Skip to content

fix(ontology): discard prior evidence when reader scope changes - #1157

Open
seonghobae wants to merge 3 commits into
mainfrom
codex/development-loop-20261004
Open

seonghobae wants to merge 3 commits into
mainfrom
codex/development-loop-20261004

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Reader scope changes now clear the previous graph, selection, page cursor, exports, and nested search before the new reader, focus, or cutoff can render. Request-generation fencing ignores late replies from the prior scope. The branch is synchronized with current main using merge commit c4bda8c29a41109088d1f9718d588160be3a1801, preserving the independent 401 recovery behavior already on main.

Denied 401/403/404 evidence is cleared and offers the appropriate next action. Same-scope transient failures retain authorized pages and allow retry. No API shape, database schema, migration, dependency, release number, model policy, or calculation changed.

Validation on the synchronized code tree: 75 backend ontology/ingestion/cutoff/visibility tests; 74 frontend explorer/layout tests; frontend lint, production build, and Storybook build. Backend tests ran with DeprecationWarning treated as an error. Synthetic denied-scope Storybook rendering was visually inspected at 1440×900 and 390×844; both disable exports and show no graph evidence. Screenshots remain outside git.

GitHub reports four failed Checks on the current head. The run-detail request was rate-limited, so their causes are not claimed here. No current-head independent approval exists. The live rules read exposes only no-force-push protection and no classic branch-protection rules; auto-merge remains unarmed so it cannot bypass the requested review/check gates. Authenticated PostgreSQL/API acceptance, production UI acceptance, and synthetic authenticated k6 capacity evidence remain unavailable.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fa40c83d-db93-4442-ae58-858d017ea38e
📥 Commits

Reviewing files that changed from the base of the PR and between 2905bae and c4bda8c.

📒 Files selected for processing (5)
  • docs/product-technical-gap-baseline.md
  • docs/storybook-inventory.md
  • frontend/src/components/OntologyExplorer.stories.tsx
  • frontend/src/components/OntologyExplorer.test.tsx
  • frontend/src/components/OntologyExplorer.tsx
🚧 Files skipped from review as they are similar to previous changes (2)
  • docs/storybook-inventory.md
  • docs/product-technical-gap-baseline.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

OntologyExplorer는 reader, focus 또는 cutoff 변경 시 기존 데이터와 선택 상태를 초기화합니다. 이전 요청의 결과와 오류는 현재 뷰에 반영되지 않습니다. 관련 테스트, Storybook 사례, ADR과 기술 기준 문서도 갱신했습니다.

Changes

OntologyExplorer 요청 범위 처리

Layer / File(s) Summary
요청 범위 초기화와 응답 처리
frontend/src/components/OntologyExplorer.tsx
token, focus, cutoff를 요청 범위로 추적합니다. 범위가 바뀌면 데이터를 초기화하고, 이전 요청의 성공과 오류를 무시합니다. 권한 거부와 focus 초기화·변경 시에도 로드 데이터와 선택 상태를 비웁니다.
범위 변경 검증과 로딩 사례
frontend/src/components/OntologyExplorer.test.tsx, frontend/src/components/OntologyExplorer.stories.tsx, docs/storybook-inventory.md, docs/adr/0184-ontology-provenance-explorer.md
테스트는 범위 및 인증 변경, 오래된 응답, 이어보기 권한 거부, 중첩 검색 결과 무효화를 검증합니다. cutoff 로딩 스토리를 추가하고 ADR에 범위 변경 시 데이터 폐기 규칙을 기록합니다.
통합 현황과 검증 기록
docs/product-technical-gap-baseline.md
PR의 저장소·브랜치 규칙 관찰, 통합 방식, 로컬 검사와 Storybook 결과를 기록합니다. 사용할 수 없었던 인증 API, PostgreSQL, k6 검증 근거도 명시합니다.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to c4bda

The change makes the ontology explorer discard earlier evidence when the reader, cutoff or focus changes, and it ignores late responses from the old scope. No concrete merge-blocking problem was found, and tests cover the main cases. Authenticated end-to-end validation was not run.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c4bda

The change reduces stale-evidence exposure when the reader or exploration scope changes. No new security issue was identified in the inspected production path. Caller-supplied data ownership and deployed authorization enforcement remain outside the verified scope.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly affected exposure is evidence already loaded into one explorer instance: graph content, selection, pagination, exports and nested search. The inspected change does not grant additional backend authority; the extent of data a reader may fetch still depends on server authorization, which was not validated here.

Security Findings and Attack Paths

  • inferred — The inspected changes narrow the prior-reader stale-evidence path rather than expand it. The production invocation is unchanged and supplies no neighborhood payload; no introduced or worsened attack path was verified within this inspected scope.

Trust Boundaries and Controls

  • observed — Focus, cutoff and cursor values remain query parameters on the existing neighborhood endpoint, and the current token is sent as a Bearer credential. Generation fencing controls which response may mutate client state; it is not a substitute for server-side authorization.
  • observed — The inherited optional neighborhood prop is trusted as supplied data and its payload carries no reader-ownership metadata. The PR preserves this contract, and the inspected production caller does not use it. Ownership guarantees for other supplied-data callers remain unproven, not an active PR finding.

Resilience and Maintainability Implications

  • observed — Obsolete failures cannot clear a newer generation's evidence or mark its token rejected. Current-generation authorization failures discard evidence, while same-scope transient continuation errors preserve loaded pages for recovery.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 3 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 독자 범위가 바뀔 때 이전 증거를 폐기하는 핵심 변경 사항을 간결하고 구체적으로 설명합니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 3 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant