Repository navigation
Fix guided responder consent, malformed setup recovery and failures - #139
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses #138. Companion: NetRatel PR #176, tracking BostonTechnologies/netratel#175. Owner acceptance remains open in #119/#136 and NetRatel #164/#171/#146.
Validate a requested responder organization against enabled local existence and current authority before persisting it as a binding. Preserve the absent-preset chooser. Retained malformed, unconsented/unprepared records can be inspected and cancelled idempotently by the original actor with current installation-admin authority, including after expiry. The special path checks immutable descriptor/hash identity, absent consent/credentials/principals/journals/exchange and terminal preparation fences; it never substitutes organizations, deletes rows or manufactures an active link.
List and status project the same authorized next action from durable role/state. Pending responder Resume opens protected approval; initiators use their protected continuation/final review; post-consent reconciliation and in-doubt abort retain existing recovery. Null-summary UI no longer claims approval was saved. Restore the adjacent missing requested-peer-tenant hidden form value, preserving absent/exact values; this is not an asserted cause of the deployed reverse error.
Handled failures carry allowlisted code/stage/local correlation through the browser and existing personal notifications. Notification persistence uses a fresh scope, no unvalidated tenant ID and no background/read/service-caller emission. Preserve product/self-instance checks, canonical snapshots, return-origin validation, incident-only defaults, optional explicit task consent and all provider/concurrency/rotation assertions. Compact the actually stretched enable button using a wrapping MudBlazor row.
Validation
Local Debug validation: combined focused web/protocol/recovery tests 132/132 passed (2m26s), final incremental UI/parent-handler run 36/36 passed (2s), and failure-reporting/transport/sign-in group 22/22 passed (597ms); groups overlap and are not additive. Chromium rendered 16 actual component/CSS layouts: setup/pending/failed/connected × 390/1440px × light/dark, without overflow. This used the existing synthetic component fixture and is static visual evidence, not a running paired browser ceremony. The existing optional Playwright spec parses/lists four tests but was not executed.
Disclosure/helper checks and whitespace checks pass; changed-file Slopwatch reports zero findings. The final new recovery group passed 15/15 cases (23 semantic scenarios) in 16s test time / 18.605s wall time. Final commit:
bcb18a9a5040a6c9e19b99df06de60ca7a72b743. Required hosted validation passed on attempt 1 in 14m41s, meeting both the under-20-minute budget and 10–15-minute target. Full .NET suite: 2,141 passed, six retained legacy skips, zero failures; .NET job 14m38s, restore 10s, build 1m07s, test stage 12m47s. Dedicated real HTTP/SQLite/PostgreSQL provider acceptance: 235/235 passed, zero skips, job 8m21s (build 1m25s, test stage 6m15s). All five required jobs passed. Seven optional deep-acceptance entries were skipped and are not counted as passes. Product/dependency versions and required workflows are unchanged. Independent agent source review found no unresolved blocking findings at both final commits; every changed file matches the reviewed snapshot. Cross-repository review covers authority, consent/preparation races, immutable grants, continuation, failure propagation and notification scope.Owner acceptance handoff
No merge, release, publication, deployment, live setting/credential change or production-row deletion is included. The reported private-network opt-in is already an installation prerequisite; no additional configuration change is established.
The deployed reverse
unsupported-peercause is unresolved because the precise submitted origin and rejecting request/metadata receipt were not captured. Controlled wrong-product/self-instance regressions preserve legitimate rejection and a distinct compatible peer succeeds in the source fixture. These are not a deployed reverse-browser pass.The existing optional paired harness requires hosted candidate/published image receipts and has no supported Debug path for both changed sources. Full paired browser activation and controlled monitoring incident delivery are unexecuted here. The previous incident HTTP 500 without a committed incident/receipt remains failed historical evidence. Rendered fixture checks are separate from functional source-pair and owner deployment acceptance.
Retest with the original account/session and current authority. Cancel retained malformed records only via the supported offered action, reload, and start fresh consent with valid explicit organization/customer/tenant selections. Inspect the counterpart separately. Prepared/committed/in-doubt links retain distributed recovery or unlink. Complete both initiation directions, pending responder approval, cancellation/expiry and read-only Test connection; optional task access stays off. Then verify one controlled monitoring event commits one incident/receipt and identical retry creates no duplicate. If reverse rejection recurs, keep the actual submitted origin, stage/correlation, discovered metadata and effective routing receipt private. Check the scoped
/notificationsguidance, including correction/retry before any attempt exists.The original UI coverage skipped real parent submission, while endpoint-handled errors bypassed exception notification middleware. Focused composition/handler, real HTTP/database and error-audience regressions address those gaps without a new evidence framework or mandatory pair matrix.