diff --git a/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts b/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts index 183527117ed..724126ff5b9 100644 --- a/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts +++ b/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts @@ -1,10 +1,10 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. /** - * #7987 (+ #8676) — `sys_account`'s credential columns must not come back on + * #7987 (+ commit d6e80b28b) — `sys_account`'s credential columns must not come back on * the generic data path. * - * [#8676] The file was #7987's three OAuth columns; it now covers the object's + * [commit d6e80b28b] The file was #7987's three OAuth columns; it now covers the object's * other two credential columns as well — `password` and * `previous_password_hashes`, the one-way hashes of ADR-0100's third channel. * They belong here rather than in a fixture of their own because they are the @@ -88,9 +88,9 @@ const PLANTED = { const TOKEN_COLUMNS = ['access_token', 'refresh_token', 'id_token'] as const; /** - * [#8676] The two one-way password hashes on the same object — ADR-0100's third + * [commit d6e80b28b] The two one-way password hashes on the same object — ADR-0100's third * channel. They serialized on this very read path alongside the OAuth columns - * (the #8676 key list was captured on this fixture's own ablation run), through + * (commit d6e80b28b's key list was captured on this fixture's own ablation run), through * the same two barriers that miss them: `collectMaskedReadFields` keys on the * field TYPE and exempts `managedBy: 'better-auth'`, while these are * `text` / `textarea`. Asserted through the SAME persona matrix below, because @@ -277,7 +277,7 @@ describe('#7987: sys_account OAuth tokens never serialize on the generic data pa assertNoCredentialColumns(row); } - // [#8676] The same spelling attack aimed at the password hashes, from both + // [commit d6e80b28b] The same spelling attack aimed at the password hashes, from both // personas. The member's own row is the one that matters most here: the // `sys_account_self` policy grants the read, so this is a LEGAL request for // their own record that must still come back without the hash. @@ -334,11 +334,11 @@ describe('#7987: sys_account OAuth tokens never serialize on the generic data pa // exactly one predicate — `internal === true` — so a column without the // flag is refused (ADR-0112 code + status). // - // ⚠️ Its instance changed with #8676, and only its instance. This test used + // ⚠️ Its instance changed with commit d6e80b28b, and only its instance. This test used // to spell the predicate with `password`, because #7987 deliberately left // that column unflagged and the test marked THAT card's scope boundary // ("a column that is **not flagged** … are deliberately NOT `internal`"). - // #8676 flags it, so the premise of `password`-as-example disappears while + // Commit d6e80b28b flags it, so the premise of `password`-as-example disappears while // the proposition itself is untouched: `scope` is an ordinary unflagged // `sys_account` column and stands in as the example. What is NOT weakened // is the guard — no ADR-0100 carve-out was added, and the positive arm @@ -361,7 +361,7 @@ describe('#7987: sys_account OAuth tokens never serialize on the generic data pa it('[#8676] `password` and `previous_password_hashes` are stripped, and reachable only through the accessor', async () => { // The card's own assertions, both directions. These are one-way password // hashes — ADR-0100's third channel — and they serialized on the generic - // data API before #8676: to an admin for every user's row, and to a member + // data API before commit d6e80b28b: to an admin for every user's row, and to a member // for their own. const rows: any[] = await ql.find('sys_account', { where: { id: memberAccountId }, diff --git a/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts b/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts index 8fc843b3a4a..0c4384ea823 100644 --- a/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts +++ b/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts @@ -30,7 +30,7 @@ // hand-roll better-auth's signed-cookie contract with // `/admin/stop-impersonating` and silently detach the #8243 bearer-rotation // hook. It is a better-auth PLUGIN endpoint with only the authorization -// predicate replaced, and since #11686 that predicate is the consolidated +// predicate replaced, and since commit 7131f12bf that predicate is the consolidated // authority `hasPlatformAdminStanding`. `has-permission` (#11900, ruled // 2026-08-25) is a third shape: a permission QUERY, raw-mounted WITHOUT // the refusing judge — the platform admin's query is answered from the @@ -59,7 +59,7 @@ // then folds back into `positions[]`. A working "Set Platform Role" // button would be a supported, gated, one-user-at-a-time channel for // resurrecting the dual identity representation the 2026-08-18 Option-3 -// veto killed. So the maintainer retired the CONSOLE ACTION (PR #11530) +// veto killed. So the maintainer retired the CONSOLE ACTION (commit 033a34c7c) // and left the vendor ROUTE mounted and vendor-gated, byte for byte. // // ⛔ THEREFORE: a `403` from any of those eight is the system working. Do not diff --git a/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts b/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts index 45cc713b5fa..3307216482e 100644 --- a/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts +++ b/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts @@ -76,7 +76,7 @@ // gate verdict and not a payload the server rejects for everyone. // // `shaded-vendor-gate` (1 route: `remove-user`) — the two halves belong to -// DIFFERENT layers, which is why it is neither of its neighbours. #11477 +// DIFFERENT layers, which is why it is neither of its neighbours. Commit 6dd3e6968 // gave the route the raw-mount shading `ban-user` already had, so an // ObjectStack gate answers the refusal (member 403 PERMISSION_DENIED, anon // 401 UNAUTHENTICATED) — but the mount DELEGATES rather than @@ -88,7 +88,7 @@ // The both-sides contrast is therefore not a 2xx but a DIFFERENCE: the // member and the admin hear two different refusals, which is what proves // the member's 403 is an authorization verdict and not a blanket refusal. -// The bucket also carries the #11477 negative — a member must never again +// The bucket also carries commit 6dd3e6968's negative — a member must never again // see the break-glass guard's `409 LAST_LOCAL_CREDENTIAL`, which before the // shading was answered ahead of every authorization layer and VARIED WITH // THE TARGET, disclosing per-record state to a caller entitled to none. @@ -336,7 +336,7 @@ function expectationsFor(targetUserId: string): Record body: { userId: targetUserId }, }, - // ── #11477 — shaded for ORDERING, still admitted by the vendor ───────── + // ── Commit 6dd3e6968 — shaded for ORDERING, still admitted by the vendor ─ // // The only member of its bucket, and the bucket exists because this route // genuinely has a third shape rather than because the other two did not @@ -345,7 +345,7 @@ function expectationsFor(targetUserId: string): Record // owned by different layers: // // refusal → ObjectStack's gate (403 PERMISSION_DENIED), because the - // mount answers first. That is #11477's whole point: the + // mount answers first. That is commit 6dd3e6968's whole point: the // break-glass `hooks.before` guard used to answer an // authenticated non-admin BEFORE any authorization ran, and // its 409 differed per target — a per-record disclosure. @@ -634,7 +634,7 @@ describe('#9482 C9: every derived /admin/ route refuses a non-admin', () => { }, 600_000); it('the shaded vendor route refuses a non-admin from the ObjectStack gate, before the break-glass guard', async () => { - // #11477. The both-sides contrast here is NOT a 2xx — it is that the two + // Commit 6dd3e6968. The both-sides contrast here is NOT a 2xx — it is that the two // callers hear DIFFERENT refusals. A member is turned away by ObjectStack's // gate (`PERMISSION_DENIED`) and a platform admin gets past it only to be // turned away by the vendor's (`YOU_ARE_NOT_ALLOWED_*`, #9969). Two @@ -653,7 +653,7 @@ describe('#9482 C9: every derived /admin/ route refuses a non-admin', () => { expect(member.status, `${route} member: ${member.body}`).toBe(403); expect(member.code, `${route} member code: ${member.body}`).toBe('PERMISSION_DENIED'); - // ⛔ The load-bearing negative. Before #11477 the break-glass + // ⛔ The load-bearing negative. Before commit 6dd3e6968 the break-glass // `hooks.before` guard answered an authenticated non-admin ahead of every // authorization layer, and its answer varied with the TARGET — a // per-record disclosure to a caller entitled to nothing. A member must @@ -720,7 +720,7 @@ describe('#9482 C9: every derived /admin/ route refuses a non-admin', () => { // transaction, so this route answers the authorization question like // every other member of the bucket and needs no exception. // - // ⚠️ #11477 moved `remove-user` OUT of this bucket entirely — its raw + // ⚠️ Commit 6dd3e6968 moved `remove-user` OUT of this bucket entirely — its raw // mount now answers a member from ObjectStack's gate // (`403 PERMISSION_DENIED`) before better-auth is reached at all, so the // vendor-vocabulary rule below no longer describes it. It lives in diff --git a/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts b/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts index 322547bc1f2..5807f02b701 100644 --- a/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts +++ b/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts @@ -9,7 +9,7 @@ // "refused outright (#4757)", on the reasoning that "nothing was ever queried" // must not read as "nothing to authorize". `attachment-access-hooks.ts` carries // exactly that refusal, and `attachment-access-hooks.test.ts` pins it against a -// wired engine (#9797). This file pins it END TO END, on the real stack, where +// wired engine (commit 1258dcaee). This file pins it END TO END, on the real stack, where // RBAC and plugin-sharing are in the path and the session is a real one. // // ## History — this file's original verdict has been OVERTAKEN, twice @@ -20,7 +20,7 @@ // the `where === undefined` check. That was a PRODUCT gap (#9719), and this // file deliberately declined to pin the behaviour of the day. // -// It has since been fixed. #9719/PR #9797 added an opt-in whole-operation +// It has since been fixed. #9719/commit 1258dcaee added an opt-in whole-operation // dispatch to the engine, which #9974 renamed `dispatchUnscopedMultiWrite` when // it was ruled onto `beforeUpdate` as well. `attachment-access-hooks.ts` // declares it on both sys_attachment write registrations, so the #4757 refusal @@ -35,7 +35,7 @@ // properties that look identical on a fixture whose rows split entitled/not — // which is exactly the fixture the first block below uses. Measured on this // suite: with `dispatchUnscopedMultiWrite` removed from BOTH registrations and -// service-storage rebuilt (the pre-#9797 world), the first block stays 5/5 +// service-storage rebuilt (the world before commit 1258dcaee), the first block stays 5/5 // GREEN. It cannot see the refusal it is named for. // // So the second block seeds the ONE fixture that separates them: a caller who @@ -163,7 +163,7 @@ describe('sys_attachment delete gate under an unscoped multi-delete (#9483)', () it('an unscoped multi-delete is refused OUTRIGHT — on its shape — and deletes NOTHING', async () => { // `{ multi: true }` with neither id nor where composes an AST over the whole - // table. Since #9797 the refusal that answers is #4757's whole-operation + // table. Since commit 1258dcaee the refusal that answers is #4757's whole-operation // one, dispatched BEFORE any row is resolved — not the per-row gate, which // on this fixture would also have refused (the member is the uploader of // one row and neither uploader nor parent-editor of the other). @@ -193,7 +193,7 @@ describe('sys_attachment delete gate under an unscoped multi-delete (#9483)', () it('an empty `where: {}` reaches the same verdict by a DIFFERENT rule — the per-row gate', async () => { // ⚠️ Same outcome, deliberately different mechanism, and the difference is - // load-bearing. #9797 scoped the whole-operation dispatch to a delete with + // load-bearing. Commit 1258dcaee scoped the whole-operation dispatch to a delete with // NO `where` at all; a match-all `where: {}` is a real query, so it is NOT // refused on shape — it is refused here only because this caller cannot // have the foreign row. Asserting the per-row message is what keeps that @@ -259,7 +259,7 @@ describe('sys_attachment delete gate under an unscoped multi-delete (#9483)', () // whole-operation rule or from the per-row gate, because that fixture holds one // row the caller may not touch. Here the caller uploaded BOTH rows, so the // per-row gate has nothing to refuse — anything that still refuses is refusing -// the SHAPE. Pre-#9797 this exact call resolved and emptied the table. +// the SHAPE. Before commit 1258dcaee this exact call resolved and emptied the table. // ───────────────────────────────────────────────────────────────────────────── describe('sys_attachment unscoped multi-delete is refused on its SHAPE, not on entitlement (#9483)', () => { @@ -352,7 +352,7 @@ describe('sys_attachment unscoped multi-delete is refused on its SHAPE, not on e }); it('refuses `{ multi: true }` with no id and no where — even though the caller may delete every matched row', async () => { - // #9719's measured wipe, end to end: before PR #9797 this call RESOLVED and + // #9719's measured wipe, end to end: before commit 1258dcaee this call RESOLVED and // took both rows (2 -> 0). The per-row gate licenses each row individually, // so nothing but the whole-operation #4757 rule can refuse here — which is // what makes this the case that detects its removal. diff --git a/packages/qa/dogfood/test/authz-conformance.matrix.ts b/packages/qa/dogfood/test/authz-conformance.matrix.ts index 6d7e54d01b0..0ac6f1b3428 100644 --- a/packages/qa/dogfood/test/authz-conformance.matrix.ts +++ b/packages/qa/dogfood/test/authz-conformance.matrix.ts @@ -93,7 +93,7 @@ // silencing that particular red costs an enforcement site rather than a // `covers` append on a row that records an absence. // -// [#8711] That completeness is over ROUTES, not over primitives: a primitive +// [commit 2ce1eb41b] That completeness is over ROUTES, not over primitives: a primitive // enforced by a predicate inside an existing resolver adds no entry point, so // it can be neither UNCLASSIFIED nor STALE. Measured against the rows below: // 44 of 51 carry no `covers` key at all (7 rows, 15 keys, every one an @@ -390,12 +390,12 @@ export const AUTHZ_CONFORMANCE: AuthzPrimitive[] = [ // mass-revoked) and the 0/1 storage shape the primary driver returns is // judged as well as a literal `false`. // - // [#8711] Both rows carry NO `covers`, and that is a statement about the + // [commit 60ade586e] Both rows carry NO `covers`, and that is a statement about the // RATCHET, not an omission: `discover()` enumerates HTTP entry points from a // curated per-file probe table, and a predicate inside an existing resolver // adds no entry point — so neither flag could ever have surfaced as // UNCLASSIFIED during the whole period it was inert. These two rows restore - // the ledger's stated invariant. [Resolved — maintainer ruling on #8711, + // the ledger's stated invariant. [Resolved — maintainer ruling (commit 2ce1eb41b), // 2026-08-15] The invariant's advertised SCOPE is narrowed to what the // ratchet can check, not the ratchet widened to reach in-resolver // predicates like this one — widening was measured unachievable in general @@ -408,7 +408,7 @@ export const AUTHZ_CONFORMANCE: AuthzPrimitive[] = [ enforcement: 'core/security/resolve-authz-context.ts step 6a — isRowActive gates BOTH halves, and only both hold it: (i) only ACTIVE position ids collect their `sys_position_permission_set` linkage, so a deactivated position carries no bound set; (ii) the deactivated NAME is dropped from `grants.positions`, because resolvePermissionSetsForContext requests positions as permission-set NAMES and a name left standing resolves the same grant one layer down', note: 'Only a name whose `sys_position` row is EXPLICITLY deactivated is dropped — a name with no row at all (`org_owner`, a membership-derived role, the built-in `everyone` audience anchor) has no flag to read and is untouched. Deliberately NOT a blanket revocation of the sets themselves: a set held via BOTH a deactivated position AND a direct user grant still resolves, since the direct grant is a different grant (resolve-authz-context.test.ts pins exactly that case). Symmetrically, the WRITE gates and blast-radius reads in plugin-security (assertAudienceAnchorBindingGate, setsBoundToPosition, the delegated-admin surfaces) stay UNFILTERED on purpose — dropping a deactivated row there would make a refused binding permitted, narrow a delegate\'s boundary, and make a deactivated position unmanageable. Unit-proven in core/security/resolve-authz-context.test.ts (a deactivated position stops granting its sets; an active one still grants; an absent column grants; the 0/1 shape deactivates; deactivating ONE position leaves the others granting) + core/security/row-active.test.ts. Not HIGH_RISK for the same reason as `permission-set-active`.' }, - // ── ADR-0091 D1/D2 — grant validity windows (#8811) ─────────────────── + // ── ADR-0091 D1/D2 — grant validity windows (commit d6e793507) ──────── // // The sibling of the `active` switch above, and enforced at the same seam // for the same stated reason: a grant that is supposed to lapse on a date, diff --git a/packages/qa/dogfood/test/authz-conformance.test.ts b/packages/qa/dogfood/test/authz-conformance.test.ts index 527d18d8d7f..fc6df8c01d1 100644 --- a/packages/qa/dogfood/test/authz-conformance.test.ts +++ b/packages/qa/dogfood/test/authz-conformance.test.ts @@ -3,7 +3,7 @@ // ADR-0056 D10 — the authorization conformance matrix is a CHECKED artifact, // within the scope the mechanism can see: routes are ratcheted, primitives are // hand-maintained (see the matrix's own header for the narrowed claim and the -// measured numbers — #8711). Refactored onto the reusable ADR-0060 +// measured numbers — commit 2ce1eb41b). Refactored onto the reusable ADR-0060 // `checkLedger` helper: one call asserts every shared invariant (valid state, // enforced-has-site, experimental/removed-has-note, proof-file-exists, // high-risk-has-proof). A row that regresses one of THOSE invariants, or a diff --git a/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts b/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts index 80ce3ebc33e..f58f02b9d43 100644 --- a/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts +++ b/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts @@ -431,9 +431,9 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ // `this.routeManager.register(` reads 73 because the helper's forwarder is // one of them, and it is sliced out before counting. // - // [#13214] `enforceAuth` 61 -> 64. ⛔ RE-ANCHORED, not relaxed: the control + // [commit cc837dbfe] `enforceAuth` 61 -> 64. ⛔ RE-ANCHORED, not relaxed: the control // exists to prove this census is still reading the file it thinks it is, and - // a rising `enforceAuth` is precisely what the 2026-08-30 ruling on #13214 + // a rising `enforceAuth` is precisely what the 2026-08-30 ruling (commit cc837dbfe) // was supposed to cause — `registerUiEndpoints` was the ONE route in this // file that resolved no identity, and it is now guarded. The move is +3 over // the whole file (`occurrences` counts the bare term, comments included): @@ -445,9 +445,9 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ // ⚠️ The three sibling numbers were re-derived and did NOT move, which is // what says this is a guard change and not a surface change: `population` // 80, `reachable` 19, `private register*Endpoints(` 17 and - // `this.routeManager.register(` 80 are all unchanged — #13214 added no route + // `this.routeManager.register(` 80 are all unchanged — commit cc837dbfe added no route // and no registrar. `blindSpot` therefore stays 61 as well. - // ⚠️ That last figure is the reading AS OF #13214 and is left as written: + // ⚠️ That last figure is the reading AS OF commit cc837dbfe and is left as written: // the control is 73 today for the spelling reason recorded above, and the // population it feeds is still 80. Do not "correct" the paragraph — it is a // dated measurement, not a live claim. diff --git a/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts b/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts index 6cb5590d806..1d4ac547b63 100644 --- a/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts +++ b/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts @@ -1,12 +1,12 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. /** - * #10243 — the toggle card, now RULED: `POST /automation/:name/toggle` is + * The toggle card, now RULED (commit 266436a7f): `POST /automation/:name/toggle` is * gated on `manage_metadata`, and this file pins the closed door over HTTP. * * ## ⭐ This file was re-pointed, and the re-pointing is the record * - * It first landed (PR #10996) as a pure MEASUREMENT of the open half of the + * It first landed (commit 02b41232d) as a pure MEASUREMENT of the open half of the * card: whether one tenant's ungated toggle reached every organization. It * did — and it said, in this docblock, that a ruling *"flips these expectations * to a 403, and the flip is the point — an unrecorded verdict cannot be diff --git a/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts b/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts index 2f72b4dc269..4f1871ff773 100644 --- a/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts +++ b/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts @@ -193,7 +193,7 @@ describe('#8049: /auth/change-password clears the force-change flag and enforces SYS, ) )[0]; - // [#8676] `previous_password_hashes` is `internal: true`, so it is omitted + // [commit d6e80b28b] `previous_password_hashes` is `internal: true`, so it is omitted // from the row above — there is no `isSystem` carve-out on the strip. Read // it through the engine's privileged accessor, which is the same channel // the production reuse ring now uses. ⛔ Do NOT "fix" a `[]` here by diff --git a/packages/qa/dogfood/test/build-shaped-artifact.ts b/packages/qa/dogfood/test/build-shaped-artifact.ts index 6b2afacf6ed..20c8535fa3d 100644 --- a/packages/qa/dogfood/test/build-shaped-artifact.ts +++ b/packages/qa/dogfood/test/build-shaped-artifact.ts @@ -1,7 +1,7 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // // A stand-in for `objectstack build`, for fixtures that need "the stack as a -// deployment receives it" (#6293). +// deployment receives it" (commit c39a911ae). // // ## The trap this exists to close // @@ -76,7 +76,7 @@ import { normalizeStackInput, ObjectStackDefinitionSchema } from '@objectstack/s // #12879 closed that hole, and this import is the one in-repo case it had to // decide explicitly. Declaring the subpath in the CLI's `exports` was the other // option and is the wrong one twice over: it would make an internal compiler -// util part of the published contract — which is #6293's ruling inverted (reach +// util part of the published contract — which is commit c39a911ae's ruling inverted (reach // the goal WITHOUT growing `@objectstack/cli`'s public entry) — and it would // ratify an accidental reachability nobody ever offered, pricing every later // internal refactor of that package at a minor bump. @@ -199,7 +199,7 @@ export function buildShapedArtifact(stack: Record): BuildShaped // else — no error, no warning, no key. Measured on this exact stack then: // hand the lowering the `{ effect: 'writes' }` husk `JSON.stringify` leaves // behind and the artifact came out `functions: {}`, parsing green, which is - // the #6293 failure wearing a different hat; the parse below could not see it, + // the failure commit c39a911ae fixed, wearing a different hat; the parse below could not see it, // because by the time it ran the evidence had been deleted. // // The producer was fixed at the source — an entry `lowerCallables` does not diff --git a/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts b/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts index 1e097bd6248..b57eff0799d 100644 --- a/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts +++ b/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts @@ -21,7 +21,7 @@ // // ⚠️ WHY THIS FILE IS ORG-BOUND, AND WHY THAT IS THE POINT ⚠️ // -// [#8408 / #8839] This file used to boot ORG-LESS, and the moderation half of +// [#8408 / commit c25b2d52a] This file used to boot ORG-LESS, and the moderation half of // case (d) — "a user who can EDIT the record may moderate anyone's comment on // it" — was GREEN ONLY BECAUSE OF THAT. It was #8023's disarm, measured rather // than suspected: @@ -42,7 +42,7 @@ // fixture was not evidence that moderation works; it was evidence that // moderation works WHEN NOBODY IS AN ORG MEMBER. // -// Maintainer ruling (2026-08-15, #8839 — reading 1): moderation is a declared, +// Maintainer ruling (2026-08-15, commit c25b2d52a — reading 1): moderation is a declared, // implemented capability and the platform delete floor must not pre-empt it. // `member_default` now carries a per-object `sys_comment_moderation` delete // policy (`id != null`, domained to `org_member`) contributing the alternate @@ -74,7 +74,7 @@ import { assertArmed, principalArmed } from './armed.js'; const SYS = { isSystem: true } as const; /** - * [#8074 / #8839] The control this file measures, and the default that silences + * [#8074 / commit c25b2d52a] The control this file measures, and the default that silences * it. Named here so the failure message says what was disarmed rather than * which assertion happened to notice. */ @@ -119,7 +119,7 @@ describe('sys_comment permission matrix (#4630)', () => { // AuditPlugin owns sys_comment: the #2707 enable.feeds gate AND the // #4630 record-level gates both ride on it. extraPlugins: [new AuditPlugin()], - // [#8839] Org-bound on purpose — see the header. A `sys_member` row is + // [commit c25b2d52a] Org-bound on purpose — see the header. A `sys_member` row is // what makes a sign-up hold `org_member`, which is what brings BOTH the // wildcard delete floor and the `sys_comment_moderation` policy into // scope. Org-less, case (d)'s moderation limb measures neither. @@ -141,7 +141,7 @@ describe('sys_comment permission matrix (#4630)', () => { await ql.insert('sys_user_permission_set', { user_id: userId, permission_set_id: managerSet.id }, { context: { ...SYS } }); } - // [#8074 / #8839] The precondition the header records in prose, now read off + // [#8074 / commit c25b2d52a] The precondition the header records in prose, now read off // the live stack and enforced BEFORE anything is measured. Asserted here // rather than in an `it()` on purpose: a disarmed fixture must produce ZERO // green cells, and #8023's harm was exactly one green cell in a matrix that @@ -271,7 +271,7 @@ describe('sys_comment permission matrix (#4630)', () => { // memberB holds the delete bit and can READ the record, but is neither the // author nor able to EDIT the (admin-owned, public_read) parent → 403. // - // [#8839] The CODE is asserted exactly, and that is the negative control for + // [commit c25b2d52a] The CODE is asserted exactly, and that is the negative control for // this whole card. Before the fix this refusal came from the platform's // wildcard delete floor (`PERMISSION_DENIED`, "(row-level security)") — the // parent-blind gate that was ALSO refusing legitimate moderators one case @@ -280,7 +280,7 @@ describe('sys_comment permission matrix (#4630)', () => { // plugin-audit's parent-derived gate instead: `RECORD_NOT_ACCESSIBLE`. // // So this is not a cosmetic tightening. Accepting `PERMISSION_DENIED` here - // would let the exact regression #8839 fixed pass unnoticed: the floor + // would let the exact regression commit c25b2d52a fixed pass unnoticed: the floor // re-asserting itself over `sys_comment` looks identical to a correct // refusal at the status-code level, and it kills moderation while this case // stays green. If this ever reddens with `PERMISSION_DENIED`, moderation is diff --git a/packages/qa/dogfood/test/enterprise-organizations.ts b/packages/qa/dogfood/test/enterprise-organizations.ts index 5c528f7cb02..ef4587ac6e5 100644 --- a/packages/qa/dogfood/test/enterprise-organizations.ts +++ b/packages/qa/dogfood/test/enterprise-organizations.ts @@ -142,7 +142,7 @@ export async function probeOrganizations( pkg: string = ORGANIZATIONS_PKG, ): Promise { const root = hostRoot ?? process.cwd(); - // #10943: hand the helper THIS module's resolver. Its undeclared fallback is + // Commit 46d34ab7c: hand the helper THIS module's resolver. Its undeclared fallback is // documented as "the importing package's own resolution", and a bare // `import()` written inside `@objectstack/types` is that package's // resolution, not this one's — it can see only `@objectstack/spec`. It makes diff --git a/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts b/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts index 3e39ea9dc5e..724ad875b6a 100644 --- a/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// Fixture for the #16659 acting-organization pins: two `schedule` flows that +// Fixture for commit ecdfc9411's acting-organization pins: two `schedule` flows that // differ in EXACTLY ONE key — the `organization` declaration on the start node // — so the pins' red/green is attributable to that key and to nothing else. // @@ -12,7 +12,7 @@ /** * Object the tick touches, so a run has a data write of its own to land. * - * `due_date` is what the `time_relative` sweep selects on (#16659 F2). It is a + * `due_date` is what the `time_relative` sweep selects on (commit ecdfc9411, F2). It is a * `datetime` rather than a `date` deliberately: the window the trigger computes * is a pair of ISO-8601 instants, and comparing them against a column the * driver truncates to `YYYY-MM-DD` puts a per-driver truncation rule between @@ -115,7 +115,7 @@ export function organizationLessScheduleFlow(recipientId: string): unknown { } /** - * [#16659 F2] The `time_relative` twin: a sweep that declares its acting + * [commit ecdfc9411, F2] The `time_relative` twin: a sweep that declares its acting * organization, selects `sched_org_target` rows whose `due_date` falls in the * next week, and — once per matched record — notifies and writes. * diff --git a/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts b/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts index 032a59d05cd..4bbb11e3428 100644 --- a/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts +++ b/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// [#9934] The producer-side user-facing marking, end-to-end through the real +// [commit 79c46da90] The producer-side user-facing marking, end-to-end through the real // stack — the producer half of the objectui#5210 ruling (maintainer, // 2026-08-19, option 1: producer-side opt-in). // @@ -86,7 +86,7 @@ const ufmStack = defineStack({ { // A sandboxed L2 BODY hook — the metadata-app authoring surface the // marking exists for. Its marking must survive the QuickJS boundary - // (the #9934 side-channel) and ride the sandbox-unwrap envelope. + // (the side-channel commit 79c46da90 added) and ride the sandbox-unwrap envelope. name: 'ufm_ref_guard', object: 'ufm_task', events: ['beforeDelete'], diff --git a/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts b/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts index 4eeef032e2d..14c33040a3a 100644 --- a/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts +++ b/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts @@ -43,7 +43,7 @@ describe('dogfood: /meta/:type/:name/published and /meta/object/:name/state/:fie const artifactPath = join(tempDir, 'objectstack.json'); // The real `objectstack build` lowering, not `JSON.stringify(stack)` — // that drops callables silently and the artifact parses green carrying - // none of what it advertises (#6293). + // none of what it advertises (commit c39a911ae). writeBuildShapedArtifact(showcaseStack as unknown as Record, artifactPath); stack = await bootStack(showcaseStack, { diff --git a/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts b/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts index b6a7adf5f20..fe7651b5b05 100644 --- a/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts +++ b/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts @@ -202,7 +202,7 @@ describe('dogfood: the metadata door attributes a two-package artifact per packa beforeAll(async () => { tempDir = mkdtempSync(join(tmpdir(), 'os-14599-mp-')); const artifactPath = join(tempDir, 'objectstack.json'); - // The real build lowering, not `JSON.stringify(stack)` (#6293). + // The real build lowering, not `JSON.stringify(stack)` (commit c39a911ae). writeBuildShapedArtifact(multiPackageStack as unknown as Record, artifactPath); stack = await bootStack(multiPackageStack, { diff --git a/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts b/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts index aff0bbd837e..253d7e1d2ad 100644 --- a/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts +++ b/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts @@ -43,7 +43,7 @@ * * ## Two more published surfaces move with the verb, and are pinned here too * - * The contract review of PR #16687 measured what the first round did not name: + * The contract review recorded in commit 779710213 measured what the first round did not name: * * - the DERIVED `import` door. `API_METHOD_DERIVATION` (`@objectstack/spec`, * `api-derivation.ts`) derives `import` from `any: ['create', 'update']`, so diff --git a/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts b/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts index 1dd56a47d8a..85b50ad5833 100644 --- a/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts +++ b/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts @@ -288,7 +288,7 @@ describe('#12159 Part 1 — a composition WITH automation: flows and actions bot const rows = await ql.find(LEDGER, { where: { metadata_type: 'flow' }, context: SYSTEM_CTX }); const row = rows.find((r) => r.name === FLOW); // The durable half. A toggle that only moved the engine's in-process - // projection is the #10243 mechanism ADR-0126 §7.2 retires, and it + // projection is the mechanism commit 02b41232d measured, which ADR-0126 §7.2 retires, and it // would look identical on the wire. expect(row, `no durable '${FLOW}' row — the flow ledger is not attached: ${JSON.stringify(rows)}`).toBeDefined(); expect(row!.active === false || row!.active === 0).toBe(true); diff --git a/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts b/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts index 8c30c18683e..6912955a070 100644 --- a/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts +++ b/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// [#16659] A time-triggered flow declares its acting organization and the run +// [commit ecdfc9411] A time-triggered flow declares its acting organization and the run // executes as it — proven end to end through the real automation + messaging + // ObjectQL stack, on BOTH drivers. // @@ -143,7 +143,7 @@ for (const databaseDriver of ['sqlite-wasm', 'memory'] as const) { // ⚠️ sqlite-wasm ONLY, and the asymmetry is measured rather than // assumed: `driver-memory` declares NO row-level tenant isolation and // REFUSES any call the engine hands a tenant scope - // (`MemoryMultiTenantUnsupportedError`, #16589 / #6915). An org-bound + // (`MemoryMultiTenantUnsupportedError`, commit 555a89cbd / #6915). An org-bound // session makes the authorization resolver's own `sys_position` read // tenant-scoped, so on that driver every HTTP request from such a // session 503s before reaching any route. The HTTP control is therefore @@ -532,7 +532,7 @@ for (const databaseDriver of ['sqlite-wasm', 'memory'] as const) { * third id, and `orgA`'s absence is the witness. On `driver-memory` no * session can be org-bound — the driver declares no row-level tenant * isolation and refuses any tenant-scoped call - * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, #16589 / #6915), so the + * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, commit 555a89cbd / #6915), so the * authorization resolver's own `sys_position` read is refused and the * door answers 503 before any route runs. This suite therefore boots * memory with `orgContext: false`, which leaves the HTTP caller carrying diff --git a/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts b/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts index 6b288bc5f03..180bb78ba22 100644 --- a/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts +++ b/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// [#16659 F2] A `time_relative` sweep SELECTS inside its declared organization +// [commit ecdfc9411, F2] A `time_relative` sweep SELECTS inside its declared organization // — proven on the real ObjectQL + driver stack, with matching rows in TWO // organizations. // @@ -105,7 +105,7 @@ const SYS = { context: { isSystem: true } }; * - **sqlite-wasm** enforces tenant isolation, so it can be asked the real * differential question: with rows in A and B, which come back? * - **memory** implements none and REFUSES any call handed a tenant scope - * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, #16589). The question it answers is the + * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, commit 555a89cbd). The question it answers is the * one the card is really about: when a sweep required to stay inside one * organization cannot be served, does it SAY SO or go quiet? */ @@ -319,7 +319,7 @@ for (const databaseDriver of ['sqlite-wasm', 'memory'] as const) { * The store cannot honour the scope, so the sweep must be LOUD. * * PREDICTION, written before the run: `driver-memory` refuses the scoped - * `find` (#16589), the sweep's own error isolation catches it, and the + * `find` (commit 555a89cbd), the sweep's own error isolation catches it, and the * failure is logged at `error` naming the flow. ⛔ What must NOT happen is * the sweep quietly answering with every organization's rows — that is the * silent non-isolation the driver's refusal exists to remove, and this diff --git a/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts b/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts index ebbe1dcd211..9390046afb5 100644 --- a/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts @@ -23,7 +23,7 @@ // half — a guest / previewMode boot writes an `@anon` metadata seed, so does the // server refuse an anonymous WRITE? — and no artifact in this repo answered it // end-to-end. The mutating routes are now driven here as real HTTP (six when -// #11373 measured; five since #12176 D3 retired the compound save — see the +// #11373 measured; five since commit 7986d973f (D3) retired the compound save — see the // retired-door case beside the table). The reading is recorded in full at the // door table below; the short version is that the umbrella already refused all // of them, so #11373 is a measurement plus its pin, not a fix. @@ -128,7 +128,7 @@ interface MetaWriteDoor { * The five mutating `/meta` routes `registerMetadataEndpoints` composes. * * There were six when #11373 measured: `PUT /meta/:type/:section/:name` (the - * compound save) was retired by #12176 D3 — the item-name grammar (#12194) + * compound save) was retired by commit 7986d973f (D3) — the item-name grammar (commit 311433f6b) * refuses every slash-bearing name, so the arity addressed only names that can * no longer exist. A retired door cannot sit in this table: the registered-door * anti-vacuity leg below asserts `.not.toBe(404)`, which is exactly what a @@ -148,7 +148,7 @@ const META_WRITE_DOORS: readonly MetaWriteDoor[] = [ { seam: 'POST /meta/:type/:name/rollback', method: 'POST', path: `/meta/object/${META_PROBE_OBJECT}/rollback`, body: { toVersion: 1 } }, ]; -/** The retired compound-save spelling (#12176 D3) — routed nowhere, for anyone. */ +/** The retired compound-save spelling (commit 7986d973f, D3) — routed nowhere, for anyone. */ const RETIRED_COMPOUND_PATH = `/meta/object/views/${META_PROBE_VIEW}`; // ── #5632 — the TWO declared anonymous-401 envelopes, as executable rules ─── @@ -289,7 +289,7 @@ describe('showcase: anonymous posture is uniform across surfaces (#2567)', () => // method, same body, one process, one second apart: a session changes // the answer, so the refusal is the auth floor and not the door being // broken. (Deliberately not `.toBe(403)`. A member's exact status is the - // capability gate's business — #8919's proof owns that, and pinning it + // capability gate's business — commit b5378550e's proof owns that, and pinning it // here would make this file red for another proof's reasons. Measured // today it is 403 FORBIDDEN `manage_metadata` on all six.) // diff --git a/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts b/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts index 4d21af3f6b7..e1f4fe59a09 100644 --- a/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts @@ -110,9 +110,9 @@ beforeAll(async () => { // The artifact is written the way `objectstack build` writes one — the