Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .changeset/cloud-connection-provenance-anchors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
'@objectstack/cloud-connection': patch
---

Provenance comments in `@objectstack/cloud-connection` were re-anchored

Comment and docblock lines under `src/` that cited tracker numbers which no
longer resolve on GitHub now cite the commit in this repository's history that
decided the matter, and say in their own words what was decided. Comments
only: no route, error code, refusal text, type, export or runtime behaviour
changes.
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@
*
* ## Why an enumeration and not four more assertions
*
* The same reason as the `/meta` precedent (#8919,
* The same reason as the `/meta` precedent (commit b5378550e,
* `meta-write-door-capability-enumeration.test.ts`): a gate held by repetition
* drifts the moment someone adds a fifth route by copying whichever neighbour
* was nearest. `derives every mutating route the plugin mounts` builds the door
Expand All @@ -47,7 +47,7 @@
* ⚠️ The `GET` listing is deliberately NOT in this family. It is a read, and
* this card's ruling is about the four mutating doors; silently folding it in
* here would have decided its posture by accident. That posture has since been
* ruled on separately (#9011: authenticated floor, with `installedBy` and
* ruled on separately (commit 01074e551: authenticated floor, with `installedBy` and
* `storageDir` narrowed to `manage_metadata` holders) and is pinned in
* `marketplace-install-local-list-posture.test.ts` — so the filter below still
* means "not this family", never "ungated".
Expand Down Expand Up @@ -300,7 +300,7 @@ describe('#8976 — the mutating install-local doors are enumerated, not recited
// Without this, a refactor that stopped mounting the GET would leave the
// assertion above passing while silently proving less than it claims.
// The listing's OWN posture lives in
// `marketplace-install-local-list-posture.test.ts` (#9011); ⛔ the fix
// `marketplace-install-local-list-posture.test.ts` (commit 01074e551); ⛔ the fix
// for an unauthorized read there is a refusal, never an unmounted route
// — cloud#1287 made this mount unconditional so air-gapped boxes stop
// 404ing, and this assertion is what keeps that true.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.

/**
* [#9011] `GET /api/v1/marketplace/install-local` — the read door's posture.
* [commit 01074e551] `GET /api/v1/marketplace/install-local` — the read door's posture.
*
* ## THIS is the file that answers "is the installed-apps LISTING gated?"
*
Expand Down Expand Up @@ -299,7 +299,7 @@ describe('#9011 — a `manage_metadata` holder still gets the full payload', ()
expect(res.payload.data.storageDir).toBe(new LocalManifestSource(dir).dir);
const [item] = res.payload.data.items;
expect(item.installedBy).toBe('usr_operator');
// The pre-#9011 wire shape, intact for the caller who is entitled to it.
// The wire shape before commit 01074e551, intact for the caller who is entitled to it.
expect(Object.keys(item).sort()).toEqual(
['installedAt', 'installedBy', 'manifestId', 'packageId', 'version', 'versionId', 'withSampleData'],
);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@
* → lists currently installed marketplace packages. Requires an
* authenticated principal (anonymous → 401); `installedBy` and
* `storageDir` are served only to a `manage_metadata` holder
* (#9011). The four routes above require `manage_metadata`
* (commit 01074e551). The four routes above require `manage_metadata`
* outright (#8976).
*
* DELETE /api/v1/marketplace/install-local/:manifestId
Expand Down Expand Up @@ -95,7 +95,7 @@ const ROUTE_BASE = '/api/v1/marketplace/install-local';
*
* `manage_metadata` is ADR-0066 D1's authoring capability and the SAME key the
* platform's other metadata-write doors already require — `PUT`/`DELETE`
* `/api/v1/meta/:type/:name`, `POST /meta/_migrate-stored`, and since #8919 the
* `/api/v1/meta/:type/:name`, `POST /meta/_migrate-stored`, and since commit b5378550e the
* publish/rollback promotion verbs. These four routes are a metadata-write door
* by every measure that matters: `POST` hot-registers an inline manifest's
* objects into the shared registry and then runs `syncSchemas()` against the
Expand Down Expand Up @@ -998,7 +998,7 @@ export class MarketplaceInstallLocalPlugin implements Plugin {
* short list was served with `success: true` and nobody, anywhere, could
* have known.
*
* ## [#9011] Authenticated floor + field narrowing — the posture, ruled
* ## [commit 01074e551] Authenticated floor + field narrowing — the posture, ruled
*
* #8976 gated the four MUTATING doors and left this read as the only
* anonymous door on the surface: `handleList` opened on `this.readAll()`,
Expand Down Expand Up @@ -1810,15 +1810,15 @@ export class MarketplaceInstallLocalPlugin implements Plugin {
systemPermissions: Array.isArray(authz.systemPermissions) ? authz.systemPermissions : [],
};
} catch (err) {
// [#13279] `null` here means "nobody is authenticated", which is
// [commit 6a180e42d] `null` here means "nobody is authenticated", which is
// not what a permission-store outage established. Re-raised.
if (isAuthzStoreUnavailableError(err)) throw err;
return null;
}
};

/**
* [#9011] The ONE `401` this plugin issues — every door, one literal.
* [commit 01074e551] The ONE `401` this plugin issues — every door, one literal.
*
* The five routes now share an authenticated floor but NOT a capability
* requirement (the four writes demand `manage_metadata`; the read narrows
Expand Down
Loading