Skip to content

Release: integrate fail-closed staging product proof - #381

Merged
bizzybee90 merged 206 commits into
mainfrom
codex/cloud-product-proof-20260801-4d338ea2
Aug 3, 2026
Merged

Release: integrate fail-closed staging product proof#381
bizzybee90 merged 206 commits into
mainfrom
codex/cloud-product-proof-20260801-4d338ea2

Conversation

@bizzybee90

@bizzybee90 bizzybee90 commented Aug 1, 2026

Copy link
Copy Markdown
Owner

Purpose

Integrate the fail-closed staging product-proof chain required to earn exact-main authenticated desktop, mobile and accessibility evidence without weakening production, provider, tenant or secret boundaries.

Included scope

  • Exact Cloudflare immutable-preview deployment binding and artifact verification.
  • Source-derived HTTP, asset and Supabase Realtime policy for 18 ordered product-proof states at two fixed viewports, deriving exactly 36 screenshots.
  • Native invalid-email validation with zero submission/Auth request and no reflected validation copy.
  • Fresh two-tenant synthetic staging fixture, exact tenant-A denial, tenant-B reopen/state-HMAC continuity and always-cleanup contracts.
  • Complete visible-control keyboard traversal, safe Enter/Space/Escape/dialog/focus-return checks, axe zero violations/incomplete, masked screenshots and trusted live network evidence.
  • Real per-viewport execution timing and a separate read-only structural-validation workflow that can report only structurally_valid_pending_semantic_review.
  • GitHub artifact provenance plus gated private Supabase writer/readback, source-controlled Auth-principal lifecycle and deterministic UUID-bound Storage policy apply/verify/rollback.
  • Shared staging concurrency, workflow timeouts, security contracts and canonical release-board milestones.

Explicit exclusions

  • No production deployment, production SQL, provider messages/calls, reviews, Stripe action, public signup, Checkout or usage billing.
  • No real customer data.
  • General consent for the future sanitized export is recorded, but evidence-store Auth/policy activation and protected credentials remain fail-closed pending separate project-mutation authority.
  • The release owner explicitly authorized CodeRabbit source-diff export on 2026-08-01. The first substantive review requested changes; every validated defect is remediated on the exact successor and fresh review is pending. This does not authorize staging/provider/project mutation.
  • Structural validation is not semantic approval. Neither workflow invokes semantic finalization.

Security and tenancy impact

  • Fresh staging-only synthetic sessions use exact password-grant and local logout mediation; unknown credential-bearing requests fail closed.
  • Tenant A/B identities, workspace/conversation filters and route-specific Realtime topics are exact; tenant denial never joins the protected conversation topic.
  • Validation values, credentials, identifiers and synthetic visible content are omitted, HMAC-bound or masked before persistence.
  • Keyboard activation is limited to reviewed non-mutating controls; live policy forbids Auth submission, provider, billing, Storage and mutating REST/RPC actions.
  • Evidence Auth users are exact-UUID bound; compensation deletes only users created by the current invocation.
  • Storage policy apply is transactional and fails on drift/overlap. Rollback drops only exact policies, retains objects/bucket and refuses principal deletion while evidence remains.
  • Structural validation runs only after a successful exact-main product-proof run, has actions: read/contents: read, no Environment/secrets/provider/staging access, and cannot approve semantic review.

Data impact

  • No production migration.
  • The authorized private no-project-reference Supabase feasibility request was sent successfully; no project/provider activation or mutation was requested or performed.
  • Read-only evidence-store preflight proves the private bucket and RLS exist with zero principals, policies or objects, but both required operation-aware Storage helpers are absent. Export therefore remains stopped pending separate activation authority.
  • Staging-only synthetic fixtures and the private evidence store remain sequential and captain-controlled.
  • No backfill. Synthetic tenant cleanup is journalled, idempotent and state-bound.
  • Evidence retention/decommission is separate from provisioning rollback.
  • The production-rehearsal runbook truthfully retains the unconfigured external-owner trust root and fresh signed six-surface containment receipt as blockers.

Verification

  • Complete application suite: 807/807.
  • Trusted cloud product-proof suite: 244/244.
  • Production-cutoff readiness suite: 188/188.
  • UI/documentation audit: 52/52.
  • Focused conversation failure proof: 6/6.
  • Parsed workflow/action contracts: 10/10.
  • Lint, typecheck, changed-file formatting, diff checks and production build pass locally; the repository-wide Prettier check still reports 146 unchanged legacy files.
  • Production dependency audit reports 0 vulnerabilities.
  • The first substantive CodeRabbit review raised 39 unresolved threads across 27 files. Three independent classifications verified every thread and top-level actionable comment; validated workflow, SQL, protected-file, cleanup, browser, evidence, UI and documentation findings are fixed. Incorrect suggestions that would weaken or misdescribe the reviewed contract were not applied.
  • Three final integrated reviews report P0/P1/P2 = 0/0/0 on the remediated source. The canonical board records one docs-only tally ambiguity found and closed before publication.
  • The final follow-up preserves primary signed-out failures over cleanup errors, rejects forbidden workflow contexts even when nested inside expressions, proves stale conversation cancellation, and rejects secret-like screenshot locator identities without persisting raw locators. Independent exact-diff re-review reports P0/P1/P2 = 0/0/0.
  • The final HMAC-only follow-up removes raw locator IDs from the signed privacy plan, resolves masks against the transient live snapshot only, and fails closed on unknown/duplicate HMACs. Two independent exact-diff reviews report P0/P1/P2 = 0/0/0.
  • Exact predecessor 3f657711 passed CI 30696601609, schema baseline 30696601610 and fresh CodeQL 30696600597. Intermediate successors e8ee1991 and 1cafc745 passed CI, schema baseline and CodeQL. CodeRabbit's 1cafc745 review identified one remaining raw-locator privacy issue; exact successor 6126e393 removes it with HMAC-only plan replay and has now passed CI, schema baseline, all CodeQL analyses and the CodeRabbit status check.

