diff --git a/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts b/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts index 5dfa39d3d05..2bfa9f7bcf6 100644 --- a/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts +++ b/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts @@ -118,7 +118,7 @@ async function boot(ctx: any, options: Record = {}) { return plugin; } -describe('[#10036] the "nothing is enforced" warning must fire when SecurityPlugin.start() bailed', () => { +describe('the "nothing is enforced" warning must fire when SecurityPlugin.start() bailed', () => { // ── The state the warning describes, constructed for real ─────────────── // // SecurityPlugin registers `security.permissions` / `security.rls` / diff --git a/packages/qa/dogfood/test/armed.ts b/packages/qa/dogfood/test/armed.ts index 9d212a9e293..35d9f4a2712 100644 --- a/packages/qa/dogfood/test/armed.ts +++ b/packages/qa/dogfood/test/armed.ts @@ -133,9 +133,9 @@ export async function assertArmed(probes: readonly ArmingProbe[]): Promise if (!Array.isArray(probes) || probes.length === 0) { throw new Error( 'assertArmed(): the arming declaration is EMPTY, which asserts nothing. An empty ' + - 'declaration would certify every fixture that forgot to write one — the exact defect ' + - 'class this helper exists to close (#8074). Name at least one control, or do not call ' + - 'assertArmed at all and say in the fixture header why no precondition applies.', + 'declaration would certify every fixture that forgot to write one — the exact defect class this ' + + 'helper exists to close, a fixture that passes while the control it measures is not engaged. Name ' + + 'at least one control, or do not call assertArmed at all and say in the fixture header why no precondition applies.', ); } @@ -159,7 +159,7 @@ export async function assertArmed(probes: readonly ArmingProbe[]): Promise if (disarmed.length > 0) { throw new Error( - `[#8074] this fixture is DISARMED: ${disarmed.length} of ${probes.length} control(s) it ` + + `assertArmed(): this fixture is DISARMED: ${disarmed.length} of ${probes.length} control(s) it ` + 'measures are not engaged on the booted stack, so its assertions would pass without ' + 'testing anything.\n\n' + `${disarmed.join('\n\n')}\n\n` + diff --git a/packages/qa/dogfood/test/build-shaped-artifact.ts b/packages/qa/dogfood/test/build-shaped-artifact.ts index 20c8535fa3d..a7f5170e4a2 100644 --- a/packages/qa/dogfood/test/build-shaped-artifact.ts +++ b/packages/qa/dogfood/test/build-shaped-artifact.ts @@ -189,7 +189,7 @@ export function buildShapedArtifact(stack: Record): BuildShaped `declares ${expected.length} (${expected.join(', ') || 'none'}). Either a callable was ` + `dropped, or \`lowerCallables\` grew a slot \`callableSlots\` in ` + `packages/qa/dogfood/test/build-shaped-artifact.ts does not know about — fix the walk, ` + - `never the assertion (#6293).`, + `never the assertion.`, ); } @@ -222,7 +222,7 @@ export function buildShapedArtifact(stack: Record): BuildShaped `without a sound — ${dropped.join(', ')}. An entry it does not recognise is deleted ` + `rather than handed to the schema, so the artifact would parse green carrying nothing ` + `where these were. Most likely the entry is a headless husk (an object with an effect ` + - `and no handler), which is what a plain \`JSON.stringify\` of the stack leaves (#6293).`, + `and no handler), which is what a plain \`JSON.stringify\` of the stack leaves.`, ); } } @@ -262,7 +262,7 @@ export function buildShapedArtifact(stack: Record): BuildShaped if (leftover.length > 0) { throw new Error( `build-shaped artifact: ${leftover.length} value(s) are still functions after lowering and ` + - `would be dropped by JSON.stringify without a sound: ${leftover.join(', ')} (#6293).`, + `would be dropped by JSON.stringify without a sound: ${leftover.join(', ')}.`, ); } diff --git a/packages/qa/dogfood/test/enterprise-organizations.ts b/packages/qa/dogfood/test/enterprise-organizations.ts index ef4587ac6e5..379509284f0 100644 --- a/packages/qa/dogfood/test/enterprise-organizations.ts +++ b/packages/qa/dogfood/test/enterprise-organizations.ts @@ -181,7 +181,7 @@ export async function probeOrganizations( 'problem — the package publishes no entry Node can load, and the importer\'s ' + 'message below is the authority on what it has to publish' : `declare ${pkg} in ${root}'s own package.json and install it — being ` + - 'reachable as somebody else\'s transitive dependency is not enough (#4719)'; + 'reachable as somebody else\'s transitive dependency is not enough'; if (declared) { throw new Error( `${MULTI_ORG_ENV}=1 declares that ${pkg} (enterprise, ADR-0105 D12) is ` + diff --git a/packages/qa/dogfood/test/expression-conformance.ledger.ts b/packages/qa/dogfood/test/expression-conformance.ledger.ts index f21b363262e..99ab76ff0a5 100644 --- a/packages/qa/dogfood/test/expression-conformance.ledger.ts +++ b/packages/qa/dogfood/test/expression-conformance.ledger.ts @@ -141,7 +141,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [ }, { id: 'sharing-condition', - summary: 'sharing-rule `condition` → criteria_json (ADR-0058 D3, closes #1887)', + summary: 'sharing-rule `condition` → criteria_json (ADR-0058 D3: compiled from the authored CEL, a faithful lowering rather than a divergent hand-written filter)', dialect: 'cel', mode: 'compile', state: 'enforced', failPolicy: 'fail-closed', enforcement: 'plugin-sharing/bootstrap-declared-sharing-rules.ts celToFilter → compileCelToFilter; matched by sharing-rule-service findMatchingRecords', covers: ['security/sharing.zod.ts:CriteriaSharingRuleSchema.condition'], @@ -290,7 +290,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [ // from the schema. dialect: 'settings-visibility', mode: 'interpret', state: 'enforced', failPolicy: 'fail-closed', enforcement: - 'service-settings `evaluateVisibility` (visibility-eval.ts), called from `SettingsService.validatePatch` — a closed grammar: single root `data`, one-level member access, `|| && !`, `=== !== == != >= <= > <`, parens, and string/number/bool/null literals, optionally `${…}`-wrapped, as a bare string or a `{dialect, source}` envelope. Fail-closed since #7310: a predicate outside the grammar REFUSES the save (SettingsValidationError, HTTP 400) instead of skipping the specifier — `visible` gates every other check on the key (`required`, `options`, `pattern`, `valueDomain`, the value window), so skipping it switched all of them off at once. The console evaluates the same string client-side through `new Function(...)`. Since #7327 the spec DECLARES that same grammar (`SettingsVisibilityInputSchema`), so it is refused at publish/parse too', + 'service-settings `evaluateVisibility` (visibility-eval.ts), called from `SettingsService.validatePatch` — a closed grammar: single root `data`, one-level member access, `|| && !`, `=== !== == != >= <= > <`, parens, and string/number/bool/null literals, optionally `${…}`-wrapped, as a bare string or a `{dialect, source}` envelope. Fail-closed: a predicate outside the grammar REFUSES the save (SettingsValidationError, HTTP 400) instead of skipping the specifier — `visible` gates every other check on the key (`required`, `options`, `pattern`, `valueDomain`, the value window), so skipping it switched all of them off at once. The console evaluates the same string client-side through `new Function(...)`. The spec DECLARES that same grammar (`SettingsVisibilityInputSchema`) rather than CEL, so it is refused at publish/parse too', covers: ['system/settings-manifest.zod.ts:SpecifierSchema.visible', 'system/settings-manifest.zod.ts:SettingsManifestSchema.visible'], // Proof is the producer/consumer pin rather than a runtime fixture: the // failure mode this surface actually has is the two sides disagreeing about @@ -300,7 +300,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [ }, { id: 'cel-action-param-option-visible', - summary: "action param option-list per-option gating (params[].options[].visibleWhen, #5016)", + summary: "action param option-list per-option gating (params[].options[].visibleWhen, the same per-option key a field's option list declares)", // Same key, same evaluator and same binding environment as the per-option // `visibleWhen` on a FIELD's option list — which is why it is `cel`, // `interpret` and `fail-soft-log` like `cel-field-rule` rather than @@ -316,7 +316,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [ }, { id: 'cel-bulk-action-visible', - summary: "selection-bar bulk action per-record eligibility (bulkActionDefs[].visible, objectui#3067)", + summary: "selection-bar bulk action per-record eligibility (bulkActionDefs[].visible)", dialect: 'cel', mode: 'interpret', state: 'enforced', failPolicy: 'fail-closed', enforcement: 'console (objectui) partitionBulkRows (plugin-grid/bulkEligibility.ts) → evalRowPredicate → @objectstack/formula celEngine (interpret), evaluated ONCE PER SELECTED RECORD with that record bound: the button is offered when at least one selected record passes, and the run covers only those — the rest are reported as skipped in the dialog. Faults hide the record (fallback:false, warnOnError) rather than acting on one the predicate was written to exclude; UI gating only, write enforcement stays with permissions/hooks', // Reached the ledger in #4457, not #3067: the key existed and was evaluated @@ -340,14 +340,14 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [ }, { id: 'cel-row-crud-visible', - summary: 'built-in row Edit/Delete per-record visibility (RowCrudActionOverride.visibleWhen, objectui#2614)', + summary: 'built-in row Edit/Delete per-record visibility (RowCrudActionOverride.visibleWhen)', dialect: 'cel', mode: 'interpret', state: 'enforced', failPolicy: 'fail-closed', enforcement: 'console (objectui) RowActionMenu BuiltinRowActionItem + data-table DataTableBuiltinRowActionItem → useRowPredicate → @objectstack/formula celEngine (interpret); FALSE/fault hides the row button (UI gating only — write enforcement stays with permissions/hooks)', covers: ['data/object.zod.ts:RowCrudActionOverrideSchema.visibleWhen'], }, { id: 'cel-row-crud-disabled', - summary: 'built-in row Edit/Delete per-record disabling (userActions.{edit,delete}.disabledWhen, objectui#2614)', + summary: 'built-in row Edit/Delete per-record disabling (userActions.{edit,delete}.disabledWhen)', dialect: 'cel', mode: 'interpret', state: 'enforced', failPolicy: 'fail-soft-log', enforcement: 'console (objectui) RowActionMenu BuiltinRowActionItem + data-table DataTableBuiltinRowActionItem → useRowPredicate → @objectstack/formula celEngine (interpret); TRUE renders the button disabled, a fault leaves it enabled (server hooks are the real boundary)', covers: ['data/object.zod.ts:RowCrudActionOverrideSchema.disabledWhen'], diff --git a/packages/qa/dogfood/test/fixtures/attachments-fixture.ts b/packages/qa/dogfood/test/fixtures/attachments-fixture.ts index 6737a29ab8c..9a467bd77f4 100644 --- a/packages/qa/dogfood/test/fixtures/attachments-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/attachments-fixture.ts @@ -137,7 +137,7 @@ export const attachmentsFixtureStack = defineStack({ type: 'app', name: 'Attachments Permission Matrix Fixture', description: - 'Three-object