-
Notifications
You must be signed in to change notification settings - Fork 0
fix(accessibility): fail closed on invalid collaboration connection status #208
Copy link
Copy link
Open
Labels
area: accessibilityAccessibility and assistive-technology supportAccessibility and assistive-technology supportarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Description
Activity
Metadata
Metadata
Assignees
Labels
area: accessibilityAccessibility and assistive-technology supportAccessibility and assistive-technology supportarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Current authoritative state
Protected shipped truth is exact
main@a40b9489665bed7d95af619a6079b9c51cab299a; invalid runtime collaboration states still fall through to the misleading ready label. Closed Draft #167 is historical evidence only.Issue-specific Draft PR #406 /
codex/collaboration-status-validation-208owns this repair. It is stacked on awareness-containment PR #403 at exact base66a9caa7cb6a9aa5e399ce5ca76d987737aa7c45; current exact head is02f55466c0111bb53c6886f5d4a95de2068e944a. This is active-PR behavior, not protected-main shipped truth.Required behavior
collaborationConnectionLabel()preserves exactlyundefined -> Collaboration ready,connecting -> Connecting,connected -> Connected,disconnected -> Disconnected, andoffline -> Offline. Every other runtime value fails closed with stable payload-redactedRangeError('Collaboration connection status must be connecting, connected, disconnected, or offline.')instead of presenting an invalid host state as ready.Provider transport/lifecycle, authorization, tenancy, persistence, credentials, deployment, retention, migration, model policy, and durable audit remain host-owned.
Exact-head evidence
Test-only
05f1c3089379339851170260652e95c5d26cf2b3reproduces the defect with 1 failure / 29 passing checks. Current GREEN head passes:Repository-local success is not protected integration, independent approval, or release proof. Keep #406 Draft until #403/#405 integrate or the dependency chain is otherwise resolved, and while #118 owns the protected release boundary. Before lifecycle action, refetch exact head/base, reviews, threads, live rules, and every applicable workflow; do not transfer #167 evidence, self-approve, weaken gates, or fabricate release identity.