diff --git a/.changeset/cloud-connection-provenance-anchors.md b/.changeset/cloud-connection-provenance-anchors.md new file mode 100644 index 00000000000..36304ce36af --- /dev/null +++ b/.changeset/cloud-connection-provenance-anchors.md @@ -0,0 +1,11 @@ +--- +'@objectstack/cloud-connection': patch +--- + +Provenance comments in `@objectstack/cloud-connection` were re-anchored + +Comment and docblock lines under `src/` that cited tracker numbers which no +longer resolve on GitHub now cite the commit in this repository's history that +decided the matter, and say in their own words what was decided. Comments +only: no route, error code, refusal text, type, export or runtime behaviour +changes. diff --git a/packages/cloud-connection/src/marketplace-install-local-capability-enumeration.test.ts b/packages/cloud-connection/src/marketplace-install-local-capability-enumeration.test.ts index f57b6672102..85565c13e25 100644 --- a/packages/cloud-connection/src/marketplace-install-local-capability-enumeration.test.ts +++ b/packages/cloud-connection/src/marketplace-install-local-capability-enumeration.test.ts @@ -37,7 +37,7 @@ * * ## Why an enumeration and not four more assertions * - * The same reason as the `/meta` precedent (#8919, + * The same reason as the `/meta` precedent (commit b5378550e, * `meta-write-door-capability-enumeration.test.ts`): a gate held by repetition * drifts the moment someone adds a fifth route by copying whichever neighbour * was nearest. `derives every mutating route the plugin mounts` builds the door @@ -47,7 +47,7 @@ * ⚠️ The `GET` listing is deliberately NOT in this family. It is a read, and * this card's ruling is about the four mutating doors; silently folding it in * here would have decided its posture by accident. That posture has since been - * ruled on separately (#9011: authenticated floor, with `installedBy` and + * ruled on separately (commit 01074e551: authenticated floor, with `installedBy` and * `storageDir` narrowed to `manage_metadata` holders) and is pinned in * `marketplace-install-local-list-posture.test.ts` — so the filter below still * means "not this family", never "ungated". @@ -300,7 +300,7 @@ describe('#8976 — the mutating install-local doors are enumerated, not recited // Without this, a refactor that stopped mounting the GET would leave the // assertion above passing while silently proving less than it claims. // The listing's OWN posture lives in - // `marketplace-install-local-list-posture.test.ts` (#9011); ⛔ the fix + // `marketplace-install-local-list-posture.test.ts` (commit 01074e551); ⛔ the fix // for an unauthorized read there is a refusal, never an unmounted route // — cloud#1287 made this mount unconditional so air-gapped boxes stop // 404ing, and this assertion is what keeps that true. diff --git a/packages/cloud-connection/src/marketplace-install-local-list-posture.test.ts b/packages/cloud-connection/src/marketplace-install-local-list-posture.test.ts index 06ba45c41d6..cbb95b03884 100644 --- a/packages/cloud-connection/src/marketplace-install-local-list-posture.test.ts +++ b/packages/cloud-connection/src/marketplace-install-local-list-posture.test.ts @@ -1,7 +1,7 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. /** - * [#9011] `GET /api/v1/marketplace/install-local` — the read door's posture. + * [commit 01074e551] `GET /api/v1/marketplace/install-local` — the read door's posture. * * ## THIS is the file that answers "is the installed-apps LISTING gated?" * @@ -299,7 +299,7 @@ describe('#9011 — a `manage_metadata` holder still gets the full payload', () expect(res.payload.data.storageDir).toBe(new LocalManifestSource(dir).dir); const [item] = res.payload.data.items; expect(item.installedBy).toBe('usr_operator'); - // The pre-#9011 wire shape, intact for the caller who is entitled to it. + // The wire shape before commit 01074e551, intact for the caller who is entitled to it. expect(Object.keys(item).sort()).toEqual( ['installedAt', 'installedBy', 'manifestId', 'packageId', 'version', 'versionId', 'withSampleData'], ); diff --git a/packages/cloud-connection/src/marketplace-install-local-plugin.ts b/packages/cloud-connection/src/marketplace-install-local-plugin.ts index ce38ed61118..2ef0f0ae8ba 100644 --- a/packages/cloud-connection/src/marketplace-install-local-plugin.ts +++ b/packages/cloud-connection/src/marketplace-install-local-plugin.ts @@ -32,7 +32,7 @@ * → lists currently installed marketplace packages. Requires an * authenticated principal (anonymous → 401); `installedBy` and * `storageDir` are served only to a `manage_metadata` holder - * (#9011). The four routes above require `manage_metadata` + * (commit 01074e551). The four routes above require `manage_metadata` * outright (#8976). * * DELETE /api/v1/marketplace/install-local/:manifestId @@ -95,7 +95,7 @@ const ROUTE_BASE = '/api/v1/marketplace/install-local'; * * `manage_metadata` is ADR-0066 D1's authoring capability and the SAME key the * platform's other metadata-write doors already require — `PUT`/`DELETE` - * `/api/v1/meta/:type/:name`, `POST /meta/_migrate-stored`, and since #8919 the + * `/api/v1/meta/:type/:name`, `POST /meta/_migrate-stored`, and since commit b5378550e the * publish/rollback promotion verbs. These four routes are a metadata-write door * by every measure that matters: `POST` hot-registers an inline manifest's * objects into the shared registry and then runs `syncSchemas()` against the @@ -998,7 +998,7 @@ export class MarketplaceInstallLocalPlugin implements Plugin { * short list was served with `success: true` and nobody, anywhere, could * have known. * - * ## [#9011] Authenticated floor + field narrowing — the posture, ruled + * ## [commit 01074e551] Authenticated floor + field narrowing — the posture, ruled * * #8976 gated the four MUTATING doors and left this read as the only * anonymous door on the surface: `handleList` opened on `this.readAll()`, @@ -1810,7 +1810,7 @@ export class MarketplaceInstallLocalPlugin implements Plugin { systemPermissions: Array.isArray(authz.systemPermissions) ? authz.systemPermissions : [], }; } catch (err) { - // [#13279] `null` here means "nobody is authenticated", which is + // [commit 6a180e42d] `null` here means "nobody is authenticated", which is // not what a permission-store outage established. Re-raised. if (isAuthzStoreUnavailableError(err)) throw err; return null; @@ -1818,7 +1818,7 @@ export class MarketplaceInstallLocalPlugin implements Plugin { }; /** - * [#9011] The ONE `401` this plugin issues — every door, one literal. + * [commit 01074e551] The ONE `401` this plugin issues — every door, one literal. * * The five routes now share an authenticated floor but NOT a capability * requirement (the four writes demand `manage_metadata`; the read narrows