same // `normalizeStackInput` → `lowerCallables` → `ObjectStackDefinitionSchema` // pipeline `packages/cli/src/commands/compile.ts` runs, reusing those exact - // functions rather than re-deriving them (#6293). + // functions rather than re-deriving them (commit c39a911ae). // - // Until #6293 this line was `JSON.stringify(stack)` minus `functions`, and + // Until commit c39a911ae this line was `JSON.stringify(stack)` minus `functions`, and // the omission was deliberate and declared (#4976) because the substitute // could not carry them: `JSON.stringify` drops a bare callable KEY AND ALL // and reduces a declared one (`{ handler: fn, effect }`) to the headless husk @@ -155,7 +155,7 @@ afterAll(async () => { }); // ============================================================================ -// 0. The artifact this boot ingests is the shape the build writes (#6293) +// 0. The artifact this boot ingests is the shape the build writes (commit c39a911ae) // ============================================================================ describe('[#6293] the stand-in artifact carries what a built one carries', () => { diff --git a/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts b/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts index 3fec1eda046..27c45d8797a 100644 --- a/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts @@ -61,7 +61,7 @@ describe('dogfood: an object extension reaches every /meta read (#7556)', () => const artifactPath = join(tempDir, 'objectstack.json'); // The real `objectstack build` lowering, not `JSON.stringify(stack)` — that // drops callables silently and the artifact parses green carrying none of - // what it advertises (#6293). + // what it advertises (commit c39a911ae). writeBuildShapedArtifact(showcaseStack as unknown as Record, artifactPath); stack = await bootStack(showcaseStack, { diff --git a/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts b/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts index c364a922646..2d159ac9963 100644 --- a/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts @@ -69,10 +69,10 @@ // Whether a package extension's label should outrank a tenant's Studio rename // is a fold-precedence decision the 2026-08-13 ruling did not make, and it is // NOT arm B (nothing here proposes dropping scalars from the fold). It was filed -// as a sub-issue of #8284 — #8460 — and ruled on separately. +// as a sub-issue of #8284 and ruled on separately (ADR-0029 D9.2a). // // ══════════════════════════════════════════════════════════════════════════ -// [#8460] THE FOLD LAYER, RULED AND FIXED — THE SECOND PIN IS NOW GREEN +// [ADR-0029 D9.2a] THE FOLD LAYER, RULED AND FIXED — THE SECOND PIN IS NOW GREEN // ══════════════════════════════════════════════════════════════════════════ // // Maintainer ruling, 2026-08-13 (option A, "tenant wins"): an extender's scalar @@ -244,11 +244,11 @@ describe('dogfood: the object-extension fold and the i18n catalog disagree on sc // is not the file's only word about it. This case asserts AGREEMENT and // the absence of the catalog string — never which value they agree on — // so it held under #8284 (all three served the extension's label, the - // tenant's rename lost inside the fold) and it holds under #8460 (all + // tenant's rename lost inside the fold) and it holds under ADR-0029 D9.2a (all // three serve the tenant's 'Customer', because the extender now yields // to a diverged base). That is the point of stating it this way: the // convergence #8284 bought is pinned independently of the fold - // precedence #8460 then settled, so a regression in either is visible + // precedence ADR-0029 D9.2a then settled, so a regression in either is visible // here without this case having to be rewritten when the other moves. // // Performs its own PUT rather than leaning on the case above: that case diff --git a/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts b/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts index 09074d46b41..342b8ccd99c 100644 --- a/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts @@ -8,22 +8,22 @@ // 1. A data-door create/edit lands in the METADATA store (write-through) and // the record is re-derived by the AWAITED projector — consistent on the // very next read, no race. -// 2. [#6483 inverted this pin] A data-door edit of a CODE-DECLARED set is +// 2. [commit ee58392e1 inverted this pin] A data-door edit of a CODE-DECLARED set is // REFUSED — `permission` rolled back to `allowOrgOverride: false` // (ADR-0005 security row: "Authorization correctness; overlays would // create silent privilege drift"), so overriding an artifact-backed set // answers 403 `not_overridable` instead of minting an overlay. The -// pre-#6483 behaviour (ADR-0094's 2026-07-14 "customize via env +// behaviour before commit ee58392e1 (ADR-0094's 2026-07-14 "customize via env // overlay" direction) is closed until an ADR-0005 revision readmits the // type; ADR-0086 two-doors applies meanwhile (edit the package, // re-publish). // 3. Deleting a runtime-only set retires its record; deleting an // artifact-backed set never removes it — the definition ships with the -// app and cannot be removed from the environment. Since #6483 there is +// app and cannot be removed from the environment. Since commit ee58392e1 there is // no overlay left to lift, so that "reset" is a no-op success, not the // revert-to-the-declared-body step ADR-0094's 2026-07-14 direction // described (retired by D5-R). -// 4. [#6483 inverted this pin too] An environment-door metadata save that +// 4. [commit ee58392e1 inverted this pin too] An environment-door metadata save that // targets a package-owned, artifact-backed set is refused the same way — // record, provenance and effective body all stay exactly as shipped. // (Package-bound rows MATERIALIZED through the metadata door carry @@ -100,11 +100,11 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { expect(await overlayBody(NAME), 'metadata overlay gone too').toBeFalsy(); }); - // ── 2. Data-door edit of a DECLARED set is REFUSED (#6483) ──────────────── + // ── 2. Data-door edit of a DECLARED set is REFUSED (commit ee58392e1) ───── it('editing a declared set through the data door is refused — no overlay is minted', async () => { // member_default is a platform-declared set (an artifact baseline // exists), so the write-through's `saveMetaItem` hits the ADR-0005 type - // gate: `permission` is no longer `allowOrgOverride` (#6483, the + // gate: `permission` is no longer `allowOrgOverride` (commit ee58392e1, the // security row's "silent privilege drift"). The refusal must be LOUD — // an error status, not a 2xx that quietly skipped the metadata write — // and must leave no overlay behind (#6190's phantom-write shape is the @@ -124,13 +124,13 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { // ── 3. Delete of an artifact-backed set RESETS (does not remove) ────────── it('deleting a declared set through the data door resets it to the declared body, keeping the record', async () => { - // (#6483: with the edit above refused, there is no overlay to lift — the + // (commit ee58392e1: with the edit above refused, there is no overlay to lift — the // delete is a no-op reset. The invariant it pins is unchanged: a // declared definition cannot be removed from the environment.) const before = await findSet('member_default'); const res = await stack.apiAs(adminToken, 'DELETE', `/data/sys_permission_set/${before.id}`); expect(res.status).toBeLessThan(300); - // [#19306] The status cannot tell this reset apart from a real deletion — + // [commit f9e16d856] The status cannot tell this reset apart from a real deletion — // the whole envelope used to be byte-identical to one, so every assertion // below stayed green while the door told the caller the set was gone. // `success: false` is the one field that says the record is still here, @@ -144,7 +144,7 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { expect(after.description ?? null).not.toBe('customized via Setup (ADR-0094)'); }); - // ── 4. Env overlay of a PACKAGE set is REFUSED (#6483) ──────────────────── + // ── 4. Env overlay of a PACKAGE set is REFUSED (commit ee58392e1) ───────── it('an environment-door metadata save on a package-owned set is refused and changes nothing', async () => { const contributor = await findSet('showcase_contributor'); expect(contributor?.managed_by, 'showcase_contributor is package-owned').toBe('package'); @@ -152,7 +152,7 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { const baseline = layeredBefore?.code ?? null; expect(baseline, 'the packaged declaration is the code layer').toBeTruthy(); - // #6483 — `permission` rolled back to `allowOrgOverride: false` + // Commit ee58392e1 — `permission` rolled back to `allowOrgOverride: false` // (ADR-0005 security row). The overlay ADR-0094's 2026-07-14 direction // used here is exactly the per-org shadowing of a code-shipped // authorization contract the ADR forbids, so the save refuses LOUDLY at diff --git a/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts b/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts index 2fa6a37340d..a7178dcdd40 100644 --- a/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts +++ b/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts @@ -13,7 +13,7 @@ // edit into an env-scope ADR-0005 overlay" direction was RETIRED on // 2026-08-09 — see ADR-0094 D5-R): a data-plane edit of a // package-managed, ARTIFACT-BACKED row is REFUSED with 403 -// `not_overridable` and no overlay is minted — #6483 rolled +// `not_overridable` and no overlay is minted — commit ee58392e1 rolled // `permission` back to `allowOrgOverride: false`, and ADR-0086 names // the supported channel instead: edit the package and re-publish. // A "delete" through this door still degrades to a RESET — a packaged @@ -78,9 +78,9 @@ describe('two-doors permission separation (ADR-0086 P2)', () => { }); }); - // ── 块2 — admin door: artifact-backed rows now REFUSE the overlay (#6483) ─ + // ── 块2 — admin door: artifact-backed rows now REFUSE the overlay (commit ee58392e1) ─ it('块2: an admin edit of a package-managed set is refused — no env overlay is minted (#6483)', async () => { - // Pre-#6483 this edit became an env-scope overlay (ADR-0094's 2026-07-14 + // Before commit ee58392e1 this edit became an env-scope overlay (ADR-0094's 2026-07-14 // direction). `permission` has since rolled back to // `allowOrgOverride: false` (ADR-0005 security row: "Authorization // correctness; overlays would create silent privilege drift"), so the @@ -105,13 +105,13 @@ describe('two-doors permission separation (ADR-0086 P2)', () => { }); it('块2: "deleting" the package set through the env door still RESETS to the shipped declaration', async () => { - // (#6483: with the edit above refused there is no overlay to lift, but + // (commit ee58392e1: with the edit above refused there is no overlay to lift, but // the invariant is unchanged and still pinned: the env door can never // remove a packaged definition — delete degrades to reset.) const before = await findSet('showcase_contributor'); const res = await stack.apiAs(adminToken, 'DELETE', `/data/sys_permission_set/${before.id}`); expect(res.status).toBeLessThan(300); - // [#19306] The status cannot tell this reset apart from a real deletion — + // [commit f9e16d856] The status cannot tell this reset apart from a real deletion — // the whole envelope used to be byte-identical to one, so every assertion // below stayed green while the door told the caller the set was gone. // `success: false` is the one field that says the record is still here, @@ -127,14 +127,14 @@ describe('two-doors permission separation (ADR-0086 P2)', () => { }); it('块2: the admin door CAN still edit an env-authored set (isolates the gate to artifact-backed rows)', async () => { - // The specimen was `member_default` until #6483: its record is env-owned + // The specimen was `member_default` until commit ee58392e1: its record is env-owned // (`managed_by` ≠ 'package'), but its METADATA identity is a platform // artifact (`defaultPermissionSets`), so with `permission` rolled back // to `allowOrgOverride: false` the write-through's `saveMetaItem` now // refuses to overlay it — the record's provenance column was never what // the gate reads. A truly env-AUTHORED set (created through the data // door, definition living only in `sys_metadata`) rides the - // `allowRuntimeCreate` tier, which #6483 deliberately left open — that + // `allowRuntimeCreate` tier, which commit ee58392e1 deliberately left open — that // is the boundary this case isolates. const NAME = 'twodoors_env_authored'; const created = await stack.apiAs(adminToken, 'POST', '/data/sys_permission_set', { diff --git a/packages/qa/dogfood/vitest.config.ts b/packages/qa/dogfood/vitest.config.ts index 449ce1e1630..82e8e513515 100644 --- a/packages/qa/dogfood/vitest.config.ts +++ b/packages/qa/dogfood/vitest.config.ts @@ -64,7 +64,7 @@ const SHARED_SHOWCASE = [ 'test/two-doors-permission.dogfood.test.ts', ]; -// #17853 / #17978 — say so when a path named on the command line will run no +// Commit 08f5f0e5a / #17978 — say so when a path named on the command line will run no // tests. Invoked HERE, at config load, and ⛔ deliberately NOT as a // `test.reporters` entry: naming that option replaces vitest's own reporter // defaulting instead of extending it, which measurably changes a healthy run's @@ -204,7 +204,7 @@ export default defineConfig({ find: /^@objectstack\/trigger-record-change$/, replacement: path.resolve(__dirname, '../../triggers/trigger-record-change/src/index.ts'), }, - // [#16659] `schedule-acting-organization.dogfood.test.ts` and + // [commit ecdfc9411] `schedule-acting-organization.dogfood.test.ts` and // `schedule-sweep-organization-scope.dogfood.test.ts` drive // `ScheduleTrigger` / `TimeRelativeTrigger` themselves: the pins' // whole subject is which