From 57ffb83b003d1f35560544a2e140af944782a6cd Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 15:59:25 +0000 Subject: [PATCH] docs(dogfood): re-anchor the dead tracker citations in packages/qa/dogfood's files outside src to the commits and ADR that decided them Comment prose only, in test/** and vitest.config.ts: every comment site whose tracker number answers 404 now cites the commit in this repository's history that decided what the line describes, or the ADR clause that records the ruling (ADR-0029 D9.2a). String literals, describe/it titles and messages are untouched. Every file keeps its line count. Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB Co-authored-by: Claude --- ...auth-tokens-not-serialized.dogfood.test.ts | 16 +++++++-------- ...in-platform-admin-standing.dogfood.test.ts | 4 ++-- ...min-route-nonadmin-refusal.dogfood.test.ts | 14 ++++++------- ...ments-unscoped-delete-gate.dogfood.test.ts | 14 ++++++------- .../dogfood/test/authz-conformance.matrix.ts | 8 ++++---- .../qa/dogfood/test/authz-conformance.test.ts | 2 +- .../test/authz-probe-blind-spot.census.ts | 8 ++++---- ...mation-toggle-tenant-scope.dogfood.test.ts | 4 ++-- ...earer-lane-password-change.dogfood.test.ts | 2 +- .../qa/dogfood/test/build-shaped-artifact.ts | 6 +++--- ...comments-permission-matrix.dogfood.test.ts | 14 ++++++------- .../dogfood/test/enterprise-organizations.ts | 2 +- .../fixtures/schedule-organization-fixture.ts | 6 +++--- ...efusal-user-facing-marking.dogfood.test.ts | 4 ++-- ...published-and-state-routes.dogfood.test.ts | 2 +- .../multi-package-artifact.dogfood.test.ts | 2 +- .../organization-update-door.dogfood.test.ts | 2 +- ...ed-activation-ledger-reach.dogfood.test.ts | 2 +- ...hedule-acting-organization.dogfood.test.ts | 6 +++--- ...e-sweep-organization-scope.dogfood.test.ts | 6 +++--- ...se-anonymous-deny-surfaces.dogfood.test.ts | 8 ++++---- ...case-declarative-endpoints.dogfood.test.ts | 6 +++--- ...object-extension-meta-read.dogfood.test.ts | 2 +- ...xtension-scalar-divergence.dogfood.test.ts | 8 ++++---- ...case-permission-projection.dogfood.test.ts | 20 +++++++++---------- .../test/two-doors-permission.dogfood.test.ts | 14 ++++++------- packages/qa/dogfood/vitest.config.ts | 4 ++-- 27 files changed, 93 insertions(+), 93 deletions(-) diff --git a/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts b/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts index 183527117ed..724126ff5b9 100644 --- a/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts +++ b/packages/qa/dogfood/test/account-oauth-tokens-not-serialized.dogfood.test.ts @@ -1,10 +1,10 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. /** - * #7987 (+ #8676) — `sys_account`'s credential columns must not come back on + * #7987 (+ commit d6e80b28b) — `sys_account`'s credential columns must not come back on * the generic data path. * - * [#8676] The file was #7987's three OAuth columns; it now covers the object's + * [commit d6e80b28b] The file was #7987's three OAuth columns; it now covers the object's * other two credential columns as well — `password` and * `previous_password_hashes`, the one-way hashes of ADR-0100's third channel. * They belong here rather than in a fixture of their own because they are the @@ -88,9 +88,9 @@ const PLANTED = { const TOKEN_COLUMNS = ['access_token', 'refresh_token', 'id_token'] as const; /** - * [#8676] The two one-way password hashes on the same object — ADR-0100's third + * [commit d6e80b28b] The two one-way password hashes on the same object — ADR-0100's third * channel. They serialized on this very read path alongside the OAuth columns - * (the #8676 key list was captured on this fixture's own ablation run), through + * (commit d6e80b28b's key list was captured on this fixture's own ablation run), through * the same two barriers that miss them: `collectMaskedReadFields` keys on the * field TYPE and exempts `managedBy: 'better-auth'`, while these are * `text` / `textarea`. Asserted through the SAME persona matrix below, because @@ -277,7 +277,7 @@ describe('#7987: sys_account OAuth tokens never serialize on the generic data pa assertNoCredentialColumns(row); } - // [#8676] The same spelling attack aimed at the password hashes, from both + // [commit d6e80b28b] The same spelling attack aimed at the password hashes, from both // personas. The member's own row is the one that matters most here: the // `sys_account_self` policy grants the read, so this is a LEGAL request for // their own record that must still come back without the hash. @@ -334,11 +334,11 @@ describe('#7987: sys_account OAuth tokens never serialize on the generic data pa // exactly one predicate — `internal === true` — so a column without the // flag is refused (ADR-0112 code + status). // - // ⚠️ Its instance changed with #8676, and only its instance. This test used + // ⚠️ Its instance changed with commit d6e80b28b, and only its instance. This test used // to spell the predicate with `password`, because #7987 deliberately left // that column unflagged and the test marked THAT card's scope boundary // ("a column that is **not flagged** … are deliberately NOT `internal`"). - // #8676 flags it, so the premise of `password`-as-example disappears while + // Commit d6e80b28b flags it, so the premise of `password`-as-example disappears while // the proposition itself is untouched: `scope` is an ordinary unflagged // `sys_account` column and stands in as the example. What is NOT weakened // is the guard — no ADR-0100 carve-out was added, and the positive arm @@ -361,7 +361,7 @@ describe('#7987: sys_account OAuth tokens never serialize on the generic data pa it('[#8676] `password` and `previous_password_hashes` are stripped, and reachable only through the accessor', async () => { // The card's own assertions, both directions. These are one-way password // hashes — ADR-0100's third channel — and they serialized on the generic - // data API before #8676: to an admin for every user's row, and to a member + // data API before commit d6e80b28b: to an admin for every user's row, and to a member // for their own. const rows: any[] = await ql.find('sys_account', { where: { id: memberAccountId }, diff --git a/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts b/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts index 8fc843b3a4a..0c4384ea823 100644 --- a/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts +++ b/packages/qa/dogfood/test/admin-platform-admin-standing.dogfood.test.ts @@ -30,7 +30,7 @@ // hand-roll better-auth's signed-cookie contract with // `/admin/stop-impersonating` and silently detach the #8243 bearer-rotation // hook. It is a better-auth PLUGIN endpoint with only the authorization -// predicate replaced, and since #11686 that predicate is the consolidated +// predicate replaced, and since commit 7131f12bf that predicate is the consolidated // authority `hasPlatformAdminStanding`. `has-permission` (#11900, ruled // 2026-08-25) is a third shape: a permission QUERY, raw-mounted WITHOUT // the refusing judge — the platform admin's query is answered from the @@ -59,7 +59,7 @@ // then folds back into `positions[]`. A working "Set Platform Role" // button would be a supported, gated, one-user-at-a-time channel for // resurrecting the dual identity representation the 2026-08-18 Option-3 -// veto killed. So the maintainer retired the CONSOLE ACTION (PR #11530) +// veto killed. So the maintainer retired the CONSOLE ACTION (commit 033a34c7c) // and left the vendor ROUTE mounted and vendor-gated, byte for byte. // // ⛔ THEREFORE: a `403` from any of those eight is the system working. Do not diff --git a/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts b/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts index 45cc713b5fa..3307216482e 100644 --- a/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts +++ b/packages/qa/dogfood/test/admin-route-nonadmin-refusal.dogfood.test.ts @@ -76,7 +76,7 @@ // gate verdict and not a payload the server rejects for everyone. // // `shaded-vendor-gate` (1 route: `remove-user`) — the two halves belong to -// DIFFERENT layers, which is why it is neither of its neighbours. #11477 +// DIFFERENT layers, which is why it is neither of its neighbours. Commit 6dd3e6968 // gave the route the raw-mount shading `ban-user` already had, so an // ObjectStack gate answers the refusal (member 403 PERMISSION_DENIED, anon // 401 UNAUTHENTICATED) — but the mount DELEGATES rather than @@ -88,7 +88,7 @@ // The both-sides contrast is therefore not a 2xx but a DIFFERENCE: the // member and the admin hear two different refusals, which is what proves // the member's 403 is an authorization verdict and not a blanket refusal. -// The bucket also carries the #11477 negative — a member must never again +// The bucket also carries commit 6dd3e6968's negative — a member must never again // see the break-glass guard's `409 LAST_LOCAL_CREDENTIAL`, which before the // shading was answered ahead of every authorization layer and VARIED WITH // THE TARGET, disclosing per-record state to a caller entitled to none. @@ -336,7 +336,7 @@ function expectationsFor(targetUserId: string): Record body: { userId: targetUserId }, }, - // ── #11477 — shaded for ORDERING, still admitted by the vendor ───────── + // ── Commit 6dd3e6968 — shaded for ORDERING, still admitted by the vendor ─ // // The only member of its bucket, and the bucket exists because this route // genuinely has a third shape rather than because the other two did not @@ -345,7 +345,7 @@ function expectationsFor(targetUserId: string): Record // owned by different layers: // // refusal → ObjectStack's gate (403 PERMISSION_DENIED), because the - // mount answers first. That is #11477's whole point: the + // mount answers first. That is commit 6dd3e6968's whole point: the // break-glass `hooks.before` guard used to answer an // authenticated non-admin BEFORE any authorization ran, and // its 409 differed per target — a per-record disclosure. @@ -634,7 +634,7 @@ describe('#9482 C9: every derived /admin/ route refuses a non-admin', () => { }, 600_000); it('the shaded vendor route refuses a non-admin from the ObjectStack gate, before the break-glass guard', async () => { - // #11477. The both-sides contrast here is NOT a 2xx — it is that the two + // Commit 6dd3e6968. The both-sides contrast here is NOT a 2xx — it is that the two // callers hear DIFFERENT refusals. A member is turned away by ObjectStack's // gate (`PERMISSION_DENIED`) and a platform admin gets past it only to be // turned away by the vendor's (`YOU_ARE_NOT_ALLOWED_*`, #9969). Two @@ -653,7 +653,7 @@ describe('#9482 C9: every derived /admin/ route refuses a non-admin', () => { expect(member.status, `${route} member: ${member.body}`).toBe(403); expect(member.code, `${route} member code: ${member.body}`).toBe('PERMISSION_DENIED'); - // ⛔ The load-bearing negative. Before #11477 the break-glass + // ⛔ The load-bearing negative. Before commit 6dd3e6968 the break-glass // `hooks.before` guard answered an authenticated non-admin ahead of every // authorization layer, and its answer varied with the TARGET — a // per-record disclosure to a caller entitled to nothing. A member must @@ -720,7 +720,7 @@ describe('#9482 C9: every derived /admin/ route refuses a non-admin', () => { // transaction, so this route answers the authorization question like // every other member of the bucket and needs no exception. // - // ⚠️ #11477 moved `remove-user` OUT of this bucket entirely — its raw + // ⚠️ Commit 6dd3e6968 moved `remove-user` OUT of this bucket entirely — its raw // mount now answers a member from ObjectStack's gate // (`403 PERMISSION_DENIED`) before better-auth is reached at all, so the // vendor-vocabulary rule below no longer describes it. It lives in diff --git a/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts b/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts index 322547bc1f2..5807f02b701 100644 --- a/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts +++ b/packages/qa/dogfood/test/attachments-unscoped-delete-gate.dogfood.test.ts @@ -9,7 +9,7 @@ // "refused outright (#4757)", on the reasoning that "nothing was ever queried" // must not read as "nothing to authorize". `attachment-access-hooks.ts` carries // exactly that refusal, and `attachment-access-hooks.test.ts` pins it against a -// wired engine (#9797). This file pins it END TO END, on the real stack, where +// wired engine (commit 1258dcaee). This file pins it END TO END, on the real stack, where // RBAC and plugin-sharing are in the path and the session is a real one. // // ## History — this file's original verdict has been OVERTAKEN, twice @@ -20,7 +20,7 @@ // the `where === undefined` check. That was a PRODUCT gap (#9719), and this // file deliberately declined to pin the behaviour of the day. // -// It has since been fixed. #9719/PR #9797 added an opt-in whole-operation +// It has since been fixed. #9719/commit 1258dcaee added an opt-in whole-operation // dispatch to the engine, which #9974 renamed `dispatchUnscopedMultiWrite` when // it was ruled onto `beforeUpdate` as well. `attachment-access-hooks.ts` // declares it on both sys_attachment write registrations, so the #4757 refusal @@ -35,7 +35,7 @@ // properties that look identical on a fixture whose rows split entitled/not — // which is exactly the fixture the first block below uses. Measured on this // suite: with `dispatchUnscopedMultiWrite` removed from BOTH registrations and -// service-storage rebuilt (the pre-#9797 world), the first block stays 5/5 +// service-storage rebuilt (the world before commit 1258dcaee), the first block stays 5/5 // GREEN. It cannot see the refusal it is named for. // // So the second block seeds the ONE fixture that separates them: a caller who @@ -163,7 +163,7 @@ describe('sys_attachment delete gate under an unscoped multi-delete (#9483)', () it('an unscoped multi-delete is refused OUTRIGHT — on its shape — and deletes NOTHING', async () => { // `{ multi: true }` with neither id nor where composes an AST over the whole - // table. Since #9797 the refusal that answers is #4757's whole-operation + // table. Since commit 1258dcaee the refusal that answers is #4757's whole-operation // one, dispatched BEFORE any row is resolved — not the per-row gate, which // on this fixture would also have refused (the member is the uploader of // one row and neither uploader nor parent-editor of the other). @@ -193,7 +193,7 @@ describe('sys_attachment delete gate under an unscoped multi-delete (#9483)', () it('an empty `where: {}` reaches the same verdict by a DIFFERENT rule — the per-row gate', async () => { // ⚠️ Same outcome, deliberately different mechanism, and the difference is - // load-bearing. #9797 scoped the whole-operation dispatch to a delete with + // load-bearing. Commit 1258dcaee scoped the whole-operation dispatch to a delete with // NO `where` at all; a match-all `where: {}` is a real query, so it is NOT // refused on shape — it is refused here only because this caller cannot // have the foreign row. Asserting the per-row message is what keeps that @@ -259,7 +259,7 @@ describe('sys_attachment delete gate under an unscoped multi-delete (#9483)', () // whole-operation rule or from the per-row gate, because that fixture holds one // row the caller may not touch. Here the caller uploaded BOTH rows, so the // per-row gate has nothing to refuse — anything that still refuses is refusing -// the SHAPE. Pre-#9797 this exact call resolved and emptied the table. +// the SHAPE. Before commit 1258dcaee this exact call resolved and emptied the table. // ───────────────────────────────────────────────────────────────────────────── describe('sys_attachment unscoped multi-delete is refused on its SHAPE, not on entitlement (#9483)', () => { @@ -352,7 +352,7 @@ describe('sys_attachment unscoped multi-delete is refused on its SHAPE, not on e }); it('refuses `{ multi: true }` with no id and no where — even though the caller may delete every matched row', async () => { - // #9719's measured wipe, end to end: before PR #9797 this call RESOLVED and + // #9719's measured wipe, end to end: before commit 1258dcaee this call RESOLVED and // took both rows (2 -> 0). The per-row gate licenses each row individually, // so nothing but the whole-operation #4757 rule can refuse here — which is // what makes this the case that detects its removal. diff --git a/packages/qa/dogfood/test/authz-conformance.matrix.ts b/packages/qa/dogfood/test/authz-conformance.matrix.ts index 6d7e54d01b0..0ac6f1b3428 100644 --- a/packages/qa/dogfood/test/authz-conformance.matrix.ts +++ b/packages/qa/dogfood/test/authz-conformance.matrix.ts @@ -93,7 +93,7 @@ // silencing that particular red costs an enforcement site rather than a // `covers` append on a row that records an absence. // -// [#8711] That completeness is over ROUTES, not over primitives: a primitive +// [commit 2ce1eb41b] That completeness is over ROUTES, not over primitives: a primitive // enforced by a predicate inside an existing resolver adds no entry point, so // it can be neither UNCLASSIFIED nor STALE. Measured against the rows below: // 44 of 51 carry no `covers` key at all (7 rows, 15 keys, every one an @@ -390,12 +390,12 @@ export const AUTHZ_CONFORMANCE: AuthzPrimitive[] = [ // mass-revoked) and the 0/1 storage shape the primary driver returns is // judged as well as a literal `false`. // - // [#8711] Both rows carry NO `covers`, and that is a statement about the + // [commit 60ade586e] Both rows carry NO `covers`, and that is a statement about the // RATCHET, not an omission: `discover()` enumerates HTTP entry points from a // curated per-file probe table, and a predicate inside an existing resolver // adds no entry point — so neither flag could ever have surfaced as // UNCLASSIFIED during the whole period it was inert. These two rows restore - // the ledger's stated invariant. [Resolved — maintainer ruling on #8711, + // the ledger's stated invariant. [Resolved — maintainer ruling (commit 2ce1eb41b), // 2026-08-15] The invariant's advertised SCOPE is narrowed to what the // ratchet can check, not the ratchet widened to reach in-resolver // predicates like this one — widening was measured unachievable in general @@ -408,7 +408,7 @@ export const AUTHZ_CONFORMANCE: AuthzPrimitive[] = [ enforcement: 'core/security/resolve-authz-context.ts step 6a — isRowActive gates BOTH halves, and only both hold it: (i) only ACTIVE position ids collect their `sys_position_permission_set` linkage, so a deactivated position carries no bound set; (ii) the deactivated NAME is dropped from `grants.positions`, because resolvePermissionSetsForContext requests positions as permission-set NAMES and a name left standing resolves the same grant one layer down', note: 'Only a name whose `sys_position` row is EXPLICITLY deactivated is dropped — a name with no row at all (`org_owner`, a membership-derived role, the built-in `everyone` audience anchor) has no flag to read and is untouched. Deliberately NOT a blanket revocation of the sets themselves: a set held via BOTH a deactivated position AND a direct user grant still resolves, since the direct grant is a different grant (resolve-authz-context.test.ts pins exactly that case). Symmetrically, the WRITE gates and blast-radius reads in plugin-security (assertAudienceAnchorBindingGate, setsBoundToPosition, the delegated-admin surfaces) stay UNFILTERED on purpose — dropping a deactivated row there would make a refused binding permitted, narrow a delegate\'s boundary, and make a deactivated position unmanageable. Unit-proven in core/security/resolve-authz-context.test.ts (a deactivated position stops granting its sets; an active one still grants; an absent column grants; the 0/1 shape deactivates; deactivating ONE position leaves the others granting) + core/security/row-active.test.ts. Not HIGH_RISK for the same reason as `permission-set-active`.' }, - // ── ADR-0091 D1/D2 — grant validity windows (#8811) ─────────────────── + // ── ADR-0091 D1/D2 — grant validity windows (commit d6e793507) ──────── // // The sibling of the `active` switch above, and enforced at the same seam // for the same stated reason: a grant that is supposed to lapse on a date, diff --git a/packages/qa/dogfood/test/authz-conformance.test.ts b/packages/qa/dogfood/test/authz-conformance.test.ts index 527d18d8d7f..fc6df8c01d1 100644 --- a/packages/qa/dogfood/test/authz-conformance.test.ts +++ b/packages/qa/dogfood/test/authz-conformance.test.ts @@ -3,7 +3,7 @@ // ADR-0056 D10 — the authorization conformance matrix is a CHECKED artifact, // within the scope the mechanism can see: routes are ratcheted, primitives are // hand-maintained (see the matrix's own header for the narrowed claim and the -// measured numbers — #8711). Refactored onto the reusable ADR-0060 +// measured numbers — commit 2ce1eb41b). Refactored onto the reusable ADR-0060 // `checkLedger` helper: one call asserts every shared invariant (valid state, // enforced-has-site, experimental/removed-has-note, proof-file-exists, // high-risk-has-proof). A row that regresses one of THOSE invariants, or a diff --git a/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts b/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts index 80ce3ebc33e..f58f02b9d43 100644 --- a/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts +++ b/packages/qa/dogfood/test/authz-probe-blind-spot.census.ts @@ -431,9 +431,9 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ // `this.routeManager.register(` reads 73 because the helper's forwarder is // one of them, and it is sliced out before counting. // - // [#13214] `enforceAuth` 61 -> 64. ⛔ RE-ANCHORED, not relaxed: the control + // [commit cc837dbfe] `enforceAuth` 61 -> 64. ⛔ RE-ANCHORED, not relaxed: the control // exists to prove this census is still reading the file it thinks it is, and - // a rising `enforceAuth` is precisely what the 2026-08-30 ruling on #13214 + // a rising `enforceAuth` is precisely what the 2026-08-30 ruling (commit cc837dbfe) // was supposed to cause — `registerUiEndpoints` was the ONE route in this // file that resolved no identity, and it is now guarded. The move is +3 over // the whole file (`occurrences` counts the bare term, comments included): @@ -445,9 +445,9 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ // ⚠️ The three sibling numbers were re-derived and did NOT move, which is // what says this is a guard change and not a surface change: `population` // 80, `reachable` 19, `private register*Endpoints(` 17 and - // `this.routeManager.register(` 80 are all unchanged — #13214 added no route + // `this.routeManager.register(` 80 are all unchanged — commit cc837dbfe added no route // and no registrar. `blindSpot` therefore stays 61 as well. - // ⚠️ That last figure is the reading AS OF #13214 and is left as written: + // ⚠️ That last figure is the reading AS OF commit cc837dbfe and is left as written: // the control is 73 today for the spelling reason recorded above, and the // population it feeds is still 80. Do not "correct" the paragraph — it is a // dated measurement, not a live claim. diff --git a/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts b/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts index 6cb5590d806..1d4ac547b63 100644 --- a/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts +++ b/packages/qa/dogfood/test/automation-toggle-tenant-scope.dogfood.test.ts @@ -1,12 +1,12 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. /** - * #10243 — the toggle card, now RULED: `POST /automation/:name/toggle` is + * The toggle card, now RULED (commit 266436a7f): `POST /automation/:name/toggle` is * gated on `manage_metadata`, and this file pins the closed door over HTTP. * * ## ⭐ This file was re-pointed, and the re-pointing is the record * - * It first landed (PR #10996) as a pure MEASUREMENT of the open half of the + * It first landed (commit 02b41232d) as a pure MEASUREMENT of the open half of the * card: whether one tenant's ungated toggle reached every organization. It * did — and it said, in this docblock, that a ruling *"flips these expectations * to a 403, and the flip is the point — an unrecorded verdict cannot be diff --git a/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts b/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts index 2f72b4dc269..4f1871ff773 100644 --- a/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts +++ b/packages/qa/dogfood/test/bearer-lane-password-change.dogfood.test.ts @@ -193,7 +193,7 @@ describe('#8049: /auth/change-password clears the force-change flag and enforces SYS, ) )[0]; - // [#8676] `previous_password_hashes` is `internal: true`, so it is omitted + // [commit d6e80b28b] `previous_password_hashes` is `internal: true`, so it is omitted // from the row above — there is no `isSystem` carve-out on the strip. Read // it through the engine's privileged accessor, which is the same channel // the production reuse ring now uses. ⛔ Do NOT "fix" a `[]` here by diff --git a/packages/qa/dogfood/test/build-shaped-artifact.ts b/packages/qa/dogfood/test/build-shaped-artifact.ts index 6b2afacf6ed..20c8535fa3d 100644 --- a/packages/qa/dogfood/test/build-shaped-artifact.ts +++ b/packages/qa/dogfood/test/build-shaped-artifact.ts @@ -1,7 +1,7 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // // A stand-in for `objectstack build`, for fixtures that need "the stack as a -// deployment receives it" (#6293). +// deployment receives it" (commit c39a911ae). // // ## The trap this exists to close // @@ -76,7 +76,7 @@ import { normalizeStackInput, ObjectStackDefinitionSchema } from '@objectstack/s // #12879 closed that hole, and this import is the one in-repo case it had to // decide explicitly. Declaring the subpath in the CLI's `exports` was the other // option and is the wrong one twice over: it would make an internal compiler -// util part of the published contract — which is #6293's ruling inverted (reach +// util part of the published contract — which is commit c39a911ae's ruling inverted (reach // the goal WITHOUT growing `@objectstack/cli`'s public entry) — and it would // ratify an accidental reachability nobody ever offered, pricing every later // internal refactor of that package at a minor bump. @@ -199,7 +199,7 @@ export function buildShapedArtifact(stack: Record): BuildShaped // else — no error, no warning, no key. Measured on this exact stack then: // hand the lowering the `{ effect: 'writes' }` husk `JSON.stringify` leaves // behind and the artifact came out `functions: {}`, parsing green, which is - // the #6293 failure wearing a different hat; the parse below could not see it, + // the failure commit c39a911ae fixed, wearing a different hat; the parse below could not see it, // because by the time it ran the evidence had been deleted. // // The producer was fixed at the source — an entry `lowerCallables` does not diff --git a/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts b/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts index 1e097bd6248..b57eff0799d 100644 --- a/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts +++ b/packages/qa/dogfood/test/comments-permission-matrix.dogfood.test.ts @@ -21,7 +21,7 @@ // // ⚠️ WHY THIS FILE IS ORG-BOUND, AND WHY THAT IS THE POINT ⚠️ // -// [#8408 / #8839] This file used to boot ORG-LESS, and the moderation half of +// [#8408 / commit c25b2d52a] This file used to boot ORG-LESS, and the moderation half of // case (d) — "a user who can EDIT the record may moderate anyone's comment on // it" — was GREEN ONLY BECAUSE OF THAT. It was #8023's disarm, measured rather // than suspected: @@ -42,7 +42,7 @@ // fixture was not evidence that moderation works; it was evidence that // moderation works WHEN NOBODY IS AN ORG MEMBER. // -// Maintainer ruling (2026-08-15, #8839 — reading 1): moderation is a declared, +// Maintainer ruling (2026-08-15, commit c25b2d52a — reading 1): moderation is a declared, // implemented capability and the platform delete floor must not pre-empt it. // `member_default` now carries a per-object `sys_comment_moderation` delete // policy (`id != null`, domained to `org_member`) contributing the alternate @@ -74,7 +74,7 @@ import { assertArmed, principalArmed } from './armed.js'; const SYS = { isSystem: true } as const; /** - * [#8074 / #8839] The control this file measures, and the default that silences + * [#8074 / commit c25b2d52a] The control this file measures, and the default that silences * it. Named here so the failure message says what was disarmed rather than * which assertion happened to notice. */ @@ -119,7 +119,7 @@ describe('sys_comment permission matrix (#4630)', () => { // AuditPlugin owns sys_comment: the #2707 enable.feeds gate AND the // #4630 record-level gates both ride on it. extraPlugins: [new AuditPlugin()], - // [#8839] Org-bound on purpose — see the header. A `sys_member` row is + // [commit c25b2d52a] Org-bound on purpose — see the header. A `sys_member` row is // what makes a sign-up hold `org_member`, which is what brings BOTH the // wildcard delete floor and the `sys_comment_moderation` policy into // scope. Org-less, case (d)'s moderation limb measures neither. @@ -141,7 +141,7 @@ describe('sys_comment permission matrix (#4630)', () => { await ql.insert('sys_user_permission_set', { user_id: userId, permission_set_id: managerSet.id }, { context: { ...SYS } }); } - // [#8074 / #8839] The precondition the header records in prose, now read off + // [#8074 / commit c25b2d52a] The precondition the header records in prose, now read off // the live stack and enforced BEFORE anything is measured. Asserted here // rather than in an `it()` on purpose: a disarmed fixture must produce ZERO // green cells, and #8023's harm was exactly one green cell in a matrix that @@ -271,7 +271,7 @@ describe('sys_comment permission matrix (#4630)', () => { // memberB holds the delete bit and can READ the record, but is neither the // author nor able to EDIT the (admin-owned, public_read) parent → 403. // - // [#8839] The CODE is asserted exactly, and that is the negative control for + // [commit c25b2d52a] The CODE is asserted exactly, and that is the negative control for // this whole card. Before the fix this refusal came from the platform's // wildcard delete floor (`PERMISSION_DENIED`, "(row-level security)") — the // parent-blind gate that was ALSO refusing legitimate moderators one case @@ -280,7 +280,7 @@ describe('sys_comment permission matrix (#4630)', () => { // plugin-audit's parent-derived gate instead: `RECORD_NOT_ACCESSIBLE`. // // So this is not a cosmetic tightening. Accepting `PERMISSION_DENIED` here - // would let the exact regression #8839 fixed pass unnoticed: the floor + // would let the exact regression commit c25b2d52a fixed pass unnoticed: the floor // re-asserting itself over `sys_comment` looks identical to a correct // refusal at the status-code level, and it kills moderation while this case // stays green. If this ever reddens with `PERMISSION_DENIED`, moderation is diff --git a/packages/qa/dogfood/test/enterprise-organizations.ts b/packages/qa/dogfood/test/enterprise-organizations.ts index 5c528f7cb02..ef4587ac6e5 100644 --- a/packages/qa/dogfood/test/enterprise-organizations.ts +++ b/packages/qa/dogfood/test/enterprise-organizations.ts @@ -142,7 +142,7 @@ export async function probeOrganizations( pkg: string = ORGANIZATIONS_PKG, ): Promise { const root = hostRoot ?? process.cwd(); - // #10943: hand the helper THIS module's resolver. Its undeclared fallback is + // Commit 46d34ab7c: hand the helper THIS module's resolver. Its undeclared fallback is // documented as "the importing package's own resolution", and a bare // `import()` written inside `@objectstack/types` is that package's // resolution, not this one's — it can see only `@objectstack/spec`. It makes diff --git a/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts b/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts index 3e39ea9dc5e..724ad875b6a 100644 --- a/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/schedule-organization-fixture.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// Fixture for the #16659 acting-organization pins: two `schedule` flows that +// Fixture for commit ecdfc9411's acting-organization pins: two `schedule` flows that // differ in EXACTLY ONE key — the `organization` declaration on the start node // — so the pins' red/green is attributable to that key and to nothing else. // @@ -12,7 +12,7 @@ /** * Object the tick touches, so a run has a data write of its own to land. * - * `due_date` is what the `time_relative` sweep selects on (#16659 F2). It is a + * `due_date` is what the `time_relative` sweep selects on (commit ecdfc9411, F2). It is a * `datetime` rather than a `date` deliberately: the window the trigger computes * is a pair of ISO-8601 instants, and comparing them against a column the * driver truncates to `YYYY-MM-DD` puts a per-driver truncation rule between @@ -115,7 +115,7 @@ export function organizationLessScheduleFlow(recipientId: string): unknown { } /** - * [#16659 F2] The `time_relative` twin: a sweep that declares its acting + * [commit ecdfc9411, F2] The `time_relative` twin: a sweep that declares its acting * organization, selects `sched_org_target` rows whose `due_date` falls in the * next week, and — once per matched record — notifies and writes. * diff --git a/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts b/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts index 032a59d05cd..4bbb11e3428 100644 --- a/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts +++ b/packages/qa/dogfood/test/hook-refusal-user-facing-marking.dogfood.test.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// [#9934] The producer-side user-facing marking, end-to-end through the real +// [commit 79c46da90] The producer-side user-facing marking, end-to-end through the real // stack — the producer half of the objectui#5210 ruling (maintainer, // 2026-08-19, option 1: producer-side opt-in). // @@ -86,7 +86,7 @@ const ufmStack = defineStack({ { // A sandboxed L2 BODY hook — the metadata-app authoring surface the // marking exists for. Its marking must survive the QuickJS boundary - // (the #9934 side-channel) and ride the sandbox-unwrap envelope. + // (the side-channel commit 79c46da90 added) and ride the sandbox-unwrap envelope. name: 'ufm_ref_guard', object: 'ufm_task', events: ['beforeDelete'], diff --git a/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts b/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts index 4eeef032e2d..14c33040a3a 100644 --- a/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts +++ b/packages/qa/dogfood/test/meta-published-and-state-routes.dogfood.test.ts @@ -43,7 +43,7 @@ describe('dogfood: /meta/:type/:name/published and /meta/object/:name/state/:fie const artifactPath = join(tempDir, 'objectstack.json'); // The real `objectstack build` lowering, not `JSON.stringify(stack)` — // that drops callables silently and the artifact parses green carrying - // none of what it advertises (#6293). + // none of what it advertises (commit c39a911ae). writeBuildShapedArtifact(showcaseStack as unknown as Record, artifactPath); stack = await bootStack(showcaseStack, { diff --git a/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts b/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts index b6a7adf5f20..fe7651b5b05 100644 --- a/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts +++ b/packages/qa/dogfood/test/multi-package-artifact.dogfood.test.ts @@ -202,7 +202,7 @@ describe('dogfood: the metadata door attributes a two-package artifact per packa beforeAll(async () => { tempDir = mkdtempSync(join(tmpdir(), 'os-14599-mp-')); const artifactPath = join(tempDir, 'objectstack.json'); - // The real build lowering, not `JSON.stringify(stack)` (#6293). + // The real build lowering, not `JSON.stringify(stack)` (commit c39a911ae). writeBuildShapedArtifact(multiPackageStack as unknown as Record, artifactPath); stack = await bootStack(multiPackageStack, { diff --git a/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts b/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts index aff0bbd837e..253d7e1d2ad 100644 --- a/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts +++ b/packages/qa/dogfood/test/organization-update-door.dogfood.test.ts @@ -43,7 +43,7 @@ * * ## Two more published surfaces move with the verb, and are pinned here too * - * The contract review of PR #16687 measured what the first round did not name: + * The contract review recorded in commit 779710213 measured what the first round did not name: * * - the DERIVED `import` door. `API_METHOD_DERIVATION` (`@objectstack/spec`, * `api-derivation.ts`) derives `import` from `any: ['create', 'update']`, so diff --git a/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts b/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts index 1dd56a47d8a..85b50ad5833 100644 --- a/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts +++ b/packages/qa/dogfood/test/packaged-activation-ledger-reach.dogfood.test.ts @@ -288,7 +288,7 @@ describe('#12159 Part 1 — a composition WITH automation: flows and actions bot const rows = await ql.find(LEDGER, { where: { metadata_type: 'flow' }, context: SYSTEM_CTX }); const row = rows.find((r) => r.name === FLOW); // The durable half. A toggle that only moved the engine's in-process - // projection is the #10243 mechanism ADR-0126 §7.2 retires, and it + // projection is the mechanism commit 02b41232d measured, which ADR-0126 §7.2 retires, and it // would look identical on the wire. expect(row, `no durable '${FLOW}' row — the flow ledger is not attached: ${JSON.stringify(rows)}`).toBeDefined(); expect(row!.active === false || row!.active === 0).toBe(true); diff --git a/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts b/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts index 8c30c18683e..6912955a070 100644 --- a/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts +++ b/packages/qa/dogfood/test/schedule-acting-organization.dogfood.test.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// [#16659] A time-triggered flow declares its acting organization and the run +// [commit ecdfc9411] A time-triggered flow declares its acting organization and the run // executes as it — proven end to end through the real automation + messaging + // ObjectQL stack, on BOTH drivers. // @@ -143,7 +143,7 @@ for (const databaseDriver of ['sqlite-wasm', 'memory'] as const) { // ⚠️ sqlite-wasm ONLY, and the asymmetry is measured rather than // assumed: `driver-memory` declares NO row-level tenant isolation and // REFUSES any call the engine hands a tenant scope - // (`MemoryMultiTenantUnsupportedError`, #16589 / #6915). An org-bound + // (`MemoryMultiTenantUnsupportedError`, commit 555a89cbd / #6915). An org-bound // session makes the authorization resolver's own `sys_position` read // tenant-scoped, so on that driver every HTTP request from such a // session 503s before reaching any route. The HTTP control is therefore @@ -532,7 +532,7 @@ for (const databaseDriver of ['sqlite-wasm', 'memory'] as const) { * third id, and `orgA`'s absence is the witness. On `driver-memory` no * session can be org-bound — the driver declares no row-level tenant * isolation and refuses any tenant-scoped call - * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, #16589 / #6915), so the + * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, commit 555a89cbd / #6915), so the * authorization resolver's own `sys_position` read is refused and the * door answers 503 before any route runs. This suite therefore boots * memory with `orgContext: false`, which leaves the HTTP caller carrying diff --git a/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts b/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts index 6b288bc5f03..180bb78ba22 100644 --- a/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts +++ b/packages/qa/dogfood/test/schedule-sweep-organization-scope.dogfood.test.ts @@ -1,6 +1,6 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. // -// [#16659 F2] A `time_relative` sweep SELECTS inside its declared organization +// [commit ecdfc9411, F2] A `time_relative` sweep SELECTS inside its declared organization // — proven on the real ObjectQL + driver stack, with matching rows in TWO // organizations. // @@ -105,7 +105,7 @@ const SYS = { context: { isSystem: true } }; * - **sqlite-wasm** enforces tenant isolation, so it can be asked the real * differential question: with rows in A and B, which come back? * - **memory** implements none and REFUSES any call handed a tenant scope - * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, #16589). The question it answers is the + * (`MEMORY_MULTI_TENANT_UNSUPPORTED`, commit 555a89cbd). The question it answers is the * one the card is really about: when a sweep required to stay inside one * organization cannot be served, does it SAY SO or go quiet? */ @@ -319,7 +319,7 @@ for (const databaseDriver of ['sqlite-wasm', 'memory'] as const) { * The store cannot honour the scope, so the sweep must be LOUD. * * PREDICTION, written before the run: `driver-memory` refuses the scoped - * `find` (#16589), the sweep's own error isolation catches it, and the + * `find` (commit 555a89cbd), the sweep's own error isolation catches it, and the * failure is logged at `error` naming the flow. ⛔ What must NOT happen is * the sweep quietly answering with every organization's rows — that is the * silent non-isolation the driver's refusal exists to remove, and this diff --git a/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts b/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts index ebbe1dcd211..9390046afb5 100644 --- a/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-anonymous-deny-surfaces.dogfood.test.ts @@ -23,7 +23,7 @@ // half — a guest / previewMode boot writes an `@anon` metadata seed, so does the // server refuse an anonymous WRITE? — and no artifact in this repo answered it // end-to-end. The mutating routes are now driven here as real HTTP (six when -// #11373 measured; five since #12176 D3 retired the compound save — see the +// #11373 measured; five since commit 7986d973f (D3) retired the compound save — see the // retired-door case beside the table). The reading is recorded in full at the // door table below; the short version is that the umbrella already refused all // of them, so #11373 is a measurement plus its pin, not a fix. @@ -128,7 +128,7 @@ interface MetaWriteDoor { * The five mutating `/meta` routes `registerMetadataEndpoints` composes. * * There were six when #11373 measured: `PUT /meta/:type/:section/:name` (the - * compound save) was retired by #12176 D3 — the item-name grammar (#12194) + * compound save) was retired by commit 7986d973f (D3) — the item-name grammar (commit 311433f6b) * refuses every slash-bearing name, so the arity addressed only names that can * no longer exist. A retired door cannot sit in this table: the registered-door * anti-vacuity leg below asserts `.not.toBe(404)`, which is exactly what a @@ -148,7 +148,7 @@ const META_WRITE_DOORS: readonly MetaWriteDoor[] = [ { seam: 'POST /meta/:type/:name/rollback', method: 'POST', path: `/meta/object/${META_PROBE_OBJECT}/rollback`, body: { toVersion: 1 } }, ]; -/** The retired compound-save spelling (#12176 D3) — routed nowhere, for anyone. */ +/** The retired compound-save spelling (commit 7986d973f, D3) — routed nowhere, for anyone. */ const RETIRED_COMPOUND_PATH = `/meta/object/views/${META_PROBE_VIEW}`; // ── #5632 — the TWO declared anonymous-401 envelopes, as executable rules ─── @@ -289,7 +289,7 @@ describe('showcase: anonymous posture is uniform across surfaces (#2567)', () => // method, same body, one process, one second apart: a session changes // the answer, so the refusal is the auth floor and not the door being // broken. (Deliberately not `.toBe(403)`. A member's exact status is the - // capability gate's business — #8919's proof owns that, and pinning it + // capability gate's business — commit b5378550e's proof owns that, and pinning it // here would make this file red for another proof's reasons. Measured // today it is 403 FORBIDDEN `manage_metadata` on all six.) // diff --git a/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts b/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts index 4d21af3f6b7..e1f4fe59a09 100644 --- a/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-declarative-endpoints.dogfood.test.ts @@ -110,9 +110,9 @@ beforeAll(async () => { // The artifact is written the way `objectstack build` writes one — the same // `normalizeStackInput` → `lowerCallables` → `ObjectStackDefinitionSchema` // pipeline `packages/cli/src/commands/compile.ts` runs, reusing those exact - // functions rather than re-deriving them (#6293). + // functions rather than re-deriving them (commit c39a911ae). // - // Until #6293 this line was `JSON.stringify(stack)` minus `functions`, and + // Until commit c39a911ae this line was `JSON.stringify(stack)` minus `functions`, and // the omission was deliberate and declared (#4976) because the substitute // could not carry them: `JSON.stringify` drops a bare callable KEY AND ALL // and reduces a declared one (`{ handler: fn, effect }`) to the headless husk @@ -155,7 +155,7 @@ afterAll(async () => { }); // ============================================================================ -// 0. The artifact this boot ingests is the shape the build writes (#6293) +// 0. The artifact this boot ingests is the shape the build writes (commit c39a911ae) // ============================================================================ describe('[#6293] the stand-in artifact carries what a built one carries', () => { diff --git a/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts b/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts index 3fec1eda046..27c45d8797a 100644 --- a/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-object-extension-meta-read.dogfood.test.ts @@ -61,7 +61,7 @@ describe('dogfood: an object extension reaches every /meta read (#7556)', () => const artifactPath = join(tempDir, 'objectstack.json'); // The real `objectstack build` lowering, not `JSON.stringify(stack)` — that // drops callables silently and the artifact parses green carrying none of - // what it advertises (#6293). + // what it advertises (commit c39a911ae). writeBuildShapedArtifact(showcaseStack as unknown as Record, artifactPath); stack = await bootStack(showcaseStack, { diff --git a/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts b/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts index c364a922646..2d159ac9963 100644 --- a/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-object-extension-scalar-divergence.dogfood.test.ts @@ -69,10 +69,10 @@ // Whether a package extension's label should outrank a tenant's Studio rename // is a fold-precedence decision the 2026-08-13 ruling did not make, and it is // NOT arm B (nothing here proposes dropping scalars from the fold). It was filed -// as a sub-issue of #8284 — #8460 — and ruled on separately. +// as a sub-issue of #8284 and ruled on separately (ADR-0029 D9.2a). // // ══════════════════════════════════════════════════════════════════════════ -// [#8460] THE FOLD LAYER, RULED AND FIXED — THE SECOND PIN IS NOW GREEN +// [ADR-0029 D9.2a] THE FOLD LAYER, RULED AND FIXED — THE SECOND PIN IS NOW GREEN // ══════════════════════════════════════════════════════════════════════════ // // Maintainer ruling, 2026-08-13 (option A, "tenant wins"): an extender's scalar @@ -244,11 +244,11 @@ describe('dogfood: the object-extension fold and the i18n catalog disagree on sc // is not the file's only word about it. This case asserts AGREEMENT and // the absence of the catalog string — never which value they agree on — // so it held under #8284 (all three served the extension's label, the - // tenant's rename lost inside the fold) and it holds under #8460 (all + // tenant's rename lost inside the fold) and it holds under ADR-0029 D9.2a (all // three serve the tenant's 'Customer', because the extender now yields // to a diverged base). That is the point of stating it this way: the // convergence #8284 bought is pinned independently of the fold - // precedence #8460 then settled, so a regression in either is visible + // precedence ADR-0029 D9.2a then settled, so a regression in either is visible // here without this case having to be rewritten when the other moves. // // Performs its own PUT rather than leaning on the case above: that case diff --git a/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts b/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts index 09074d46b41..342b8ccd99c 100644 --- a/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts +++ b/packages/qa/dogfood/test/showcase-permission-projection.dogfood.test.ts @@ -8,22 +8,22 @@ // 1. A data-door create/edit lands in the METADATA store (write-through) and // the record is re-derived by the AWAITED projector — consistent on the // very next read, no race. -// 2. [#6483 inverted this pin] A data-door edit of a CODE-DECLARED set is +// 2. [commit ee58392e1 inverted this pin] A data-door edit of a CODE-DECLARED set is // REFUSED — `permission` rolled back to `allowOrgOverride: false` // (ADR-0005 security row: "Authorization correctness; overlays would // create silent privilege drift"), so overriding an artifact-backed set // answers 403 `not_overridable` instead of minting an overlay. The -// pre-#6483 behaviour (ADR-0094's 2026-07-14 "customize via env +// behaviour before commit ee58392e1 (ADR-0094's 2026-07-14 "customize via env // overlay" direction) is closed until an ADR-0005 revision readmits the // type; ADR-0086 two-doors applies meanwhile (edit the package, // re-publish). // 3. Deleting a runtime-only set retires its record; deleting an // artifact-backed set never removes it — the definition ships with the -// app and cannot be removed from the environment. Since #6483 there is +// app and cannot be removed from the environment. Since commit ee58392e1 there is // no overlay left to lift, so that "reset" is a no-op success, not the // revert-to-the-declared-body step ADR-0094's 2026-07-14 direction // described (retired by D5-R). -// 4. [#6483 inverted this pin too] An environment-door metadata save that +// 4. [commit ee58392e1 inverted this pin too] An environment-door metadata save that // targets a package-owned, artifact-backed set is refused the same way — // record, provenance and effective body all stay exactly as shipped. // (Package-bound rows MATERIALIZED through the metadata door carry @@ -100,11 +100,11 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { expect(await overlayBody(NAME), 'metadata overlay gone too').toBeFalsy(); }); - // ── 2. Data-door edit of a DECLARED set is REFUSED (#6483) ──────────────── + // ── 2. Data-door edit of a DECLARED set is REFUSED (commit ee58392e1) ───── it('editing a declared set through the data door is refused — no overlay is minted', async () => { // member_default is a platform-declared set (an artifact baseline // exists), so the write-through's `saveMetaItem` hits the ADR-0005 type - // gate: `permission` is no longer `allowOrgOverride` (#6483, the + // gate: `permission` is no longer `allowOrgOverride` (commit ee58392e1, the // security row's "silent privilege drift"). The refusal must be LOUD — // an error status, not a 2xx that quietly skipped the metadata write — // and must leave no overlay behind (#6190's phantom-write shape is the @@ -124,13 +124,13 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { // ── 3. Delete of an artifact-backed set RESETS (does not remove) ────────── it('deleting a declared set through the data door resets it to the declared body, keeping the record', async () => { - // (#6483: with the edit above refused, there is no overlay to lift — the + // (commit ee58392e1: with the edit above refused, there is no overlay to lift — the // delete is a no-op reset. The invariant it pins is unchanged: a // declared definition cannot be removed from the environment.) const before = await findSet('member_default'); const res = await stack.apiAs(adminToken, 'DELETE', `/data/sys_permission_set/${before.id}`); expect(res.status).toBeLessThan(300); - // [#19306] The status cannot tell this reset apart from a real deletion — + // [commit f9e16d856] The status cannot tell this reset apart from a real deletion — // the whole envelope used to be byte-identical to one, so every assertion // below stayed green while the door told the caller the set was gone. // `success: false` is the one field that says the record is still here, @@ -144,7 +144,7 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { expect(after.description ?? null).not.toBe('customized via Setup (ADR-0094)'); }); - // ── 4. Env overlay of a PACKAGE set is REFUSED (#6483) ──────────────────── + // ── 4. Env overlay of a PACKAGE set is REFUSED (commit ee58392e1) ───────── it('an environment-door metadata save on a package-owned set is refused and changes nothing', async () => { const contributor = await findSet('showcase_contributor'); expect(contributor?.managed_by, 'showcase_contributor is package-owned').toBe('package'); @@ -152,7 +152,7 @@ describe('sys_permission_set pure projection (ADR-0094)', () => { const baseline = layeredBefore?.code ?? null; expect(baseline, 'the packaged declaration is the code layer').toBeTruthy(); - // #6483 — `permission` rolled back to `allowOrgOverride: false` + // Commit ee58392e1 — `permission` rolled back to `allowOrgOverride: false` // (ADR-0005 security row). The overlay ADR-0094's 2026-07-14 direction // used here is exactly the per-org shadowing of a code-shipped // authorization contract the ADR forbids, so the save refuses LOUDLY at diff --git a/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts b/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts index 2fa6a37340d..a7178dcdd40 100644 --- a/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts +++ b/packages/qa/dogfood/test/two-doors-permission.dogfood.test.ts @@ -13,7 +13,7 @@ // edit into an env-scope ADR-0005 overlay" direction was RETIRED on // 2026-08-09 — see ADR-0094 D5-R): a data-plane edit of a // package-managed, ARTIFACT-BACKED row is REFUSED with 403 -// `not_overridable` and no overlay is minted — #6483 rolled +// `not_overridable` and no overlay is minted — commit ee58392e1 rolled // `permission` back to `allowOrgOverride: false`, and ADR-0086 names // the supported channel instead: edit the package and re-publish. // A "delete" through this door still degrades to a RESET — a packaged @@ -78,9 +78,9 @@ describe('two-doors permission separation (ADR-0086 P2)', () => { }); }); - // ── 块2 — admin door: artifact-backed rows now REFUSE the overlay (#6483) ─ + // ── 块2 — admin door: artifact-backed rows now REFUSE the overlay (commit ee58392e1) ─ it('块2: an admin edit of a package-managed set is refused — no env overlay is minted (#6483)', async () => { - // Pre-#6483 this edit became an env-scope overlay (ADR-0094's 2026-07-14 + // Before commit ee58392e1 this edit became an env-scope overlay (ADR-0094's 2026-07-14 // direction). `permission` has since rolled back to // `allowOrgOverride: false` (ADR-0005 security row: "Authorization // correctness; overlays would create silent privilege drift"), so the @@ -105,13 +105,13 @@ describe('two-doors permission separation (ADR-0086 P2)', () => { }); it('块2: "deleting" the package set through the env door still RESETS to the shipped declaration', async () => { - // (#6483: with the edit above refused there is no overlay to lift, but + // (commit ee58392e1: with the edit above refused there is no overlay to lift, but // the invariant is unchanged and still pinned: the env door can never // remove a packaged definition — delete degrades to reset.) const before = await findSet('showcase_contributor'); const res = await stack.apiAs(adminToken, 'DELETE', `/data/sys_permission_set/${before.id}`); expect(res.status).toBeLessThan(300); - // [#19306] The status cannot tell this reset apart from a real deletion — + // [commit f9e16d856] The status cannot tell this reset apart from a real deletion — // the whole envelope used to be byte-identical to one, so every assertion // below stayed green while the door told the caller the set was gone. // `success: false` is the one field that says the record is still here, @@ -127,14 +127,14 @@ describe('two-doors permission separation (ADR-0086 P2)', () => { }); it('块2: the admin door CAN still edit an env-authored set (isolates the gate to artifact-backed rows)', async () => { - // The specimen was `member_default` until #6483: its record is env-owned + // The specimen was `member_default` until commit ee58392e1: its record is env-owned // (`managed_by` ≠ 'package'), but its METADATA identity is a platform // artifact (`defaultPermissionSets`), so with `permission` rolled back // to `allowOrgOverride: false` the write-through's `saveMetaItem` now // refuses to overlay it — the record's provenance column was never what // the gate reads. A truly env-AUTHORED set (created through the data // door, definition living only in `sys_metadata`) rides the - // `allowRuntimeCreate` tier, which #6483 deliberately left open — that + // `allowRuntimeCreate` tier, which commit ee58392e1 deliberately left open — that // is the boundary this case isolates. const NAME = 'twodoors_env_authored'; const created = await stack.apiAs(adminToken, 'POST', '/data/sys_permission_set', { diff --git a/packages/qa/dogfood/vitest.config.ts b/packages/qa/dogfood/vitest.config.ts index 449ce1e1630..82e8e513515 100644 --- a/packages/qa/dogfood/vitest.config.ts +++ b/packages/qa/dogfood/vitest.config.ts @@ -64,7 +64,7 @@ const SHARED_SHOWCASE = [ 'test/two-doors-permission.dogfood.test.ts', ]; -// #17853 / #17978 — say so when a path named on the command line will run no +// Commit 08f5f0e5a / #17978 — say so when a path named on the command line will run no // tests. Invoked HERE, at config load, and ⛔ deliberately NOT as a // `test.reporters` entry: naming that option replaces vitest's own reporter // defaulting instead of extending it, which measurably changes a healthy run's @@ -204,7 +204,7 @@ export default defineConfig({ find: /^@objectstack\/trigger-record-change$/, replacement: path.resolve(__dirname, '../../triggers/trigger-record-change/src/index.ts'), }, - // [#16659] `schedule-acting-organization.dogfood.test.ts` and + // [commit ecdfc9411] `schedule-acting-organization.dogfood.test.ts` and // `schedule-sweep-organization-scope.dogfood.test.ts` drive // `ScheduleTrigger` / `TimeRelativeTrigger` themselves: the pins' // whole subject is which