Skip to content

fix(workforce-validation): make authorized registry views structurally immutable #241

Description

@seonghobae

Finding

PR #235 predecessor head ccb5c0c58dc74c1d7eee59431e6337c207fcac35 already made retained ValidationPrincipal and persisted ValidityStudyRecord evidence structurally immutable, but the field-minimized authorization result still left the boundary as @dataclass(frozen=True, slots=True) ValidityStudyView.

frozen=True blocks ordinary assignment but does not prevent a caller retaining the returned view from rewriting tenant_record_id, validity_study_id, or fields through object.__setattr__. That creates a checked-versus-used gap after purpose/tenant/field authorization: a gateway, audit serializer, or role workspace can receive an object whose identity/authorized field evidence no longer matches what read_validity_study(...) actually authorized.

This is the output-side counterpart of #236/#237. It is not a reason to close or supersede #235.

Test-first repair

No force-push, destructive rebase, gate weakening, or predecessor-evidence transfer was used.

Current acceptance

Exact #235 head is 17092c94d180d082d1e389982e0beea9872f53f9 over protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Foundation 33957110271 / Repository quality 101282323502, Security Scan 33957110265, SAST Semgrep 33957110263, and CodeQL PR 33957110288 are current-head workflows and remain non-terminal at the latest read.

CodeRabbit independently reviewed exact 17092c94d... against protected develop@eb9757f... and reported no blocking issue in the requested #241 scope. It confirmed the tuple-backed ValidityStudyView, unchanged public property shape, the object.__setattr__ regression, preserved static read-port capability check/principal reconstruction/policy detachment/authorization ordering, no Keyverse/global-migration/SQL-adapter expansion, and no removed gate. This is static review evidence only; GitHub formal reviews remain empty and no qualifying approval is claimed.

Keep this issue open until the repaired #235 head reaches protected integration or a verified successor fully inherits the regression and invariant.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions