Repository navigation
feat(cli): browse contributor ready tasks and instructions - #478
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (6)
🚧 Files skipped from review as they are similar to previous changes (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Go CLI adds contributor commands to list ready tasks and read task instructions. The commands use existing public REST routes, apply response validation, and include integration coverage for output, pagination, authority, and assignment visibility. ChangesContributor task reads
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Contributor
participant CLI
participant APIClient
participant PublicRESTAPI
Contributor->>CLI: Run task ready or task show
CLI->>APIClient: Request contributor task read
APIClient->>PublicRESTAPI: Send fixed-route GET request
PublicRESTAPI-->>APIClient: Return task data
APIClient-->>CLI: Return validated response
CLI-->>Contributor: Print text or JSON output
Merge Risk: ⚪ Minimal · up to The contributor task-read commands appear ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new commands provide narrowly scoped reads while leaving access decisions on the server. The examined paths preserve credential protections and reject invalid or management-only responses before output. No authorization bypass was identified, but deployment-wide security coverage remains incomplete. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 5.88% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 17 functions across 7 files. (4 skipped: 4 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
CodeRabbit completed a fresh review of bd0cf34 with no actionable findings. The default docstring-percentage warning is advisory, not a repository gate; this slice retains behavior-focused process/API proof rather than quota-driven comments or unit tests. |
Change
WS-CLI-001-05 — contributor ready-task discovery and detail.
Goal
Let contributors browse ready work and inspect instructions without manager
metadata, task writes, or client-owned authorization.
Intent And Planning Context
Bounded change record
owns the design, acceptance criteria, alternatives and remaining boundary.
What Changed
workstream task ready PROJECT_ID [--limit N] [--cursor CURSOR]calls theexisting public contributor queue once.
workstream task show TASK_IDcalls the existing public contributor detail once.reject malformed, substituted or management-only response data before output.
docs, root README, roadmap, overview and index in the same change.
Scope Control
Only CLI code/integration tests and affected documentation/Commitrail records
changed. No backend, MCP, dependency, workflow or CI configuration changes.
Product Behavior
AUTH/TASK retain grant, lifecycle, state and assignment decisions.
Evidence
Go module verification/tidy, vet/build, Ruff/format, links, four stale scans,
Commitrail and all 16 workflow-integrity tests passed on the reviewed head.
Current candidate:
55704f73, reconciled with main31ac857b. Both CLI-05 andARCH-04E1B-B1 index entries are retained, along with main's roadmap updates.
The mixed canonical/compact duplicate UUID regression passes. Replacing only
normalized duplicate tracking with raw-string tracking fails its exact assertion
(erroneous success instead of
invalid_api_response). Existing duplicate andindependent page-size controls remain.
All 24 local HTTP process tests passed in 60.45s. Local combined and separate
real-API attempts hit the unchanged 240-second deadline; both cleaned their
isolated PostgreSQL database at Alembic
0020_review_admission_lock_orderandare not counted as passes.
Fresh hosted CLI Public Contract
passed the complete 25-test process/real-API suite in 43.65s (job 1m53s), using
the unchanged 240-second deadline and migration
0020. Tested merge commit5ef2308band review head55704f73have the identical Git tree2347ce43b83427a7122dbcab5a0ec753383fdf09.Full Backend
passed: 8,636 canonical tests completed across nine accepted lane bundles, zero
skips/deselections and no duplicate completed identities. All nine exact-source
PostgreSQL/MinIO cleanup records are complete at migration
0020. Agent Gatesand both MCP jobs passed too.
Attempt 1 reached the unchanged 1,200-second task-lane deadline after 516/527
tests completed, with no assertion failure shown and cleanup confirmed. The
unchanged-source retry completed all 527 task-lane tests within that deadline
(lane execution 1,161.755s). The final aggregate retained the eight passing
attempt-1 bundles and selected the successful task-lane attempt-2 bundle;
the original partial failure remains recorded and was not combined as success.
No source, selection, timeout or workflow changes were made to obtain the pass.
Acceptance Criteria Proof
preflight/retry/automatic pages.
null/omission, malformed replies, response bounds and redirect refusal.
draft/claimed exclusion, own-assignment detail and same-project non-owner denial.
denial; independently authorized action/project/limit cursor substitution.
Test Delta
Three grouped HTTP process tests added. The existing real API journey is extended
through one cohesive helper, reusing its bootstrap and server. No tests/assertions
removed, skipped or weakened; no test-count or coverage target.
Upstream approved-guide prerequisites reuse canonical fixtures. Inference/storage
are scripted prerequisites, not live Flow, guide-provider or S3 certification.
Real AUTH activates those projects; task/grant/lifecycle operations use public HTTP.
Impact-Routed Reviewer Results
Current review target:
55704f7338031f5880e8c153628b5216db27a878.Base/merge-base:
31ac857ba5611019ac6ef2418753d3625e952497.All three affected assignments replayed this target with matching clean
start/end snapshots. No findings remain. Earlier reviews are historical.
cli_security)cli_arch_docs)cli_qa)These are advisory mirrors, not receipt custody. Proof spans built-process
service/composition behavior and real stored PostgreSQL project/assignment
isolation. Scripted upstream guide inputs and local tokens remain fixture
boundaries; deployed providers and hosted checks are not inferred from them.
External Review
CodeRabbit completed a fresh substantive incremental review at
55704f73, withsix files processed and no actionable comments (run
918ae74d-c1b0-4989-a46c-68d0e2907e52). No review threads exist. Its defaultdocstring quota is not a repository gate or a behavior defect. The supplied
review's conflict and P3 normalization-proof gap are repaired in this candidate.
Human approval and merge remain required; none is inferred.
CI And Gate Integrity
Remaining Risks
Ready-work discovery is not a reservation or claimability guarantee. A later claim
must reauthorize. The existing 64 KiB response bound may require a smaller page.
These source commands do not imply binary distribution, deployment or completed
submission/acceptance integration.
The existing full-backend timing bottleneck remains; this bounded CLI change
does not repair lane capacity or introduce selective testing.
Human Review Focus
Contributor-only fields, exact-resource binding, one-page continuation and
server-owned current authority/assignment visibility.
Human Merge Ownership