feat: add evidence-centered HR workspace slice - #53
seonghobae wants to merge 113 commits into
Conversation
📝 WalkthroughWalkthroughHR 워크스페이스 UI와 보호된 People·Job Analysis 조회를 추가했습니다. Storybook과 Playwright 검증을 구성하고, CI·저장소 계약·문서·매니페스트를 ChangesHR 워크스페이스 통합
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant Browser
participant HRWorkspaceApp
participant PeopleAPI
participant JobAnalysisAPI
Browser->>HRWorkspaceApp: 조회 폼 제출
HRWorkspaceApp->>PeopleAPI: 목적 코드와 인증 헤더로 People 조회
PeopleAPI-->>HRWorkspaceApp: fields 응답 또는 401/403 오류
HRWorkspaceApp->>JobAnalysisAPI: 목적 코드와 인증 헤더로 snapshot 조회
JobAnalysisAPI-->>HRWorkspaceApp: snapshot 응답 또는 오류
HRWorkspaceApp-->>Browser: 결과 또는 오류 상태 렌더링
Suggested reviewers: Merge Risk: 🟡 Moderate · up to The HR workspace can continue showing previously approved People fields after access is denied and may display an older response after a newer request, creating a bounded privacy and correctness risk; inconsistent service dependency versions may also break reproducible installation or integration. These issues should be fixed or explicitly accepted before merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 15.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 20 functions across 9 files. (23 skipped: 23 unsupported.)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Fresh protected-parent authority — 2026-09-21
Current protected truth is
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. This PR remains exact016f27e13f7a47cb78a1c936aa533cc8daa2c66c, open · Draft, but the previous statement that it was current-parent/mechanically mergeable is no longer true. Fresh ancestry comparison against protecteddevelopis 113 ahead / 3 behind, with merge base9e3e4847510e1e612b48474ba42b177b8ed824df; GitHub currently reportsmergeable=false.The three protected commits after that merge base are material owner truth, not incidental branch drift. They consolidated repository-owned quality into the canonical Foundation lane, retired multiple feature-local quality workflows, updated Foundation/recovery contracts and their executable inventories, and resealed deterministic provenance. This branch therefore must not be merged or descendant-adopted as if its old parent were still protected truth.
Repair order is dependency-first and non-destructive: read/adopt the intervening protected delta → ordinary-forward reconcile this existing #53 product/UI delta onto current protected
developwithout resurrecting retired quality ownership or overwriting current Foundation contracts → resolve any resulting provenance/manifest conflicts from final bytes → reacquire browser/accessibility/Foundation/Security/SAST/CodeQL/model-review evidence on the resulting exact head. No force-push, destructive rebase, temporary base churn, predecessor-evidence transfer, self-approval, routine administrator bypass or gate weakening is authorized.#130 and its presentation descendants, including existing Validation dashboard shell #145, remain downstream of this stale root. They must not be restacked merely to manufacture fresh checks before #53 is normally reconciled/integrated. Their valid product deltas remain open and must be preserved.
Scope
Adds the dependency-free HR Home / Employee Profile fixture, shared design-token consumption, local Storybook, purpose-bound evidence review interactions, bitemporal presentation, high-impact confirmation, accessibility assertions, and English/Korean labels. This remains fixture/component-state evidence only: it does not claim deployed customer UI, People API write integration, production psychometric compute, or ownership of a dedicated-writer dependency.
This branch also owns the page-level keyboard bypass interaction for the existing HR Workspace UI. Figma
Orgmetra Baselinenodes1:10(HR Home) and1:28(Employee Profile) remain the visual geometry baseline. The bypass control is intentionally focus-only until keyboard focus, so its visible state is captured in Storybook/browser evidence rather than by creating a conflicting Figma geometry change.Retained causal repair history
A separate writer advanced predecessor
d955faf5d1e7e10ea3dda3b9deaa74db940bf634to reseal the new HR Workspaceindex.htmlprovenance. That commit also changed the unrelateddatabase/migrations/0005_outbox_delivery_finalization.sqlmanifest digest to a value that did not match the file on disk.Foundation run
33042232951, job98418198435, proved exact checkout ofd955faf...and failed atValidate foundation packwith a deterministic provenance mismatch for migration 0005. The same job's--print-manifestoutput proved the authoritative artifact evidence remained SHA-256b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961, 6,125 bytes, 170 lines. PostgreSQL integrity jobs in that run were already GREEN, so changing migration source or weakening the validator would have been wrong.016f27e13f7a47cb78a1c936aa533cc8daa2c66crestored only that unrelated migration digest while preserving valid HR Workspace index provenance. No product behavior, database migration, validation rule, security gate or dependency contract was weakened. The earlier keyboard-bypass repair also remains intact: locale E2E binds to the stable skip-link DOM identity and verifies the active English/Korean accessible name instead of re-resolving a stale English role locator after locale change.Those exact-head results are historical evidence for this branch snapshot only. They do not prove compatibility with the three newer protected commits or authorize a synthetic merge tree.
Security / review evidence boundary
The 2026-08-27 Security Scan recorded on this head is not valid evidence for the current Dependency Review contract. Its dependency-review job received HTTP
403, emittedsupported=false, skipped the pinned Dependency Review action and still returned SUCCESS under predecessor fail-open behavior. That class is now centrally fail-closed; OSV/Trivy/Scorecard/SAST do not substitute for authoritative Dependency Review.Fresh submitted-review inventory remains COMMENTED-only; no qualifying
APPROVEDreview is transferred from history. Any old review finding must be revalidated against the reconciled tree rather than blindly copied or dismissed.Current merge governance and stack discipline
The live Draft state remains authoritative. Current organization governance and central workflow defects are separate from the repository-owned stale-parent repair; neither justifies bypassing the other. Before any Ready/merge transition, freshly resolve exact head/base, conflict state, current protected workflow source, review threads, required workflow verdicts and effective rules.
Process this root before #130 and before #145. #145 already owns a valid Validation dashboard presentation-state shell; it is not a replacement root and must not be source-copied into a new lane. The later Workforce Validation commercial convergence gap (#428) consumes protected UI truth and protected/released Workforce Validation API truth rather than bypassing this stack.
Do not self-approve, use routine administrator bypass, weaken/substitute a gate, race another lifecycle writer, force-push, destructively rebase, transfer predecessor evidence, or resurrect retired feature-local quality ownership.