Skip to content

Plan ART-AUTH end-to-end authorization contract - #209

Merged
abiorh-claw merged 2 commits into
mainfrom
codex/ws-xint-002-art-auth-end-to-end-plan
Jul 27, 2026
Merged

Plan ART-AUTH end-to-end authorization contract#209
abiorh-claw merged 2 commits into
mainfrom
codex/ws-xint-002-art-auth-end-to-end-plan

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

Chunk

WS-XINT-002-PLAN — ART-AUTH end-to-end planning amendment.

Goal

Freeze the complete v0.1 ART-to-AUTH dependency before ART implementation resumes.

Why this exists

The dependency had been discovered per ART chunk. This plan closes the catalogue, prepared-capability, service-matrix, submission, checker, review, recovery, and activation surfaces end to end.

What changed

  • Added the WS-XINT-002 planning set, review log, and eleven executable implementation contracts.
  • Planned three missing actions and mandatory deletion of six obsolete upload-session actions and permissions.
  • Split initial preparation, Submission/binding consumption, checker remediation, and human-review revision.
  • Required paired human and fixed-service authorization for reviewer packets and evidence.
  • Redirected existing ART/AUTH handoffs to this source of truth.

Design chosen

One closed catalogue reconciliation and one reusable PREP extension merge first with all new actions unavailable. Narrow activation chunks follow only after exact hidden feature evidence exists. AUTH owns authority and evidence; ART owns bytes; product modules own lifecycle truth and typed fact composition.

Not in scope

No application code, migration, action activation, grant, provider behavior, or ART-03A implementation change.

Tests and evidence

Evidence Result
stale authorization documentation pass
stale artifact contracts pass
Markdown links pass
lightweight deterministic Agent Gates pass
diff integrity pass
architecture pass
security/auth pass with low risks
QA/test pass with low risks
product/ops pass with low risks
senior engineering pass with low risks
CI integrity pass

Test delta

Planning-only Markdown change. No production or test code changed. Future contracts contain exact PostgreSQL, coverage, migration, and hosted verification requirements.

External review response

All twelve initial CodeRabbit comments were addressed on repair head 834ff13b. Product/ops corrected one overbroad suggestion so remediation reruns the checker spine before a new allow_review can route it.

Remaining risks

Implementation reviews must enforce forbidden-change lists despite some broad module globs. Baseline counts must be reconfirmed from then-current main before implementation.

Human review focus

Catalogue completeness, mandatory legacy deletion, permanent handle burn, human/service separation, and evidence-ordered activation.

Merge ownership

Human-owned. Do not merge without explicit approval for PR #209.

@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This change redirects ART/AUTH dependency planning to WS-XINT-002 and adds its end-to-end contract documents. The contract defines catalogue reconciliation, PREP boundaries, activation and submission chunks, review artifact behavior, risks, status, and conformance requirements.

Changes

ART-AUTH end-to-end planning

Layer / File(s) Summary
Cross-initiative handoff boundaries
.agent-loop/initiatives/WS-ART-001-immutable-artifact-storage/AUTH_HANDOFF.md, .agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/{ACTIVATION_CUSTODY.md,CHUNK_MAP.md}
ART-facing authorization dependencies are redirected to WS-XINT-002, with contract drift prohibited and historical entries retained as baseline identifiers.
WS-XINT-002 contract foundation
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/{INTENT.md,DISCOVERY.md,DECISIONS.md,PLAN.md,RISKS.md,STATUS.md,CHUNK_MAP.md}
The initiative’s scope, ownership, decisions, phased plan, risks, status, and ordered chunk dependencies are defined.
Catalogue reconciliation and PREP boundaries
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-0{1,2}-*.md
The first chunks specify catalogue/matrix reconciliation and closed typed PREP contracts with binding, locking, opacity, and single-use requirements.
Activation and submission workflows
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-0{3,4}-*.md, .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05*.md
Chunk contracts define worker, guide, initial submission, checker remediation, and human-review revision behavior, including authority, transaction, replay, and concurrency rules.
Checker, review artifact, and conformance proofs
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-0{6,7,8}-*.md
Checker activation, lease-scoped review artifacts, evidence binding, lifecycle parity, isolation, revocation, concurrency, and verification gates are specified.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers: abiorh-claw

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the main intent and changes, but it omits several required template sections like commands run, acceptance proof, internal reviewer results, and CI/gate integrity. Add the missing template sections, especially Scope Control, Evidence commands/results, Acceptance Criteria Proof, reviewer results, CI/gate integrity, and follow-up work.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title matches the main change: a planning amendment that freezes the ART-AUTH end-to-end authorization contract.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/ws-xint-002-art-auth-end-to-end-plan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 12

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
@.agent-loop/initiatives/WS-ART-001-immutable-artifact-storage/AUTH_HANDOFF.md:
- Around line 97-100: The drift rule in AUTH_HANDOFF.md must explicitly require
deleting the six obsolete upload-session ActionIds/PermissionIds, with no
compatibility aliases or unavailable catalogue rows, and reference the exact
reconciliation contract. In
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/DECISIONS.md lines 3-5,
enumerate the exact six IDs or link to the authoritative deletion list so the
retirement is mechanically verifiable.

