You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #235 predecessor head ccb5c0c58dc74c1d7eee59431e6337c207fcac35 already made retained ValidationPrincipal and persisted ValidityStudyRecord evidence structurally immutable, but the field-minimized authorization result still left the boundary as @dataclass(frozen=True, slots=True) ValidityStudyView.
frozen=True blocks ordinary assignment but does not prevent a caller retaining the returned view from rewriting tenant_record_id, validity_study_id, or fields through object.__setattr__. That creates a checked-versus-used gap after purpose/tenant/field authorization: a gateway, audit serializer, or role workspace can receive an object whose identity/authorized field evidence no longer matches what read_validity_study(...) actually authorized.
This is the output-side counterpart of #236/#237. It is not a reason to close or supersede #235.
Test-first repair
1a344f8057755ae8b652c31963d787ff8abf2beb adds a regression that obtains a real authorized view, attempts object.__setattr__ against tenant identity, study identity, and minimized fields, and requires AttributeError while retaining the original authorized values. Its hosted runs were cancelled after the ordinary production successor was pushed, so this is causal test-first evidence rather than a claimed hosted RED.
No force-push, destructive rebase, gate weakening, or predecessor-evidence transfer was used.
Current acceptance
Exact #235 head is 17092c94d180d082d1e389982e0beea9872f53f9 over protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Foundation 33957110271 / Repository quality 101282323502, Security Scan 33957110265, SAST Semgrep 33957110263, and CodeQL PR 33957110288 are current-head workflows and remain non-terminal at the latest read.
CodeRabbit independently reviewed exact 17092c94d... against protected develop@eb9757f... and reported no blocking issue in the requested #241 scope. It confirmed the tuple-backed ValidityStudyView, unchanged public property shape, the object.__setattr__ regression, preserved static read-port capability check/principal reconstruction/policy detachment/authorization ordering, no Keyverse/global-migration/SQL-adapter expansion, and no removed gate. This is static review evidence only; GitHub formal reviews remain empty and no qualifying approval is claimed.
Keep this issue open until the repaired #235 head reaches protected integration or a verified successor fully inherits the regression and invariant.
Finding
PR #235 predecessor head
ccb5c0c58dc74c1d7eee59431e6337c207fcac35already made retainedValidationPrincipaland persistedValidityStudyRecordevidence structurally immutable, but the field-minimized authorization result still left the boundary as@dataclass(frozen=True, slots=True) ValidityStudyView.frozen=Trueblocks ordinary assignment but does not prevent a caller retaining the returned view from rewritingtenant_record_id,validity_study_id, orfieldsthroughobject.__setattr__. That creates a checked-versus-used gap after purpose/tenant/field authorization: a gateway, audit serializer, or role workspace can receive an object whose identity/authorized field evidence no longer matches whatread_validity_study(...)actually authorized.This is the output-side counterpart of #236/#237. It is not a reason to close or supersede #235.
Test-first repair
1a344f8057755ae8b652c31963d787ff8abf2bebadds a regression that obtains a real authorized view, attemptsobject.__setattr__against tenant identity, study identity, and minimizedfields, and requiresAttributeErrorwhile retaining the original authorized values. Its hosted runs were cancelled after the ordinary production successor was pushed, so this is causal test-first evidence rather than a claimed hosted RED.17092c94d180d082d1e389982e0beea9872f53f9replaces only the frozen-slot output dataclass with a slotless tuple-backedValidityStudyView. Existing keyword construction plus.tenant_record_id,.validity_study_id, and.fieldsaccess remain unchanged. Authorization, owner-port invocation, SQL/schema, Foundation wiring, and security(workforce_validation): make validity-study persistence evidence structurally immutable #236/fix(workforce-validation): make authenticated principal evidence structurally immutable #237/fix(workforce-validation): revalidate canonical principal storage before authorization #239/fix(workforce-validation): reject non-callable repository capability before authorization #240 semantics are untouched.No force-push, destructive rebase, gate weakening, or predecessor-evidence transfer was used.
Current acceptance
Exact #235 head is
17092c94d180d082d1e389982e0beea9872f53f9over protecteddevelop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Foundation33957110271/ Repository quality101282323502, Security Scan33957110265, SAST Semgrep33957110263, and CodeQL PR33957110288are current-head workflows and remain non-terminal at the latest read.CodeRabbit independently reviewed exact
17092c94d...against protecteddevelop@eb9757f...and reported no blocking issue in the requested #241 scope. It confirmed the tuple-backedValidityStudyView, unchanged public property shape, theobject.__setattr__regression, preserved static read-port capability check/principal reconstruction/policy detachment/authorization ordering, no Keyverse/global-migration/SQL-adapter expansion, and no removed gate. This is static review evidence only; GitHub formal reviews remain empty and no qualifying approval is claimed.Keep this issue open until the repaired #235 head reaches protected integration or a verified successor fully inherits the regression and invariant.