Skip to content

feat(cloudstore): record explicit prompt source attestations - #1547

Merged
dnlrsls merged 1 commit into
Gentleman-Programming:feat/prompt-inbox-foundation-trackerfrom
dnlrsls:feat/prompt-source-attestation-store
Sep 29, 2026
Merged

dnlrsls merged 1 commit into
Gentleman-Programming:feat/prompt-inbox-foundation-trackerfrom
dnlrsls:feat/prompt-source-attestation-store

Conversation

@dnlrsls

@dnlrsls dnlrsls commented Sep 29, 2026

Copy link
Copy Markdown
Member

🔗 Linked Issue

Closes #1458

Second bounded child of source-by-source reauthorization for open tracker #1464. Base is feat/prompt-inbox-foundation-tracker at f800a699, never main.

🏷️ PR Type

  • type:feature — New feature

📝 Summary

  • Add an append-only cloud audit table for explicit human source assertions, separate from registration and claim audit fields.
  • Require exact currently registered session owner and claimed prompt pair before recording the full (session, inbox, sync, owner project, prompt project) tuple with actor and timestamp.
  • No HTTP route, permission check, CLI, autosync authorization or remote delete in this slice.

📂 Changes

File Change
internal/cloud/cloudstore/cloudstore.go New attestation audit table migration.
internal/cloud/cloudstore/prompt_source_attestation.go Exact-tuple insert with independent audit fields; rejects missing claim/authority.
internal/cloud/cloudstore/prompt_source_attestation_test.go Registration, claim, mismatch, blank and repeated-audit regressions.

143 authored lines. Internal storage capability only: no user-facing behavior to document until the authenticated route and CLI children. Server must bind authenticated actor and current grants for both projects; this method intentionally grants nothing.

🧪 Test Plan

  • Focused: go test ./internal/cloud/cloudstore -run '^TestPromptSourceAttestation' -count=1 -v — PASS against a new disposable loopback Postgres instance (independent verifier; stopped and deleted after test).
  • Affected package: go test ./internal/cloud/cloudstore -count=1 — PASS against same disposable Postgres.
  • Additional: go vet ./internal/cloud/cloudstore, git diff --check — PASS. gofmt listing flags pre-existing CRLF of cloudstore.go, not an introduced Go formatting change; new files clean. Native review review-6f45fca85cba5543 approved and acknowledged. Test-first RED not observed: first test attempt skipped without DSN; real DB run verified GREEN only.
  • GitHub unit/E2E/plugin/lint/Windows/policy checks — pending at creation.

🤖 Automated Checks

CI pending; all required contexts must pass before normal merge.

✅ Contributor Checklist

💬 Notes for Reviewers

This audit row is not proof of historical local creation. A future authenticated server handler will verify the actor and current grants for both owner and prompt projects before calling this method. Pending local source mutations remain blocked until explicit per-source confirmation. No deletes or tracker merge queue yet.

@dnlrsls dnlrsls added the type:feature New feature label Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 09c02bf6-6ef3-4908-9a96-45fa57f07235

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dnlrsls
dnlrsls merged commit aee38de into Gentleman-Programming:feat/prompt-inbox-foundation-tracker Sep 29, 2026
15 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:feature New feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant