feat(schedule): authorize and audit terminal reason events - #518
feat(schedule): authorize and audit terminal reason events#518seonghobae wants to merge 14 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
Rebuild the terminal reason authorization/audit child on the exact current #517 outcome-domain head, retaining parent release-note and NVIDIA NIM/OpenCode protections while preserving only the bounded reason-event domain, tests, coverage registration, and doctoring delta.
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Rebuild the SQLite terminal-reason persistence child on the exact current #518 authorization head, preserving parent release-note and OpenCode/NIM regressions while carrying only persistence source, normalized schema tests, coverage registration, and evidence.
Buyer and governance impact
Refs #287. This bounded stacked slice adds the authorization and immutable audit contract required before
skipped,cancelled, ornot_performedcan become trusted schedule facts. It prevents silent inference, stale authority, self-approved cancellation, and unaudited mutation while remaining framework and database neutral.Exact current stack and scope
Current parent:
feat/schedule-outcome-domain-287@918e1a5194bea1ac817bdad2394adda1fdd51478(#517).Current contributor head:
cf7412e8b98dfd2ff6e76ddd232470b79f1a5b5b.The child is an ahead-only descendant of the exact parent. The live parent-to-child diff is limited to four authorization/evidence files:
CHANGELOG.md;docs/doctoring/schedule-reason-event-authorization.md;package.json;server/schedule_reason_event_domain.mjsand its focused unit/coverage contract registration as represented by the current PR file set.The branch was reconciled non-destructively with the current outcome parent and preserves protected contextual-orchestrator registrations. No editor, API route, database schema, attachment, Clearfolio, billing, dependency, lockfile, workflow, deployment, or protected-branch artifact is changed.
Authorization and audit contract
skipped,cancelled, andnot_performed;TDD and verification discipline
The contract regressions preceded production implementation and cover valid skipped/not-performed events, independent cancellation approval, stale version, self-approval, wrong reason type, malformed inputs, audit identity, port failures, immutable outputs, and exact version-bound persistence handoff. The branch was later reconciled to the parent’s current tree without dropping hierarchy or outcome behavior.
On unchanged head
cf7412e8..., repository-native Server Tests, Dependency Review, and OSV Scanner are terminal success. The stacked feature base yields six check records, all terminal-success except skipped manifest bookkeeping; no failed, queued, or in-progress check is present. There are no submitted reviews or review threads on the exact current head. Absence of protected-developworkflows on this stacked base is not promoted to evidence for those gates.The PR is Ready for independent review so the stack can progress, but it must not integrate independently of #517 and #515. Workflow/model/status evidence is not qualifying approval.
Standards and integration boundary
docs/doctoring/schedule-reason-event-authorization.mddistinguishes active-PR design from protected shipped truth and records the threat model, decision, immutable event/audit contract, approval/version semantics, rollback, and APA 7 references. The product contract supports CSAP/SOC 2 evidence readiness but does not claim certification.This PR does not close #287. Durable SQLite/PostgreSQL adapters, authenticated route/UI integration, version-store wiring, variance/forecast computation, and buyer decision views remain separate bounded work. PR #519 is the current persistence child and must remain reconciled to this exact parent.
Merge gate
Do not integrate before #517 and #515. After the prerequisite stack reaches protected
develop, reconcile this exact bounded semantic diff onto the resulting live head and rerun every then-applicable CI, browser E2E, coverage/docstring, SAST, security, dependency, supply-chain, package/provenance, resolved-thread, and qualifying independent-approval gate. No predecessor-head, author-only, skipped, neutral, status-only, synthetic, or model-only evidence transfers.Refs #287