Prevent implicit global remediation tasks when scope identity is missing - #711
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge decision: ready — a namespaced critique with no user or organisation identity can no longer silently create a globally visible remediation task.
User outcome
Retain the critique and report a recoverable routing failure when missing identity would otherwise produce an unscoped task. The investigation found a real remediation task created with null identity fields and empty publication scope edges, linked to a namespaced critique with null user/org components.
Material changes
Add a narrow check immediately before new task creation. Reuse the existing failure receipt with
remediation_task_scope_identity_missing; normal routing can retry when explicit identity is supplied. Namespace text is not converted into authority. This restriction addresses the demonstrated publication leak: read-back after global publication cannot reliably undo exposure, while retaining the critique preserves recovery.Native assignment:
#V#task_agent_9bea2c2283720d92f37b0ca4047f53f5. Target-specific evidence and controller correction instructions are retained in the worker result, outside the public repository.Evidence
pdm run pytest tests/backend/test_episode_critique_routing_service.py -q— 4 passed. The nearest faithful routing service path verifies missing identity causes no creation, the reason is persisted, explicit identity restores scoped task creation inputs, existing task/Jira reuse works, and memory-only outcomes remain available.git diff --checkpassed.Ship boundary