app exercising the #2755 attachment permission matrix: parent visibility, uploader/editor delete, enable.files gate.', + 'Three-object app exercising the non-admin attachment permission matrix: parent visibility, uploader/editor delete, enable.files gate.', }, objects: [AttCase, AttSecret, AttNoFiles, AttReadonly], }); diff --git a/packages/qa/dogfood/test/fixtures/comments-fixture.ts b/packages/qa/dogfood/test/fixtures/comments-fixture.ts index 3b7ec326eab..a38293dd87b 100644 --- a/packages/qa/dogfood/test/fixtures/comments-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/comments-fixture.ts @@ -136,7 +136,7 @@ export const commentsFixtureStack = defineStack({ type: 'app', name: 'Comments Permission Matrix Fixture', description: - 'Four-object app exercising the #4630 comment permission matrix: thread visibility, author/parent-editor writes, the enable.feeds gate.', + 'Four-object app exercising the record-level comment permission matrix: thread visibility, author/parent-editor writes, the enable.feeds gate.', }, objects: [CmtOpen, CmtPrivate, CmtReadonly, CmtNoFeeds], }); diff --git a/packages/qa/dogfood/test/fixtures/email-template-materialization-fixture.ts b/packages/qa/dogfood/test/fixtures/email-template-materialization-fixture.ts index f4c78431f76..427e36babf8 100644 --- a/packages/qa/dogfood/test/fixtures/email-template-materialization-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/email-template-materialization-fixture.ts @@ -56,7 +56,7 @@ export const emailTemplateFixtureStack = defineStack({ version: '0.0.0', type: 'app', name: 'Email Template Materialization Fixture', - description: 'Single-object app that authors one email template to prove stack `emailTemplates:` entries materialize into the sys_email_template rows sendTemplate reads (ADR-0054, #4509).', + description: 'Single-object app that authors one email template to prove stack `emailTemplates:` entries materialize into the sys_email_template rows sendTemplate reads (ADR-0054).', }, objects: [EtNote], emailTemplates: [etPasswordReset], diff --git a/packages/qa/dogfood/test/fixtures/flow-durable-suspend-fixture.ts b/packages/qa/dogfood/test/fixtures/flow-durable-suspend-fixture.ts index 75e4339d89f..cb1fe12b57a 100644 --- a/packages/qa/dogfood/test/fixtures/flow-durable-suspend-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/flow-durable-suspend-fixture.ts @@ -98,7 +98,7 @@ export const durableSuspendStack = defineStack({ version: '0.0.0', type: 'app', name: 'Durable Suspend Fixture', - description: 'Single-object app whose screen flow suspends, persists, and resumes after a cold boot (#4470).', + description: 'Single-object app whose screen flow suspends, persists, and resumes after a cold boot.', }, objects: [SuspendNote], flows: [flowDurableSuspend], diff --git a/packages/qa/dogfood/test/fixtures/flow-function-effect-fixture.ts b/packages/qa/dogfood/test/fixtures/flow-function-effect-fixture.ts index a5fb4119c59..a9f3bb94c26 100644 --- a/packages/qa/dogfood/test/fixtures/flow-function-effect-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/flow-function-effect-fixture.ts @@ -66,7 +66,7 @@ export const flowFunctionEffectStack = defineStack({ version: '0.0.0', type: 'app', name: 'Flow Function Effect Fixture', - description: "Proves a flow function's declared effect reaches the run summary (#4396).", + description: "Proves a flow function's declared effect reaches the run summary.", }, objects: [FxInvoice], flows: [sweepFlow('fxn_pure_sweep', 'scoreInvoices'), sweepFlow('fxn_writing_sweep', 'syncBilling')], diff --git a/packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts b/packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts index 120089a8266..d964d5602a4 100644 --- a/packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts @@ -122,7 +122,7 @@ export const runasFixtureStack = defineStack({ version: '0.0.0', type: 'app', name: 'Flow runAs Fixture', - description: 'Owner-isolated single-object app exercising flow.runAs identity enforcement (#1888).', + description: 'Owner-isolated single-object app exercising flow.runAs identity enforcement.', }, objects: [RunAsNote], flows: [runasSystemTouch, runasUserTouch, runasSystemRead, runasUserRead], diff --git a/packages/qa/dogfood/test/fixtures/label-scope-fixture.ts b/packages/qa/dogfood/test/fixtures/label-scope-fixture.ts index fcde6d90506..14bedf970f8 100644 --- a/packages/qa/dogfood/test/fixtures/label-scope-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/label-scope-fixture.ts @@ -52,7 +52,7 @@ export const labelScopeStack = defineStack({ version: '0.0.0', type: 'app', name: 'Label Scope Fixture', - description: 'Deal → vendor lookup exercising the #3602 label read-scope leak.', + description: 'Deal → vendor lookup exercising the dimension-label read scope: a vendor the reader cannot read is shown by raw id, never by name.', }, objects: [Vendor, Deal], }); diff --git a/packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts b/packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts index ba990f3f2b9..c946f299ff1 100644 --- a/packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts @@ -54,7 +54,7 @@ export const rlsFixtureStack = defineStack({ version: '0.0.0', type: 'app', name: 'RLS Owner Fixture', - description: 'Owner-isolated single-object app exercising the #1994 by-id-write invariant.', + description: 'Owner-isolated single-object app exercising the cross-owner by-id-write invariant: a caller that cannot read a record must not be able to write it.', }, objects: [RlsNote], }); @@ -102,7 +102,7 @@ export const ownerScopedMemberSet: PermissionSet = PermissionSetSchema.parse({ */ export const readOnlyScopedMemberSet: PermissionSet = PermissionSetSchema.parse({ name: FIXTURE_MEMBER_SET, - label: 'RLS Fixture Member — owner-scoped reads only (#1994 hole)', + label: 'RLS Fixture Member — owner-scoped reads only (no write policy: the by-id-write hole shape)', objects: noteCrud, rowLevelSecurity: [{ ...RLS.ownerPolicy('rls_note', 'created_by'), operation: 'select' }], }); diff --git a/packages/qa/dogfood/test/fixtures/webhook-materialization-fixture.ts b/packages/qa/dogfood/test/fixtures/webhook-materialization-fixture.ts index 41d629d9f0f..93aa278522b 100644 --- a/packages/qa/dogfood/test/fixtures/webhook-materialization-fixture.ts +++ b/packages/qa/dogfood/test/fixtures/webhook-materialization-fixture.ts @@ -52,7 +52,7 @@ export const webhookFixtureStack = defineStack({ version: '0.0.0', type: 'app', name: 'Webhook Materialization Fixture', - description: 'Single-object app that authors one webhook to prove stack `webhooks:` entries materialize into dispatchable sys_webhook rows (ADR-0054, #3461).', + description: 'Single-object app that authors one webhook to prove stack `webhooks:` entries materialize into dispatchable sys_webhook rows (ADR-0054).', }, objects: [WmTask], webhooks: [wmTaskChanged], diff --git a/packages/qa/dogfood/test/search-conformance.ledger.ts b/packages/qa/dogfood/test/search-conformance.ledger.ts index 8d32763242c..2a16e69f79f 100644 --- a/packages/qa/dogfood/test/search-conformance.ledger.ts +++ b/packages/qa/dogfood/test/search-conformance.ledger.ts @@ -46,7 +46,7 @@ export const SEARCH_SURFACE: ConformanceRow[] = [ }, { id: 'search-fields-override', - summary: '`$searchFields` per-query narrowing — validated against the allowed set, can never widen it; a name outside the set is 400 INVALID_FIELD at the REST ingress (#4254), not silently dropped', + summary: '`$searchFields` per-query narrowing — validated against the allowed set, can never widen it; a name outside the set is 400 INVALID_FIELD at the REST ingress, not silently dropped', surface: 'spec/api/query.zod.ts:$searchFields', state: 'enforced', enforcement: 'spec/data/search-fields.ts resolveSearchFields (intersection) + metadata-protocol/src/protocol.ts assertSearchFieldsAreSearchable (ingress gate)', diff --git a/packages/qa/dogfood/test/showcase-security.ts b/packages/qa/dogfood/test/showcase-security.ts index 93d03148dfd..1505e52bd32 100644 --- a/packages/qa/dogfood/test/showcase-security.ts +++ b/packages/qa/dogfood/test/showcase-security.ts @@ -63,7 +63,7 @@ export function showcaseAppDefaultSecurity(extraObjectGrants?: ObjectGrants): Se // which reads as a security regression rather than a missing declaration. throw new Error( '[dogfood] the showcase stack declares no `isDefault` permission set — the CLI wiring ' + - 'these fixtures model cannot be reproduced (#5491)', + 'these fixtures model cannot be reproduced, and the platform baseline alone grants a member no object access', ); } const appDefault = PermissionSetSchema.parse(declaredDefault) as PermissionSet; diff --git a/packages/qa/downstream-contract/src/stack.ts b/packages/qa/downstream-contract/src/stack.ts index fe20ebd86d1..f7eb9e91fc1 100644 --- a/packages/qa/downstream-contract/src/stack.ts +++ b/packages/qa/downstream-contract/src/stack.ts @@ -16,7 +16,7 @@ export const ContractStack = defineStack({ version: '1.0.0', type: 'app', name: 'Downstream Contract', - description: 'Frozen third-party consumer gating spec backward compatibility (#2035).', + description: 'Frozen third-party consumer gating spec backward compatibility: a spec change that needs this fixture edited to stay green is breaking.', }, objects: [Account], views: [AccountViews], diff --git a/scripts/doc-authoring-prose-id.baseline.json b/scripts/doc-authoring-prose-id.baseline.json index 3d8b2879b8b..406c73d1729 100644 --- a/scripts/doc-authoring-prose-id.baseline.json +++ b/scripts/doc-authoring-prose-id.baseline.json @@ -247,9 +247,6 @@ "#5973": 1, "#6428": 1 }, - "packages/qa/dogfood/test/armed.ts": { - "#8074": 2 - }, "packages/qa/dogfood/test/authz-conformance.matrix.ts": { "#10145": 1, "#10243": 1, @@ -298,56 +295,6 @@ "#9083": 2, "#9377": 1 }, - "packages/qa/dogfood/test/build-shaped-artifact.ts": { - "#6293": 3 - }, - "packages/qa/dogfood/test/enterprise-organizations.ts": { - "#4719": 1 - }, - "packages/qa/dogfood/test/expression-conformance.ledger.ts": { - "#1887": 1, - "#2614": 2, - "#3067": 1, - "#5016": 1, - "#7310": 1, - "#7327": 1 - }, - "packages/qa/dogfood/test/fixtures/attachments-fixture.ts": { - "#2755": 1 - }, - "packages/qa/dogfood/test/fixtures/comments-fixture.ts": { - "#4630": 1 - }, - "packages/qa/dogfood/test/fixtures/email-template-materialization-fixture.ts": { - "#4509": 1 - }, - "packages/qa/dogfood/test/fixtures/flow-durable-suspend-fixture.ts": { - "#4470": 1 - }, - "packages/qa/dogfood/test/fixtures/flow-function-effect-fixture.ts": { - "#4396": 1 - }, - "packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts": { - "#1888": 1 - }, - "packages/qa/dogfood/test/fixtures/label-scope-fixture.ts": { - "#3602": 1 - }, - "packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts": { - "#1994": 2 - }, - "packages/qa/dogfood/test/fixtures/webhook-materialization-fixture.ts": { - "#3461": 1 - }, - "packages/qa/dogfood/test/search-conformance.ledger.ts": { - "#4254": 1 - }, - "packages/qa/dogfood/test/showcase-security.ts": { - "#5491": 1 - }, - "packages/qa/downstream-contract/src/stack.ts": { - "#2035": 1 - }, "packages/services/service-analytics/src/analytics-service.ts": { "#3867": 1, "#5222": 1,