In
@.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md:
- Around line 3-8: Reconcile the trusted-main baseline before defining the
activation reconciliation delta: in
.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md
lines 3-8, identify one exact baseline commit and update the preserved
PermissionId/ActionId counts; in
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/DISCOVERY.md lines 5-14,
use that same commit and counts or explicitly document the intended snapshot
difference.

In
@.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-01-catalogue-reconciliation.md:
- Around line 35-39: Update the planned review-packet materialization mapping in
the catalogue reconciliation document to name the distinct new PermissionId
explicitly, rather than using artifact.review_packet.materialize as both action
and permission. Preserve the existing submission and binding mappings, and use
the requirement’s actual PermissionId for review-packet materialization.
- Around line 40-46: Make the reconciliation plan around the upload-session
removal explicitly enumerate all six ActionIds, all six PermissionIds, the
scheduler-expiry membership, and the expected closed-count/static-matrix
changes. Reference the reviewed catalogue artifact containing these exact
identifiers and evidence requirements, so reviewers can verify removal across
routes, commands, audits, idempotency, tests, migrations, and documentation.
- Around line 21-24: Restrict the recursive initiative-wide allowances in
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-01-catalogue-reconciliation.md:21-24
to the exact catalogue-reconciliation artifacts. Also update
.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-02-prepared-feature-boundaries.md:26
to allow only the exact PREP-boundary artifacts and required evidence files.

In
@.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-02-prepared-feature-boundaries.md:
- Around line 55-59: The prepared feature-boundaries contract must define a
mechanism that permanently burns a single-use handle even when the caller
transaction rolls back, or explicitly change the transaction model to provide
that guarantee. Update the consumption semantics and related PostgreSQL
coverage, including a test that retries the same handle after a denial or
participant failure rollback and verifies it cannot be reused.

In
@.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05B-submission-binding-consumption.md:
- Around line 5-6: Rename the transaction in the chunk summary from a
“ready-admission transaction” to a “Submission/binding transaction.” Clarify
that it consumes the durable ready admission created by WS-XINT-002-05A while
creating the immutable Submission and fixed artifact binding exactly once,
without re-admitting the work.

In
@.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05C-checker-remediation-submission.md:
- Around line 35-40: Clarify the 05C remediation flow by naming the exact
preparation actions reused from 05A, the Submission creation/binding actions
reused from 05B, and the admission/context consumed during routing. Explicitly
require atomic commit of the final CheckerRun binding, immutable
remediation_source_checker_run_id, predecessor binding, locked task context,
assignment, allow_review state, and Submission creation/binding.

In
@.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05D-human-review-revision.md:
- Around line 39-42: Update the revision lifecycle wording to describe a
revision-scoped context whose durable needs_revision obligation remains open
until atomic successor creation succeeds. Ensure the text does not imply the
obligation is closed before successor creation, preserving retry and concurrency
behavior.

In
@.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-08-conformance.md:
- Around line 54-67: Update the Verification block to explicitly cover every
conformance criterion, including Generated parity, full migration-matrix
validation, the exact stale authorization and artifact scanner categories, and
generated contract/documentation parity. Add the appropriate verification
commands where missing, or clearly map each criterion to the existing required
pass gates, including Backend / test and Agent Gates / agent-gates.

In @.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/DECISIONS.md:
- Around line 12-13: Update the decision entry describing artifact materializer
and binding identities to record the complete membership delta: add the two
review memberships and remove the scheduler-expiry membership, while preserving
that no new service identity is introduced.

In @.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/PLAN.md:
- Around line 41-54: Replace every `same` entry in the service-action table with
the explicit permission identifier matching its corresponding `ActionId`, while
preserving the existing overridden `artifact.binding.create` and
`artifact.checker_input.materialize` mappings.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8f1caf38-0170-489f-93be-2bbe21378bc2

📥 Commits

Reviewing files that changed from the base of the PR and between 2fb322b and 95090be.

📒 Files selected for processing (21)
  • .agent-loop/initiatives/WS-ART-001-immutable-artifact-storage/AUTH_HANDOFF.md
  • .agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md
  • .agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/CHUNK_MAP.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/DECISIONS.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/DISCOVERY.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/INTENT.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/PLAN.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/RISKS.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/STATUS.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-01-catalogue-reconciliation.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-02-prepared-feature-boundaries.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-03-internal-worker-activation.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-04-guide-activation.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05A-initial-submission-preparation.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05B-submission-binding-consumption.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05C-checker-remediation-submission.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05D-human-review-revision.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-06-checker-activation.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md
  • .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-08-conformance.md

Comment thread .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/DECISIONS.md Outdated
Comment thread .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/PLAN.md
@Abiorh001

Copy link
Copy Markdown
Collaborator Author

External review update: all 12 CodeRabbit findings from head 95090be5 were addressed in 834ff13b, and all 12 review threads are resolved. The durable response and refreshed trust bundle are committed. Required architecture, security, QA, product/ops, senior-engineering, and CI re-reviews passed with no blocking findings. CodeRabbit could not perform a second incremental analysis because its account review limit was reached, but its status is successful and every original comment is resolved against the repair diff. Exact-head Backend and Agent Gates remain the active hosted gates.

@abiorh-claw
abiorh-claw self-requested a review July 27, 2026 06:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants