Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# WS-ART-001 Authorization Handoff

> The complete v0.1 dependency inventory and replacement sequencing are owned
> by `../WS-XINT-002-art-auth-end-to-end/`. This handoff remains the historical
> ART-03 through ART-06 baseline and must not be used to invent a missing AUTH
> action or capability during implementation.

ART owns hidden artifact behavior, canonical product resource facts, lifecycle
guards, surface manifests, and feature tests. AUTH owns ActionId/PermissionId
catalogues, service identities, fixed matrices, evaluator integration, grants,
Expand Down Expand Up @@ -89,3 +94,10 @@ An ART implementation contract stops if its required AUTH registration or
activation contract is absent, unmerged, inactive, differently mapped, or
targets a different resource fact shape. Planned catalogue presence, a local
action string, or hidden feature code is never executable authority.

Any dependency not enumerated by WS-XINT-002 is contract drift. Stop and amend
the cross-initiative plan; do not add a local action string, permission alias,
service identity, matrix row, or alternate prepared-capability path.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
`WS-XINT-002-01` must delete all six obsolete upload-session ActionIds and
PermissionIds, plus scheduler expiry membership, with no unavailable retained
row or compatibility alias; its enumerated deletion list is authoritative.
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# Activation Custody: WS-AUTH-001

The final v0.1 ART catalogue reconciliation, PREP extension, and activation
waves are superseded prospectively by
`../WS-XINT-002-art-auth-end-to-end/`. Existing rows below remain the trusted
baseline until WS-XINT-002-01 merges; no prose in either plan changes runtime
availability.
The reconciliation baseline is trusted `main` commit
`2fb322bd2249a5fe9d3fa706dc63f033074e38ce`: 76 PermissionIds, 81 ActionIds,
22 active actions, and 59 planned actions. Older counts below are explicitly
historical snapshots at their named commits, not the WS-XINT-002 entry state.

Comment thread
coderabbitai[bot] marked this conversation as resolved.
## Authority

This plan applies the merged `WS-XINT-001` handoffs to AUTH. It distinguishes:
Expand Down Expand Up @@ -169,6 +179,11 @@ WS-AUTH-001-XINT planning reconciliation
-> AUTH-16 aggregate conformance and live proof
```

For ART dependencies, replace the generic final two steps with the exact
WS-XINT-002 sequence: complete registration, prepared feature boundaries,
fixed internal services, guide, submission, checker, review artifact access, and
end-to-end conformance. AUTH-14 and AUTH-15 are not alternate activation paths.

Only one WS-AUTH implementation chunk is active at a time. ART, REV, and CON
may build hidden behavior in their own worktrees while real actions remain
planned, but each merged AUTH activation must converge from current trusted
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# Chunk Map: WS-AUTH-001 - Workstream Authorization Service

The complete ART-facing catalogue and runtime dependency is now planned in
`../WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md`. The historical ART custody
entries in this file remain baseline identifiers only until that planning
amendment is approved and its first reconciliation chunk merges.

## Rule

Only one chunk may be active at a time. Do not start the next chunk until the
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Chunk Map: WS-XINT-002 ART-AUTH End-to-End Contract

| Chunk | Purpose | Risk | Dependency |
|---|---|---|---|
| `WS-XINT-002-01` | Reconcile the entire ART catalogue, permissions, owners, migration parity, and fixed-service matrix while every new action stays planned. | L1 | approved plan |
| `WS-XINT-002-02` | Extend PREP with closed feature-owned typed composition contracts and ART lock plans; activate nothing. | L1 | 01 |
| `WS-XINT-002-03` | Activate verifier, scheduler scan, and put resolver services from merged ART recovery evidence. | L1 | 02 plus ART 02C/02D evidence |
| `WS-XINT-002-04` | Activate guide ingest, guide binding, and guide read in evidence-ordered substeps. | L1 | 02 plus ART 03A/03B evidence |
| `WS-XINT-002-05A` | Activate initial contributor bundle preparation and durable ready admission. | L1 | 02 plus ART 04A-C evidence |
| `WS-XINT-002-05B` | Activate fresh human Submission creation plus fixed artifact binding with exactly-once admission consumption. | L1 | 05A plus ART 05/TASK evidence |
| `WS-XINT-002-05C` | Activate checker-remediation submission preparation/creation against one final CheckerRun. | L1 | 05B plus checker remediation evidence |
| `WS-XINT-002-05D` | Activate human-review revision preparation/creation against exact revision obligations. | L1 | 05B plus REV revision-preparation evidence |
| `WS-XINT-002-06` | Activate pre/post-submit materialization and checker output/binding. | L1 | 02 plus ART 04B/06A/06B evidence |
| `WS-XINT-002-07` | Activate lease-scoped review packets and finding/response evidence binding. | L1 | 02 plus merged ART/REV manifests |
| `WS-XINT-002-08` | Prove complete catalogue, least privilege, revocation, replay, concurrency, audit, and live lifecycle conformance. | L1 | 03-07 including 05A-D |

Chunks 03-07 may be split only by the evidence boundaries named above. A split
cannot add catalogue values, permissions, identities, matrix rows, or a second
runtime protocol; such a discovery is contract drift and returns to planning.
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Decisions: WS-XINT-002 ART-AUTH End-to-End Contract

1. The dependency is owned end to end by a cross-initiative plan, not by ART-03A.
2. One outer ZIP replaces the six upload-session actions with
`artifact.submission_bundle.prepare`; no compatibility aliases or retained
unavailable rows remain. The exact deleted ActionId and PermissionId values
are `artifact.upload_session.create`, `artifact.upload_session.read`,
`artifact.upload_item.write`, `artifact.upload_session.seal`,
`artifact.upload_session.cancel`, and `artifact.upload_session.expire`.
3. Initial, checker-remediation, and human-review revision submissions share the
public preparation/create actions; each has an exact closed typed context.
4. Reviewer packet materialization is a fixed-service action plus a separate
human lease decision. Neither substitutes for the other.
5. Finding and response evidence require separate human operation authority and
fixed artifact binding authority.
6. Existing artifact materializer and binding identities gain review-packet and
review-evidence memberships; scheduler loses upload-session-expiry
membership. No new service identity is introduced.
7. Operators request and inspect; fixed internal services execute recovery. Artifact
audit is not broadened implicitly to general Audit Authority.
8. Catalogue and reusable PREP dependencies are front-loaded. Activation stays
evidence-gated and cannot be eliminated safely.
9. The simple contribution loop applies: planning does not require a signed
start/cancel event or merge-intent file.
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
# Discovery: WS-XINT-002 ART-AUTH End-to-End Contract

## Observations on trusted main

- Baseline commit `2fb322bd2249a5fe9d3fa706dc63f033074e38ce` contains
76 PermissionIds and 81 ActionIds: 22 active and 59 planned. All current
artifact actions are planned and unavailable.
- The fixed service matrix has seven artifact identities and eleven memberships:
verifier, put resolver, scheduler, binding, guide reader, materializer, and
checker output.
- Six planned upload-session actions still exist even though the approved ART
design uses one continuous outer-ZIP preparation surface.
- `artifact.submission_bundle.prepare`,
`artifact.review_packet.materialize`, and
`artifact.review_evidence.binding.create` are absent from the catalogue.
- Human review evidence actions already exist as planned:
`review.finding_evidence.ingest` maps to `review.decision`, and
`review.finding_response_evidence.ingest` maps to `submission.create`.
- `PreparedAuthorizationService` in
`backend/app/modules/authorization/prepared.py` binds an opaque handle to the
exact service, session, root transaction, action, actor, scope, idempotency
key, and canonical request digest. It is single-use and rejects copying and
serialization.
- `_scope_from_resource()` supports only actor-self and admin-mutation resource
types. `AuthorizationService._prepare_prelocked()` rejects every service
action as unavailable and has no assigned-contributor or ART resource plan.
- The existing ART 03A worktree has substantial uncommitted implementation plus
a preserved `AUTH_END_TO_END_CONTRACT.md`. It must not be edited or mixed into
this planning change.
- AUTH-11A is merged on `main`; the earlier migration dependency is resolved.

## Existing plans affected

- `WS-ART-001` chunks 03A-07 cover guide ingest/use, one-ZIP submission
admission, submission binding, checker materialization/output, and recovery.
- `WS-AUTH-001/ACTIVATION_CUSTODY.md` assigns the existing 25 ART actions to
eight AUTH custodians but does not contain the final submission/review action
set.
- `WS-AUTH-001-14` mixes broader submission/checker cutover with artifact
dependencies and must not be treated as an alternate ART activation path.
- REV plans own lease, decision, finding, response, and revision facts. They do
not grant artifact bytes directly.

## Confirmed gaps

1. One closed catalogue migration must add the three missing actions and remove
the six obsolete upload-session actions and permissions without aliases.
2. The service matrix must remove scheduler expiry and add review packet and
review-evidence memberships to existing identities.
3. PREP needs a closed extension mechanism for exact feature-owned typed
resource contexts and lock plans; a generic callback or dictionary context
would violate the authorization boundary.
4. Guide ingest, submission preparation/finalization, binding, review packet,
and evidence binding need explicit transaction choreographies and crossed
concurrency proof.
5. Initial, checker-remediation, and human-review revision submissions use the
same public action but different closed locked facts. Checker remediation is
rooted in one final `needs_revision` CheckerRun without human-review facts.
Human-review revision facts include exact predecessor, active preparation
head/digest, required responses/evidence, replacement assignment, limits,
deadline, and predecessor advancement fencing.
6. Checker authority must remain byte-bounded and cannot create or consume a
Submission.

## Assumptions requiring implementation-time confirmation

- `Submission`, not a separate `SubmissionVersion` table, remains the immutable
version node linked by `supersedes_submission_id`.
- Existing service identities are sufficient; review packet uses the artifact
materializer and review evidence binding uses the artifact binding service.
- Operator artifact audit stays Operator-only unless a separately reviewed
exact Audit Authority projection is approved.
45 changes: 45 additions & 0 deletions .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/INTENT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# Intent: WS-XINT-002 ART-AUTH End-to-End Contract

## Outcome

Freeze and deliver the complete v0.1 authorization surface required by the
artifact lifecycle so ART implementation does not discover new AUTH catalogue,
principal, matrix, prepared-capability, or evidence dependencies mid-chunk.

## Why now

The existing ART plan defines guide ingestion, contributor ZIP admission,
submission binding, checker materialization, recovery, and later review use in
separate chunks. AUTH currently owns 25 planned ART actions, but the plan still
contains six obsolete upload-session actions, omits three required end-to-end
actions, and its prepared protocol cannot consume ART product resource types.
That makes ART repeatedly stop for newly discovered AUTH work.

## Boundaries

- AUTH owns ActionId/PermissionId registration, mappings, availability,
fixed-service identities and matrices, authority locking/evaluation, prepared
handles, and decision evidence.
- ART owns bytes, commitments, manifests, storage/admission facts, lifecycle
guards, resource-context composition ports, and hidden feature behavior.
- Project, task, submission, checker, and review modules own their domain rows,
lock order after AUTH authority locking, and lifecycle invariants.
- Registration and reusable runtime support may merge before feature behavior,
but every new action remains unavailable until its exact hidden behavior and
crossed-state evidence exist.

## Non-goals

- No ART, REV, task, submission, or checker implementation in this planning
amendment.
- No action activation, grant broadening, compatibility alias, generic artifact
download permission, dynamic service grants, or provider access from AUTH.
- No client delivery, marketplace, external adapter, or post-v0.1 surface.

## Proof strategy

Each implementation chunk must prove closed catalogue/database parity, typed
resource composition, least-privilege actor/service admission, transaction-local
single-use consumption, atomic decision evidence, crossed revocation/staleness,
and at least 90 percent coverage for materially changed backend subsystems.
Full-suite coverage remains hosted in GitHub Actions.
101 changes: 101 additions & 0 deletions .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/PLAN.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
# Plan: WS-XINT-002 ART-AUTH End-to-End Contract

## Design

Deliver the dependency in two front-loaded AUTH foundations followed by thin,
evidence-gated activation waves:

1. Reconcile the complete v0.1 catalogue and static service matrix once.
2. Extend PREP once with closed typed feature integration contracts.
3. Activate fixed internal recovery services before any durable provider work.
4. Activate guide ingest/use only after the matching hidden ART behavior.
5. Activate initial contributor preparation, then atomic Submission/binding
consumption, then checker-remediation and human-review revision variants as
separate reviewable gates.
6. Activate checker materialization/output only after exact checker behavior.
7. Activate reviewer packet and evidence binding only after both ART and REV
provide their hidden typed facts and lease/revision guards.
8. Run end-to-end conformance and crossed-state proof.

Registration is deliberately complete up front. Activation remains separate
because AUTH cannot safely allow an action until the protected implementation,
resource composer, and denial tests exist. Each activation chunk may only
connect a previously registered action to an exact merged feature manifest and
change its availability; it may not invent another action or permission.

## Canonical action and permission set

### Human-facing actions

| ActionId | PermissionId | Authority |
|---|---|---|
| `artifact.guide_source.ingest` | `artifact.guide_source.ingest` | exact Project Manager project grant |
| `artifact.submission_bundle.prepare` | `submission.create` | active assigned contributor |
| `submission.create` | `submission.create` | fresh active assigned contributor |
| `review.context.read` | `submission.read_for_review` | exact active reviewer lease |
| `review.finding_evidence.ingest` | `review.decision` | active reviewer lease and exact review context |
| `review.finding_response_evidence.ingest` | `submission.create` | contributor with exact revision obligation |

### Fixed-service actions

| ActionId | PermissionId | Service identity |
|---|---|---|
| `artifact.verification.execute` | `artifact.verification.execute` | `workstream.artifact.verifier` |
| `artifact.pending_work.scan` | `artifact.pending_work.scan` | `workstream.artifact.scheduler` |
| `artifact.put_attempt.resolve` | `artifact.put_attempt.resolve` | `workstream.artifact.put_resolver` |
| `artifact.guide_source.read` | `artifact.guide_source.read` | `workstream.artifact.guide_reader` |
| `artifact.guide_source.binding.create` | `artifact.binding.create` | `workstream.artifact.binding` |
| `artifact.submission.binding.create` | `artifact.binding.create` | `workstream.artifact.binding` |
| `artifact.pre_submit.checker_input.materialize` | `artifact.checker_input.materialize` | `workstream.artifact.materializer` |
| `artifact.post_submit.checker_input.materialize` | `artifact.checker_input.materialize` | `workstream.artifact.materializer` |
| `artifact.checker_output.write` | `artifact.checker_output.write` | `workstream.artifact.checker_output` |
| `artifact.checker_output.binding.create` | `artifact.binding.create` | `workstream.artifact.binding` |
| `artifact.review_packet.materialize` | `artifact.review_packet.materialize` | `workstream.artifact.materializer` |
| `artifact.review_evidence.binding.create` | `artifact.binding.create` | `workstream.artifact.binding` |
Comment thread
coderabbitai[bot] marked this conversation as resolved.

The existing bounded Operator actions remain unchanged. Fixed recovery services execute
recovery; Operators request retry/reconciliation and inspect bounded state.
There is no generic artifact-download action.

Submission preparation has three closed context variants under the same action:
initial submission; checker remediation rooted in the exact final
`needs_revision` CheckerRun; and human-review revision rooted in the exact
revision obligation. Checker remediation records the server-derived
`remediation_source_checker_run_id`, immediate same-task predecessor, existing
locked task context, and current `allow_review`; it has no ReviewFinding
response, revision preparation, human revision deadline/round consumption,
reviewer contribution, or synthetic human actor.

## Universal durable-boundary protocol

Every durable ART/product mutation must:

1. authorize before accepting expensive or sensitive bytes;
2. prepare authority inside the caller-owned root transaction;
3. lock AUTH actor/link/grant or fixed-service authority first;
4. lock and recompose exact feature facts through typed feature-owned ports;
5. consume the opaque capability against the final resource context;
6. stage bounded decision evidence and the protected mutation atomically;
7. commit once before provider I/O; and
8. obtain fresh authority for each later binding or product mutation.

Copied, serialized, replayed, cross-session, cross-action, cross-resource,
replaced-transaction, revoked, stale, or already consumed handles deny.

## Ownership rule

AUTH evaluates authority but does not load feature rows or encode product
lifecycle. Feature modules expose closed typed composers/loaders and own their
locks and invariants. ART orchestrates bytes and receives only opaque prepared
handles plus typed decisions; it never imports AUTH repositories.

## Verification

- focused PostgreSQL catalogue/migration/PREP/concurrency suites per chunk;
- static route/command/action and service-matrix parity gates;
- stale-action and forbidden-import scans;
- 90 percent coverage for materially changed backend subsystems;
- hosted GitHub Actions full backend suite preserving the 78 percent global
floor; and
- security, architecture, QA, product/ops, senior, CI, docs, reuse, and test
delta review as applicable to each L1 chunk.
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Review Log: WS-XINT-002

## Planning review

Architecture, security/auth, QA/test, product/ops, senior engineering, and CI
integrity initially returned blocking findings. The plan was repaired to split
submission activation, add checker remediation, require paired reviewer/service
authority, complete every chunk contract, and pass repository documentation
gates. All six tracks then passed with no blocking findings.

## PR #209 external review

CodeRabbit raised twelve actionable comments on the initial PR head
`95090be5`. All were accepted and repaired as recorded in
`reviews/WS-XINT-002-PLAN-external-review-response.md`. Focused internal
security/architecture re-review and exact-head hosted checks are required after
the repair commit.

Product/ops re-review found that CodeRabbit's 05C atomic-fact suggestion would
prematurely include `allow_review` in Submission creation. The repair instead
keeps `allow_review` in the later checker/routing spine for the new Submission.
Loading
Loading