Release safety

  • Deployment scope remains reviewed source only. This update authorizes no staging or production deployment.
  • Any provenance mismatch, unexpected request/topic, credential exposure, cache/service-worker bypass, dropped event, tenant drift, cleanup drift or unapproved external-store call fails the run.
  • Live exact-main execution, private export/readback and a distinct semantic agent review remain mandatory and are still Not run.

Completion check

  • Starts from protected origin/main 8fb13abfc90450ef3519179356bff3af0424190c.
  • Remote head 6126e393ce1cc7c380d82521c1cfaa0b9b568a4c has tree a0f9d83185e35a28a2cbe5c14fb393ba95f49f98, identical to clean local reviewed head 2776a59ca16149f962bb4c2e48adf87fbceaf10b.
  • Exact predecessor 3f657711 passed CI, schema baseline and CodeQL before substantive review.
  • Every validated first-review finding is remediated; final integrated reviews report P0/P1/P2 = 0/0/0.
  • Exact successor 6126e393 passed CI, schema baseline, all CodeQL analyses and the CodeRabbit status check.
  • GitHub still reports 19 unresolved non-outdated historical threads and a stale CHANGES_REQUESTED decision; verified thread closure/re-review requires separate write authority.
  • Eligible latest-head approval and zero unresolved review threads must pass.
  • Source branch will be retired after merge or closure.

Policy exception

This is a 67-file release-evidence unit. The workflow DAG, recorder, exact network/asset policy, synthetic fixture lifecycle, Storage provisioning/readback and source-ownership/security tests form one fail-closed invariant. Independent lanes were developed and reviewed separately, then integrated only after exact-tree compatibility tests passed. Merge remains prohibited until all latest-head protected checks and external stop gates are closed.

Retained branch reason / owner / review date / maximum retention date: none. The release captain will retire the source branch immediately after merge or closure.

Summary by CodeRabbit

  • New Features

    • Added protected staging product-proof validation for deployment integrity, tenant isolation, accessibility, privacy, cleanup, and evidence review.
    • Added secure release-evidence storage with independent readback and structural validation.
    • Added trusted cloud verification, deployment asset manifests, synthetic-tenant recovery, and semantic review and acceptance workflows.
  • Bug Fixes

    • Improved sensitive credential detection.
    • Conversation pages now handle loading, missing conversations, stale results, and retries.
  • Quality

    • Expanded browser, database, security, accessibility, and evidence-integrity checks.
    • Standardized coordination for shared staging operations.
  • Documentation

    • Updated release, deployment, staging, QA, and evidence-store guidance.

@coderabbitai

coderabbitai Bot commented Aug 1, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds protected staging product-proof execution, deployment and asset binding, browser and database verification, Supabase evidence storage, independent review, shared staging serialization, application fixes, and contract tests.

Changes

Product-proof execution and verification

Layer / File(s) Summary
Protected staging execution
.github/workflows/staging-product-proof-*.yml, scripts/staging-product-proof-workflow.test.mjs
Adds source-gated staging proof, tenant lifecycle controls, browser verification, sanitized artifacts, recovery, structural validation, semantic review, and final acceptance.
Product-proof contracts and runners
scripts/product-proof-*.mjs, scripts/database/*product-proof*
Adds deployment binding, asset and network contracts, live evidence, screenshot privacy, browser checks, aggregate capture, synthetic tenant lifecycle, and execution metadata.
Release-evidence storage
scripts/release-evidence/*, docs/adr/*, docs/runbooks/supabase-release-evidence-store.md
Adds Supabase principal lifecycle, exact policy provisioning, create-only uploads, independent readback, artifact verification, and manifest-bound reads.
Workflow and application integration
.github/workflows/*, package.json, src/*, vite.config.ts, vitest.config.ts, docs/architecture/*, docs/qa/*, docs/runbooks/*
Adds shared staging concurrency, trusted CI coverage, Vite manifest support, service-role detection, tolerant conversation lookup, and updated architecture and QA records.

Estimated code review effort: 5 (Critical) | ~120 minutes

Possibly related PRs

Sequence Diagram(s)

sequenceDiagram
  participant StagingProductProofWorkflow
  participant ProductProofDeploymentBinding
  participant ProductProofCloudPlaywright
  participant SupabaseEvidenceStore
  participant IndependentReader
  StagingProductProofWorkflow->>ProductProofDeploymentBinding: verify deployment receipt and source marker
  StagingProductProofWorkflow->>ProductProofCloudPlaywright: run fixed routes and tenant checks
  ProductProofCloudPlaywright->>StagingProductProofWorkflow: write sanitized evidence artifact
  StagingProductProofWorkflow->>SupabaseEvidenceStore: upload evidence with writer identity
  IndependentReader->>SupabaseEvidenceStore: read back evidence with reader identity
  IndependentReader->>StagingProductProofWorkflow: publish pending review receipt
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.40% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: integrating a fail-closed staging product-proof chain.
Description check ✅ Passed The description covers the required template sections with detailed scope, security, data, verification, release safety, documentation, and completion information.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/cloud-product-proof-20260801-4d338ea2

Comment @coderabbitai help to get the list of available commands.

This was referenced Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant