JVNAUTOSCI-2632: implement governed ontology administration - #371
Merged
Merged
Conversation
|
|
||
| # EXECUTION | ||
| def _raw_relation_by_id(relation_id: Any) -> dict[str, Any] | None: | ||
| raw_id = relation_id |
|
|
||
|
|
||
| def json_dumps_sorted(value: Any) -> str: | ||
| import json |
| "context": _json_safe(relation.get("context") or {}), | ||
| } | ||
| ) | ||
| text_relations.sort(key=lambda item: json_dumps_sorted(item)) |
| monkeypatch.setattr( | ||
| authority, | ||
| "resolve_live_semantic_roles", | ||
| lambda actor: (global_role,) if actor == semantic_admin else (), |
Comment on lines
+88
to
+90
| lambda actor: ( | ||
| (global_role, organisation_role) if actor == "#V#semantic_admin" else () | ||
| ), |
Comment on lines
+121
to
+131
| lambda actor: ( | ||
| ( | ||
| _evidence( | ||
| admin, | ||
| authority.ORGANISATION_ONTOLOGY_ADMINISTRATOR_ROLE, | ||
| "#V#org_a", | ||
| ), | ||
| ) | ||
| if actor == admin | ||
| else () | ||
| ), |
Comment on lines
+183
to
+192
| lambda actor: ( | ||
| ( | ||
| _evidence( | ||
| global_admin, | ||
| authority.GLOBAL_ONTOLOGY_ADMINISTRATOR_ROLE, | ||
| ), | ||
| ) | ||
| if actor == global_admin | ||
| else () | ||
| ), |
Comment on lines
+285
to
+295
| lambda actor: ( | ||
| ( | ||
| _evidence( | ||
| actor, | ||
| authority.ORGANISATION_ONTOLOGY_ADMINISTRATOR_ROLE, | ||
| "#V#org_a", | ||
| ), | ||
| ) | ||
| if actor in admins | ||
| else () | ||
| ), |
Comment on lines
+377
to
+387
| lambda actor: ( | ||
| ( | ||
| _evidence( | ||
| admin, | ||
| authority.ORGANISATION_ONTOLOGY_ADMINISTRATOR_ROLE, | ||
| "#V#org_a", | ||
| ), | ||
| ) | ||
| if actor == admin | ||
| else () | ||
| ), |
Comment on lines
+427
to
+431
| lambda actor: ( | ||
| (_evidence(admin, authority.GLOBAL_ONTOLOGY_ADMINISTRATOR_ROLE),) | ||
| if actor == admin | ||
| else () | ||
| ), |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements the organisation/global ontology-administrator capability tracked by JVNAUTOSCI-2632.
Why
Legitimate canonical corrections were blocked when concepts carried historical or different publication scopes, while several alternate mutation entry points could bypass the conversational guard. Historical visibility was being used as a proxy for semantic authority, and Von operational control was not represented separately.
This change makes destination publication context, represented role, and exact delegation determine authority. Visibility alone no longer grants publication rights, and operational administration does not imply semantic ontology authority.
User and developer impact
Authenticated organisation administrators can govern their organisation's ontology; global administrators can maintain the shared ontology without acquiring private organisation visibility; agents can act only under an exact server-issued delegation.
Ordinary actor-owned creation and scoped assertions remain available. Generic role, visibility, membership, merge, scope, and reserved-predicate mutations are denied or routed through dedicated lifecycle commands.
No live role migration, ontology change, deployment, or activation is performed by this PR.
Validation
F,E9clean and byte-compilation cleangit diff --checkcleanOne broader scholarly-upload replay reaches an existing downstream durable-workflow lock failure also present on
main; the upload authority path itself passes its focused suite.Release boundary
This is ready for review. Release still requires target-environment migration dry-run, guarded application, exact represented-role read-back, and replay of the motivating canonical outcomes.