coverage head
seonghobae Aug 28, 2026
527ebe1
docs(baseline): track complete replay coverage head
seonghobae Aug 28, 2026
5985235
docs: refresh current PR gate evidence
seonghobae Aug 28, 2026
d9cb1e8
docs: define baseline abbreviations
seonghobae Aug 28, 2026
53b2592
docs: track active research privacy landing
seonghobae Aug 28, 2026
0abc2db
docs: reconcile active research release status
seonghobae Aug 28, 2026
f9b691f
docs: refresh live PR count
seonghobae Aug 28, 2026
9c64428
docs: reconcile traceability evidence sections
seonghobae Aug 28, 2026
ebace78
docs: track session reload authorization remediation
seonghobae Aug 28, 2026
6dd1f87
docs: complete protected module surface map
seonghobae Aug 28, 2026
84f8f9b
docs: track latest session authorization head
seonghobae Aug 28, 2026
d9ee50d
docs: track final session authorization head
seonghobae Aug 28, 2026
5908c89
docs: track session authority contract head
seonghobae Aug 28, 2026
a61ca56
docs: correct session authorization commit reference
seonghobae Aug 28, 2026
495ba8b
Refresh session authorization traceability
seonghobae Aug 28, 2026
a0549ef
Track latest session authorization head
seonghobae Aug 28, 2026
a8bdeae
Reconcile protected-main architecture evidence
seonghobae Aug 28, 2026
12b1530
Reconcile ERD shipped persistence status
seonghobae Aug 28, 2026
00ff5b6
Merge protected main into documentation baseline
seonghobae Sep 2, 2026
324b25f
docs: make README product-first and integration-friendly
seonghobae Sep 2, 2026
642001e
docs: avoid implying a nonexistent security process
seonghobae Sep 2, 2026
dadcde5
docs: link authoritative security reporting policy
seonghobae Sep 2, 2026
cfabe63
docs: reconcile merged integration handoff status
seonghobae Sep 2, 2026
bda8324
docs: reconcile session HTTP ADR with protected main
seonghobae Sep 2, 2026
5ec90d7
docs: reconcile merged transport status in UML
seonghobae Sep 2, 2026
dd95dd5
docs: bind implemented HTTP contracts in traceability
seonghobae Sep 2, 2026
7498c2a
test: bind session HTTP to OpenAPI contract
seonghobae Sep 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
170 changes: 120 additions & 50 deletions README.md

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions docs/RISK_REGISTER.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ This register tracks material product, scientific, privacy, security, operationa
| Hosted runtime returns fallback/invented score during fast-mlsirm outage/scientific failure | critical | medium | mitigated_by_architecture | typed fail-closed scoring contract, durable pending job; end-to-end failure injection required |
| Instrument content changes without version change and historical result becomes unreproducible | critical | low | implementation_in_progress | immutable publication/version contract, content digest, result provenance; persistence constraints pending |
| Session/response race creates duplicate or inconsistent scoring evidence | high | medium | implementation_in_progress | idempotent response ledger + immutable snapshot; real DB concurrency/atomic outbox tests pending |
| Cross-tenant object reference exposes another user's session/result/research/data-rights state | critical | medium | evidence_required | tenant/resource authorization architecture; transport/persistence negative tests pending |
| Cross-tenant object reference exposes another user's session/result/research/data-rights state | critical | medium | implementation_in_progress | result-export authorization is protected-main evidence; session reload remediation is Active PR #438 at `67f4508f85ec3483c1358b8c1db99e4c92ba0727`; transport/persistence negative tests and protected-main refetch remain pending |
| Anonymous-to-account link permits account takeover/history theft | critical | medium | evidence_required | dual proof-of-control + Keyverse validation; adapter and adversarial tests pending |
| Keyverse identity role is confused with product/research authorization | high | medium | mitigated_by_architecture | separate domain authorization and separation-of-duties policy; integration tests pending |
| Research release contains operational/Keyverse/linkage identifier | critical | medium | mitigated_by_architecture | restricted linkage + release validation; adversarial release pipeline pending |
Expand All @@ -42,7 +42,7 @@ This register tracks material product, scientific, privacy, security, operationa
| Factor rotation is marketed as globally optimal/universally best | medium | medium | mitigated_by_architecture | best-observed multi-start + stability/recovery policy; no universal criterion claim |
| Published research/score artifacts mutate in place after correction | high | low | mitigated_by_architecture | content addressing + supersession; physical DB/object-store constraints pending |
| Cross-service direct database access creates hidden coupling/privacy blast radius | high | medium | mitigated_by_architecture | ADR-0001/0015; credential/dependency fitness tests pending |
| Outbox/inbox replay duplicates external release/deletion/scoring side effects | high | medium | evidence_required | transactional outbox/inbox design plus Active PR #264 exact-event publisher-to-fenced-persistence handoff; live worker, crash/recovery, and external side-effect idempotency evidence pending |
| Outbox/inbox replay duplicates external release/deletion/scoring side effects | high | medium | evidence_required | transactional outbox/inbox design plus protected-main exact-event publisher-to-fenced-persistence handoff from merged #264; live worker, crash/recovery, and external side-effect idempotency evidence remain pending |
| Optional dependency outage is reported as total product outage or blocks personal results | medium | medium | mitigated_by_architecture | capability-scoped readiness/degradation; deployment failure tests pending |
| Community profile silently depends on g7/AI/TEPP/portal | high | low | mitigated_by_architecture | ADR-0002/0011 + deployment profile contract; install/end-to-end proof pending |
| OpenAPI/AsyncAPI target docs are published before implementation and mislead integrators | medium | medium | mitigated_by_architecture | ADR-0014 as-built-only contract rule; CI gate pending |
Expand Down
77 changes: 39 additions & 38 deletions docs/TRACEABILITY.md
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.

Large diffs are not rendered by default.

16 changes: 8 additions & 8 deletions docs/adr/0014-api-and-event-contract-representation.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@
- Scope: Psychometrics Commons public/admin HTTP APIs, product-owned durable domain events, errors, schema/version negotiation
- Supersedes: none
- Superseded by: none
- Current/as-built status: persist-backed session create/reload HTTP (`POST /v1/sessions`, `GET /v1/sessions/{session_ref}`, `openapi/sessions.yaml`) exists on Active PR #232 and is not protected-main truth; remaining public/admin families and durable external event transport are still unimplemented on protected main
- Current/as-built status: persist-backed session create/reload HTTP (`POST /v1/sessions`, `GET /v1/sessions/{session_ref}`, `openapi/sessions.yaml`) is protected-main implementation evidence through merged #232; remaining public/admin families and durable external event transport are still incomplete on the evaluated protected-main baseline
- Target status: every implemented HTTP/event surface has an exact versioned machine-readable as-built contract and deterministic integrity/idempotency semantics
- Migration status: no deployed HTTP/event transport requires migration yet; the first implementation must introduce the contract in the same or prerequisite PR
- Migration status: the protected-main session HTTP family ships with its OpenAPI contract and existing session persistence migrations; each additional HTTP/event family must introduce its machine-readable contract in the same or a prerequisite change and add persistence migration only when that family owns new durable state

## Context

Expand Down Expand Up @@ -103,7 +103,7 @@ When durable event transport is implemented, the AsyncAPI/schema artifact must e

## Data and persistence impact

No transport persistence exists yet on protected main. The target logical model requires outbox event identity, tenant/subject binding, schema/canonicalization version, payload digest, delivery attempts, inbox deduplication identity, processing state, side-effect evidence, and quarantine/reconciliation evidence. `docs/architecture/ERD.md` defines the logical target; physical migrations must preserve these semantics when introduced.
Protected main already contains product-owned persistence used by the implemented session HTTP family. Durable external event transport remains incomplete: its target logical model requires outbox event identity, tenant/subject binding, schema/canonicalization version, payload digest, delivery attempts, inbox deduplication identity, processing state, side-effect evidence, and quarantine/reconciliation evidence. `docs/architecture/ERD.md` defines the logical target; physical migrations must preserve these semantics when introduced.

## Invariants

Expand Down Expand Up @@ -153,7 +153,7 @@ Transport/broker choice is deployment-specific, but health and reconciliation mu

## Migration and rollout

The first implemented HTTP transport must introduce its OpenAPI document in the same PR or an accepted prerequisite PR. The first durable event transport must do the same for AsyncAPI plus the canonicalization/digest implementation and persistence constraints.
The session HTTP family satisfied the HTTP side of this ADR by landing its implementation and `openapi/sessions.yaml` together through merged #232. Each later HTTP family must introduce or update its exact OpenAPI contract in the same PR or an accepted prerequisite PR. The first durable event transport must do the same for AsyncAPI plus the canonicalization/digest implementation and persistence constraints.

Contract changes are validated before deployment. During compatibility windows, old and new versions may be served/consumed concurrently only when the implementation has explicit routing/adapter tests.

Expand All @@ -165,7 +165,7 @@ Rollback must restore an application version that still understands any messages
- `docs/architecture/UML.md` must not model receipt as equivalent to externally visible side-effect completion.
- `docs/architecture/SECURITY_AND_DATA.md` must preserve tenant/purpose boundaries for event payloads and quarantine.
- `docs/architecture/DEPLOYMENT_AND_OPERATIONS.md` must include replay/quarantine/recovery evidence when event transport is implemented.
- `docs/TRACEABILITY.md` remains target until as-built OpenAPI/AsyncAPI and transport tests exist.
- `docs/TRACEABILITY.md` must distinguish the protected-main session HTTP family from target or active-PR transport families and bind each implemented family to its exact machine-readable contract.
Comment thread
seonghobae marked this conversation as resolved.

## Validation and release evidence

Expand All @@ -186,7 +186,7 @@ Release gates for an implemented transport include:
- client/consumer compatibility tests for the supported window;
- security tests that verify examples/errors/quarantine evidence do not disclose prohibited data.

Until the transport exists, these are explicit target acceptance requirements rather than fabricated passing evidence.
These are release requirements for the transport families to which they apply; absence of a not-yet-implemented family is not converted into fabricated passing evidence.

## Alternatives considered

Expand Down Expand Up @@ -233,7 +233,7 @@ Costs:

## Follow-up work

- when the first HTTP transport lands, add the exact OpenAPI document and route/problem contract tests;
- keep each implemented HTTP family synchronized with its exact OpenAPI route/problem contract tests;
- when the first durable event transport lands, add AsyncAPI plus canonicalization/digest test vectors and tenant-bound outbox/inbox migrations;
- add consumer crash/replay/quarantine integration tests against the selected persistence/broker adapters;
- link deployment-specific deduplication-retention policy to backup/restore and broker retention evidence.
Expand All @@ -244,7 +244,7 @@ Costs:
- Technical requirements: `docs/TRD.md` API, event, transactional integration, version compatibility, security, and validation sections.
- Architecture: `ARCHITECTURE.md`, `docs/architecture/ERD.md`, `docs/architecture/UML.md`, `docs/architecture/DEPLOYMENT_AND_OPERATIONS.md`.
- Decisions: ADR-0015 for persistence/transaction boundaries.
- Delivery evidence: `docs/TRACEABILITY.md`, `docs/ROADMAP.md`, `tests/documentation_architecture_contract.rs` until as-built transport tests replace documentation-only fitness evidence.
- Delivery evidence: `docs/TRACEABILITY.md`, `docs/ROADMAP.md`, tests for implemented transport contracts, and `tests/documentation_architecture_contract.rs` for documentation fitness.

## Reversal conditions

Expand Down
Loading
Loading