Repository navigation
docs(arch): split contribution policy AUTH registration #331
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,122 @@ | ||
| # Chunk Contract: WS-ARCH-001-CP01A — AUTH Adapter-Binding Registration | ||
|
|
||
| ## Parent initiative | ||
|
|
||
| WS-ARCH-001 — Modular Monolith Boundaries | ||
|
|
||
| ## Goal | ||
|
|
||
| Register the exact adapter-binding authorization contract while every new | ||
| action remains planned and unavailable. | ||
|
|
||
| ## Why this chunk exists | ||
|
|
||
| CON CP02 cannot implement hidden binding behavior against invented identifiers | ||
| or an untyped AUTH seam. This chunk reserves only the four operations CP02 | ||
| needs. Dependency-aware retirement remains later; fulfillment, callbacks, and | ||
| delivery are separate security boundaries. | ||
|
|
||
| ## Approved plan reference | ||
|
|
||
| - INTENT: `.agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/INTENT.md` | ||
| - PLAN: `.agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/PLAN.md` | ||
| - CHUNK_MAP: `.agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/CHUNK_MAP.md` | ||
|
|
||
| ## Risk class | ||
|
|
||
| L1 | ||
|
|
||
| ## SLA | ||
|
|
||
| P1 | ||
|
|
||
| ## Allowed files | ||
|
|
||
| ```text | ||
| backend/app/modules/authorization/catalogue.py | ||
| backend/app/modules/authorization/api/__init__.py | ||
| backend/app/modules/authorization/api/action_ids.py | ||
| backend/app/modules/authorization/api/adapter_bindings.py | ||
| backend/tests/authorization/test_adapter_binding_registration.py | ||
| .agent-loop/CURRENT_STATE.md | ||
| .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/{CHUNK_MAP.md,STATUS.md} | ||
| .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/chunks/WS-ARCH-001-CP01A-auth-adapter-binding-registration.md | ||
| .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/reviews/WS-ARCH-001-CP01A-*.md | ||
| .agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/{CHUNK_MAP.md,STATUS.md} | ||
| ``` | ||
|
|
||
| ## Not allowed | ||
|
|
||
| ```text | ||
| CON application/model/repository/route changes | ||
| database migrations or persisted service rows | ||
| evaluators, grants, service identities, fixed-service matrix rows, or activation | ||
| compensation.adapter_binding.retire | ||
| fulfillment, callback, dispatcher, award, TASK, REV, or delivery authority | ||
| generic resource dictionaries or a second prepared-authorization protocol | ||
| compatibility aliases or non-canonical policy naming | ||
| ``` | ||
|
|
||
| ## Exact registration manifest | ||
|
|
||
| | ActionId | PermissionId | Context | | ||
| |---|---|---| | ||
| | `compensation.adapter_binding.read` | `compensation.adapter_binding.manage` | exact project and binding identity | | ||
| | `compensation.adapter_binding.create` | `compensation.adapter_binding.manage` | exact project, instrument, unit, adapter actor, and non-secret route facts | | ||
| | `compensation.adapter_binding.suspend` | `compensation.adapter_binding.manage` | exact project and active binding identity | | ||
| | `compensation.adapter_binding.resume` | `compensation.adapter_binding.manage` | exact project and suspended binding identity | | ||
|
|
||
| ## Acceptance criteria | ||
|
|
||
| - [ ] Four closed ActionIds map only to existing | ||
| `compensation.adapter_binding.manage` under CP01A custody. | ||
| - [ ] All four definitions remain `PLANNED`; no evaluator, identity, grant, | ||
| matrix row, route, or product behavior can use them. | ||
| - [ ] AUTH public API exposes typed immutable query/mutation fact models and | ||
| canonical resource-digest helpers without importing CON internals. | ||
| - [ ] Mutation facts can be carried by the existing opaque PREP port; no handle | ||
| construction, serialization, consumption, or runtime evaluator is added. | ||
| - [ ] Independent tests prove identifier spelling, permission/owner mapping, | ||
| typed fact validation and digest domain separation, catalogue/API parity, | ||
| and planned denial. | ||
| - [ ] Retirement/callback/fulfillment identifiers are absent. | ||
|
Comment on lines
+60
to
+82
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
rg -n -C 3 \
'compensation\.adapter_binding\.(read|create|suspend|resume)|compensation\.adapter_binding\.manage|PLANNED|ActionOwner' \
backend/app/modules/authorization backend/tests/authorizationRepository: Flow-Research/workstream Length of output: 50380 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== candidate authorization files =='
git ls-files | rg '(^|/)(authorization|auth)(/|\.|$)|catalogue|adapter_binding' | head -200
echo '== exact compensation adapter-binding references =='
rg -n -C 2 --glob '!*.lock' \
'compensation\.adapter_binding\.(read|create|suspend|resume|manage)|ADAPTER_BINDING|adapter_binding' \
backend/app/modules/authorization backend/tests/authorization .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries 2>/dev/null | head -400
echo '== ActionId and planned metadata slices =='
sed -n '1,125p' backend/app/modules/authorization/catalogue.py
sed -n '245,310p' backend/app/modules/authorization/catalogue.py
sed -n '860,930p' backend/app/modules/authorization/catalogue.py
sed -n '1035,1080p' backend/app/modules/authorization/catalogue.py
echo '== API/resource context candidates =='
rg -n -C 2 \
'resource.?context|ResourceContext|adapter.?binding|digest|opaque|PREP|fact model|Fact' \
backend/app/modules/authorization backend/tests/authorization 2>/dev/null | head -500
echo '== lifecycle and alias exclusions across tracked files =='
rg -n -i \
'compensation\.adapter_binding|adapter[_ .-]?binding.*(retir|fulfill|callback|alias)|(retir|fulfill|callback|alias).*adapter[_ .-]?binding' \
--glob '!*.lock' . | head -500Repository: Flow-Research/workstream Length of output: 50381 🏁 Script executed: #!/bin/bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
import re
targets = [
"compensation.adapter_binding.read",
"compensation.adapter_binding.create",
"compensation.adapter_binding.suspend",
"compensation.adapter_binding.resume",
"compensation.adapter_binding.manage",
]
roots = [Path("backend/app/modules/authorization"), Path("backend/tests/authorization")]
files = [p for root in roots if root.exists() for p in root.rglob("*") if p.is_file()]
for target in targets:
hits = []
for path in files:
text = path.read_text(errors="replace")
for i, line in enumerate(text.splitlines(), 1):
if target in line:
hits.append(f"{path}:{i}:{line.strip()}")
print(f"TARGET {target}")
print("\n".join(hits) if hits else "(no matches)")
print("== catalogue enum/definition/planned slices ==")
catalogue = Path("backend/app/modules/authorization/catalogue.py")
if catalogue.exists():
lines = catalogue.read_text(errors="replace").splitlines()
for i, line in enumerate(lines, 1):
if any(x in line for x in (
"COMPENSATION_ADAPTER_BINDING",
"ADAPTER_BINDING",
"FUTURE_INTENT_REQUIRED_ACTIONS",
"ActionId(",
"_planned(",
"_active(",
)):
if 1 <= i <= len(lines):
print(f"{i}:{line}")
PY
echo '== all tracked references, focused =='
rg -n -i --glob '!*.lock' \
'compensation\.adapter_binding\.(read|create|suspend|resume|manage)|adapter[_ .-]?binding' \
. | head -600Repository: Flow-Research/workstream Length of output: 50381 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== exact catalogue declarations and definitions =='
rg -n \
'COMPENSATION_ADAPTER_BINDING|compensation\.adapter_binding' \
backend/app/modules/authorization/catalogue.py backend/tests/authorization 2>/dev/null || true
echo '== nearby enum declarations =='
sed -n '1,90p' backend/app/modules/authorization/catalogue.py
sed -n '200,245p' backend/app/modules/authorization/catalogue.py
echo '== all tracked exact action IDs =='
for id in read create suspend resume; do
printf '%s: ' "$id"
git grep -n -F "compensation.adapter_binding.$id" -- ':!*.lock' 2>/dev/null || true
done
echo '== relevant ownership and planned-action sets =='
rg -n -C 4 \
'CP01A|ARCH_001|FUTURE_INTENT_REQUIRED_ACTIONS|ActionAvailability\.PLANNED|COMPENSATION_' \
backend/app/modules/authorization/catalogue.py backend/tests/authorization 2>/dev/null | head -300Repository: Flow-Research/workstream Length of output: 16942 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== ActionId enum and action-definition region =='
sed -n '95,235p' backend/app/modules/authorization/catalogue.py
sed -n '285,770p' backend/app/modules/authorization/catalogue.py | rg -n -C 2 \
'COMPENSATION|ADAPTER|compensation|adapter|_planned|_active|ActionOwner'
echo '== AUTH source/test file list =='
git ls-files backend/app/modules/authorization backend/tests/authorization
echo '== focused AUTH source references =='
rg -n -i \
'adapter.?binding|resource.?context|digest|opaque|mutation.?fact|callback|fulfillment|retir|alias' \
backend/app/modules/authorization backend/tests/authorization 2>/dev/null | head -500
echo '== candidate API declarations outside catalogue =='
rg -n -i \
'adapter.?binding|resource.?context|digest|mutation.?fact|opaque' \
backend/app backend/tests \
--glob '*.py' \
--glob '!**/snapshots/**' \
--glob '!**/fixtures/**' 2>/dev/null | head -700Repository: Flow-Research/workstream Length of output: 50381 Register the four actions in AUTH before accepting this manifest. The AUTH catalogue and API contain no 🤖 Prompt for AI Agents |
||
|
|
||
| ## Verification commands | ||
|
|
||
| ```bash | ||
| cd backend && uv run ruff check app/modules/authorization tests/authorization/test_adapter_binding_registration.py | ||
| cd backend && uv run pytest -q tests/authorization/test_adapter_binding_registration.py tests/test_authorization.py | ||
| python3 scripts/workstream_agent_gate.py --help | ||
| python3 scripts/check_stale_authorization_docs.py | ||
| python3 scripts/check_chunk_state_sync.py --base-ref origin/main | ||
| python3 scripts/check_markdown_links.py | ||
| git diff --check | ||
| ``` | ||
|
|
||
| Hosted CI owns the full repository coverage gate. Authorization remains at or | ||
| above 90 percent and repository-wide coverage remains at or above 78 percent. | ||
|
|
||
| ## Required reviewers | ||
|
|
||
| - [ ] architecture | ||
| - [ ] security/auth | ||
| - [ ] senior engineering | ||
| - [ ] QA/test | ||
| - [ ] product/ops | ||
| - [ ] reuse/dedup | ||
| - [ ] test delta | ||
| - [ ] docs | ||
|
|
||
| ## Human review focus | ||
|
|
||
| Confirm the exact four-action manifest, the exclusion of retirement and all | ||
| service/callback authority, and proof that registration cannot activate use. | ||
|
|
||
| ## Stop conditions | ||
|
|
||
| Stop if CP02 needs another action, permission, resource fact, evaluator, | ||
| identity, migration, or product import; update and re-review the contract first. | ||
|
|
||
| ## Merge state | ||
|
|
||
| - Outcome on merge: `planned` | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,122 @@ | ||
| # Chunk Contract: WS-ARCH-001-CP01B — AUTH ContributionPolicy Registration | ||
|
|
||
| ## Parent initiative | ||
|
|
||
| WS-ARCH-001 — Modular Monolith Boundaries | ||
|
|
||
| ## Goal | ||
|
|
||
| Register the canonical ContributionPolicy authorization contract while every | ||
| new action remains planned and unavailable. | ||
|
|
||
| ## Why this chunk exists | ||
|
|
||
| CP04 needs stable `contribution.policy.*` identifiers and typed AUTH facts, but | ||
| policy registration must not inherit adapter-binding behavior or activate a | ||
| Finance operation before hidden CON proof exists. | ||
|
|
||
| ## Approved plan reference | ||
|
|
||
| - INTENT: `.agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/INTENT.md` | ||
| - PLAN: `.agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/PLAN.md` | ||
| - CHUNK_MAP: `.agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/CHUNK_MAP.md` | ||
|
|
||
| ## Risk class | ||
|
|
||
| L1 | ||
|
|
||
| ## SLA | ||
|
|
||
| P1 | ||
|
|
||
| ## Allowed files | ||
|
|
||
| ```text | ||
| backend/app/modules/authorization/catalogue.py | ||
| backend/app/modules/authorization/api/__init__.py | ||
| backend/app/modules/authorization/api/action_ids.py | ||
| backend/app/modules/authorization/api/contribution_policies.py | ||
| backend/tests/authorization/test_contribution_policy_registration.py | ||
| .agent-loop/CURRENT_STATE.md | ||
| .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/{CHUNK_MAP.md,STATUS.md} | ||
| .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/chunks/WS-ARCH-001-CP01B-auth-contribution-policy-registration.md | ||
| .agent-loop/initiatives/WS-ARCH-001-modular-monolith-boundaries/reviews/WS-ARCH-001-CP01B-*.md | ||
| .agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/{CHUNK_MAP.md,STATUS.md} | ||
| ``` | ||
|
|
||
| ## Not allowed | ||
|
|
||
| ```text | ||
| CON application/model/repository/route changes | ||
| database migrations or persisted service rows | ||
| evaluators, grants, service identities, fixed-service matrix rows, or activation | ||
| adapter-binding lifecycle behavior | ||
| fulfillment, callback, dispatcher, award, TASK, REV, or delivery authority | ||
| generic resource dictionaries or a second prepared-authorization protocol | ||
| compatibility aliases or non-canonical ContributionPolicy identifiers | ||
| ``` | ||
|
|
||
| ## Exact registration manifest | ||
|
|
||
| | ActionId | PermissionId | Context | | ||
| |---|---|---| | ||
| | `contribution.policy.read` | `compensation.policy.manage` | exact project, policy, and optional version identity | | ||
| | `contribution.policy.create_draft` | `compensation.policy.manage` | exact project and policy collection | | ||
| | `contribution.policy.update_draft` | `compensation.policy.manage` | exact project, policy, and draft version identity | | ||
| | `contribution.policy.publish` | `compensation.policy.manage` | exact project, policy, complete draft version, rule/definition digest, and referenced binding identities | | ||
| | `contribution.policy.retire` | `compensation.policy.manage` | exact project, policy, and published version identity | | ||
|
|
||
| ## Acceptance criteria | ||
|
|
||
| - [ ] Five canonical `contribution.policy.*` ActionIds map only to existing | ||
| `compensation.policy.manage` under CP01B custody. | ||
| - [ ] All five definitions remain `PLANNED`; no evaluator, identity, grant, | ||
| matrix row, route, or product behavior can use them. | ||
| - [ ] AUTH public API exposes typed immutable query/mutation fact models and | ||
| canonical resource-digest helpers without importing CON internals. | ||
| - [ ] Mutation facts use the existing opaque PREP port; no handle construction, | ||
| serialization, consumption, or runtime evaluator is added. | ||
| - [ ] Independent tests prove identifier spelling, permission/owner mapping, | ||
| typed fact validation and digest domain separation, catalogue/API parity, | ||
| and planned denial. | ||
| - [ ] No `compensation.policy.*` ActionId alias is introduced. | ||
|
Comment on lines
+59
to
+82
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
rg -n -C 3 \
'contribution\.policy\.(read|create_draft|update_draft|publish|retire)|compensation\.policy\.manage|PLANNED|ActionOwner|compensation\.policy\.' \
backend/app/modules/authorization backend/tests/authorizationRepository: Flow-Research/workstream Length of output: 50380 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- ActionId and permission declarations ---'
sed -n '1,225p' backend/app/modules/authorization/catalogue.py | \
rg -n -C 2 'class ActionId|CONTRIBUTION|COMPENSATION_POLICY|contribution\.policy|compensation\.policy'
printf '%s\n' '--- Catalogue references ---'
sed -n '780,1090p' backend/app/modules/authorization/catalogue.py | \
rg -n -C 3 'CONTRIBUTION|COMPENSATION_POLICY|contribution\.policy|compensation\.policy|FUTURE_INTENT'
printf '%s\n' '--- Repository-wide exact identifiers and aliases ---'
rg -n \
'contribution\.policy\.(read|create_draft|update_draft|publish|retire)|compensation\.policy\.[A-Za-z0-9_.-]+' \
backend .agent-loop --glob '*.py' --glob '*.md' --glob '*.json' --glob '*.yaml' --glob '*.yml' \
| head -200Repository: Flow-Research/workstream Length of output: 50381 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- Focused AUTH catalogue matches ---'
rg -n \
'CONTRIBUTION|COMPENSATION_POLICY|contribution\.policy|compensation\.policy|FUTURE_INTENT_REQUIRED_ACTIONS' \
backend/app/modules/authorization backend/tests/authorization || true
printf '%s\n' '--- Exact action and permission enum members ---'
python3 - <<'PY'
from pathlib import Path
path = Path("backend/app/modules/authorization/catalogue.py")
lines = path.read_text().splitlines()
for start, end in ((1, 180), (240, 290), (880, 910), (1040, 1080)):
print(f"--- lines {start}-{end} ---")
for number in range(start, min(end, len(lines)) + 1):
print(f"{number}:{lines[number - 1]}")
PY
printf '%s\n' '--- Repository-wide exact matches, excluding generated/database artifacts ---'
rg -n \
'contribution\.policy\.(read|create_draft|update_draft|publish|retire)|compensation\.policy\.[A-Za-z0-9_.-]+' \
backend/app backend/tests \
--glob '*.py' --glob '*.md' --glob '*.json' --glob '*.yaml' --glob '*.yml' \
--glob '!**/dump/**' --glob '!**/snapshot/**' --glob '!**/fixtures/**' \
|| trueRepository: Flow-Research/workstream Length of output: 17467 🏁 Script executed: #!/bin/bash
set -euo pipefail
python3 - <<'PY'
import ast
from pathlib import Path
path = Path("backend/app/modules/authorization/catalogue.py")
tree = ast.parse(path.read_text())
wanted = {
"contribution.policy.read",
"contribution.policy.create_draft",
"contribution.policy.update_draft",
"contribution.policy.publish",
"contribution.policy.retire",
}
action_values = {}
action_definitions = []
planned_set = set()
for node in ast.walk(tree):
if isinstance(node, ast.ClassDef) and node.name == "ActionId":
for item in node.body:
if isinstance(item, ast.Assign) and isinstance(item.value, ast.Constant):
for target in item.targets:
if isinstance(target, ast.Name):
action_values[target.id] = item.value.value
if isinstance(node, ast.Assign):
targets = {t.id for t in node.targets if isinstance(t, ast.Name)}
if "ACTION_DEFINITIONS" in targets and isinstance(node.value, ast.Tuple):
for call in node.value.elts:
if not isinstance(call, ast.Call) or not isinstance(call.func, ast.Name):
continue
if call.func.id not in {"_planned", "_active"} or not call.args:
continue
action_arg = call.args[0]
if isinstance(action_arg, ast.Attribute):
action_definitions.append(
(action_arg.attr, call.func.id, ast.unparse(call))
)
if "FUTURE_INTENT_REQUIRED_ACTIONS" in targets:
values = node.value
if isinstance(values, ast.Call) and isinstance(values.args[0], ast.Set):
for item in values.args[0].elts:
if isinstance(item, ast.Attribute):
planned_set.add(item.attr)
print("ActionId values:")
for value in sorted(wanted):
names = [name for name, actual in action_values.items() if actual == value]
print(f" {value}: {names or 'ABSENT'}")
print("ACTION_DEFINITIONS:")
for name, availability, expression in action_definitions:
if name in {
name for name, actual in action_values.items() if actual in wanted
}:
print(f" {name}: {availability} ({expression})")
print("FUTURE_INTENT_REQUIRED_ACTIONS contains wanted members:")
print(sorted(
name for name, actual in action_values.items()
if actual in wanted and name in planned_set
))
print("Alias/runtime exact-string scan:")
matches = []
for root in (Path("backend/app"), Path("backend/tests")):
for file in root.rglob("*.py"):
text = file.read_text()
for value in wanted | {"compensation.policy.manage"}:
if value in text:
matches.append((str(file), value))
for file, value in sorted(set(matches)):
print(f" {file}: {value}")
PYRepository: Flow-Research/workstream Length of output: 630 Register the five planned 🤖 Prompt for AI Agents |
||
|
|
||
| ## Verification commands | ||
|
|
||
| ```bash | ||
| cd backend && uv run ruff check app/modules/authorization tests/authorization/test_contribution_policy_registration.py | ||
| cd backend && uv run pytest -q tests/authorization/test_contribution_policy_registration.py tests/test_authorization.py | ||
| python3 scripts/workstream_agent_gate.py --help | ||
| python3 scripts/check_stale_authorization_docs.py | ||
| python3 scripts/check_chunk_state_sync.py --base-ref origin/main | ||
| python3 scripts/check_markdown_links.py | ||
| git diff --check | ||
| ``` | ||
|
|
||
| Hosted CI owns the full repository coverage gate. Authorization remains at or | ||
| above 90 percent and repository-wide coverage remains at or above 78 percent. | ||
|
|
||
| ## Required reviewers | ||
|
|
||
| - [ ] architecture | ||
| - [ ] security/auth | ||
| - [ ] senior engineering | ||
| - [ ] QA/test | ||
| - [ ] product/ops | ||
| - [ ] reuse/dedup | ||
| - [ ] test delta | ||
| - [ ] docs | ||
|
|
||
| ## Human review focus | ||
|
|
||
| Confirm canonical ContributionPolicy terminology, exact five-action manifest, | ||
| binding lineage on publish, and proof that registration cannot activate use. | ||
|
|
||
| ## Stop conditions | ||
|
|
||
| Stop if CP04 needs another action, permission, resource fact, evaluator, | ||
| identity, migration, or product import; update and re-review the contract first. | ||
|
|
||
| ## Merge state | ||
|
|
||
| - Outcome on merge: `planned` | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,39 @@ | ||
| # WS-ARCH-001 CP01 Split External Review Response | ||
|
|
||
| ## Comments addressed | ||
|
|
||
| - Replaced two nonexistent future verification commands in CP01A and CP01B | ||
| with repository-owned runnable checks. | ||
| - Expanded the binding-authority risk mitigation to name retirement, | ||
| fulfillment, callback, and delivery exclusions across identifiers, | ||
| permissions, identities, routes, evaluators, and service-matrix rows. | ||
|
|
||
| ## Comments not applied | ||
|
|
||
| - CP01A and CP01B remain executable implementation contracts for future PRs. | ||
| Their actions remain planned/unavailable on merge, but those PRs still make | ||
| real AUTH catalogue and typed-public-API changes. Only CP01 is the | ||
| non-executable planning parent. | ||
| - CodeRabbit's requests to implement the registered actions in PR #331 were not | ||
| applied. PR #331 is the bounded plan/chunk split; runtime implementation | ||
| belongs to the later one-chunk-per-PR CP01A and CP01B changes. | ||
|
|
||
| ## Human decisions needed | ||
|
|
||
| None. These dispositions preserve the approved planning-only scope. | ||
|
|
||
| ## Commands rerun | ||
|
|
||
| ```text | ||
| python3 scripts/check_chunk_state_sync.py --base-ref origin/main | ||
| python3 scripts/check_markdown_links.py | ||
| python3 scripts/check_stale_workstream_wording.py | ||
| python3 scripts/check_stale_authorization_docs.py | ||
| python3 scripts/workstream_agent_gate.py --help | ||
| git diff --check | ||
| ``` | ||
|
|
||
| ## Remaining risks | ||
|
|
||
| CP01A and CP01B implementation still require separate human approval and their | ||
| full contract verification on then-current main. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
Mark CP01A and CP01B as non-executable contracts.
The child contracts register unavailable actions. They do not add runtime behavior or activation.
Proposed executable contractconflicts with the parent’snon-executablestatus and the CP01A/CP01B contract boundaries. UseProposed non-executable registration contractfor both rows.As per coding guidelines: “Do not implement a chunk until its allowed files, not-allowed changes, acceptance criteria, risk class, verification commands, and required reviewers are explicit.” The PR objective also states that CP01A and CP01B are non-executable planning chunks.
Proposed wording fix
📝 Committable suggestion
🤖 Prompt for AI Agents
Source: Coding guidelines