fix(security): gate summary shared-catalog enrichment - #1079
seonghobae wants to merge 34 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (13)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough요약 저장 경로가 계정의 Changes요약 카탈로그 인가
Priority: ⬆️ High Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant API
participant AccountPolicy
participant SummaryIngestion
participant SharedCatalog
API->>AccountPolicy: 현재 계정의 post_admin 권한 확인
AccountPolicy->>SummaryIngestion: 보강 허용 여부와 클라이언트 전달
SummaryIngestion->>SharedCatalog: 허용 시 조직·팀 생성 또는 갱신
SummaryIngestion->>SharedCatalog: 차단 시 기존 팀과 조직만 조회
Merge Risk: ⚪ Minimal · up to The authorization boundary preserves reader summary access while preventing shared-catalog mutation; no remaining merge-blocking risk was identified. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh review found one stale test contract before validation: A bounded temporary patch workflow is staged at current head The patch job |
|
Additional review finding before full-suite admission: The repair is to make this enrichment-specific transaction test pass |
|
Live authority update for the current Draft lane:
This PR stays Draft. Do not treat |
|
Fresh review found one workflow-governance defect in the temporary #1078 patch lane: |
|
@coderabbitai resume 현재 validation authority는 |
|
✅ Action performedReviews resumed. Full review finished. |
|
@coderabbitai review |
|
|
@coderabbitai review Current review authority moved to exact head |
|
검토 범위에는
|
|
Fresh owner-path integration finding: canonical read-only queue-health PR I repaired this at the canonical owner boundary rather than changing this leaf. New Draft child #1079 itself stays unchanged at |
2026-09-15 02:47 KST current-head authority updateExact product head remains unchanged at Fresh exact-head state:
No source change, no no-op wake commit, no rerun, no selector/provider/model/timeout change, and no lifecycle flip was made. The correct merge boundary therefore remains fail-closed: wait for Required CodeQL compatibility + terminal Strix/Noema/OpenCode evidence + qualifying independent approval, then normal protected merge. Dynamic gap projection was refreshed in Draft docs lane #1041 at exact |
|
@coderabbitai full review 현재 validation authority는 변경 없는 exact head |
|
검토는 ✅ Action performedFull review finished. |
|
Live exact-head review authority update (2026-09-15 KST): CodeRabbit has now completed a full base→head review of protected |
Live exact-head authority — 2026-09-15 08:xx KSTThis supersedes the earlier nonterminal review/check status notes for unchanged exact head
Merge remains fail-closed until the fresh current-head CodeQL producer/compatibility path is terminal GREEN, OpenCode publishes its authenticated current-head verdict, Strix and Noema acquire complete terminal evidence through their canonical owner repairs, and a qualifying current-head approval exists. The product authorization/catalog boundary itself remains unchanged and retains the prior exact-head GREEN repository/security evidence. |
|
Current CodeQL authority correction for exact #1079 head
The findings are repository-baseline files outside #1079's 13-file authorization diff, so they are not new summary-catalog authorization regressions and must not be patched into this PR:
The local #1079 compatibility jobs remain the earlier terminal fail-closed readers from before producer completion; because the producer published failure, there is no GREEN receipt to wake/reconcile. Required CodeQL therefore remains legitimately RED. Keep #1079 Ready only as its existing validation state; do not churn this head, copy baseline fixes into it, synthesize a status, or weaken the Medium+ gate. Promotion now requires the owner repairs to land/reconverge, then a fresh exact-head canonical scan/compatibility settlement plus the existing OpenCode/Strix/Noema/independent-approval gates. |
|
Owner repair update: the four JavaScript |
|
Current CodeQL authority correction: canonical producer run |
Pull request was converted to draft
Problem and owner boundary
GET /api/posts/{post_id}/summaryis readable underpost_read, but missing-summary materialization previously admitted shared Customer Master catalog mutation capabilities. This lane owns the LineageWeave authorization/application boundary only: shared-catalog enrichment is derived frompost_admin; readers get lookup/reuse without create/upsert; Null hierarchy/relation clients andallow_catalog_enrichment=Falseremain the fail-closed reader default. The canonical corporate catalog remains incorporate_entity_ingestion. ADR 0375 remains Proposed.Current exact authority — 2026-09-23 KST
main@83eba56149eb802cd63642c507c324c9976ec78ec2923950e73c88a9f9fd932332ddd47682da124bAPPROVED: noneRepository-owned acceptance is terminal and the repaired product boundary remains GREEN:
34815479029: SUCCESS, including frontend, full PostgreSQL suite, and PostgreSQL + Keycloak + Valkey summary-authorization integration;34815434313: SUCCESS;34815434486: SUCCESS;34815434324: terminal FAILURE at canonical verdict settlement.The latest Required CodeQL attempt is no longer a simple producer-queue snapshot. Detect-languages
106390839868is SUCCESS. Actions receiver106390838575settled SUCCESS, while JavaScript/TypeScript106390838277and Python106390838659each acquired hosted runners, read the current-head dispatch verdict, then failed at terminal enforcement. Follow-on coordinator106488973605later completedDispatch current-head CodeQL scanSUCCESS on the same exact head. The overall run therefore remains non-accepting and belongs to canonical.github#1929; do not copy the central dispatch/receiver control plane or synthesize a status here.The two CodeRabbit source findings in this lane were repaired in the current history; there is still no qualifying submitted
APPROVEDreview. Historical Strix/Noema/OpenCode control-plane evidence remains external-owner evidence and is not grounds to weaken this authorization lane or copy provider/routing/sidecar policy into LineageWeave.Promotion boundary
Keep Draft and unmerged until Required CodeQL reaches terminal acceptance on an unchanged current head, model-backed review/coverage evidence is current and accepting, all valid findings remain resolved, and qualifying independent approval exists. ADR 0375 stays Proposed until normal protected integration.
Do not use no-op commits, private-environment fabrication, provider/model fallback, manual status synthesis, self-approval, force push, destructive rebase, blind rerun, source-neutral wake commit, owner-source copy, total elapsed model timeout, or gate weakening to manufacture evidence.
Fixes #1078.