Repository navigation
fix: harden IDEA authority, persistence and replay protection - #54
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e8ed987d6a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const resolution = resolveDecisionInput({ | ||
| input: selectedNumber, | ||
| activeMenu, | ||
| rootDir, | ||
| expectedStage: 'UNDERSTAND', | ||
| currentFingerprint: workflow.pendingInteraction.sourceFingerprint, | ||
| authority: 'Product Owner', | ||
| }); |
There was a problem hiding this comment.
Resolve the menu only after the action commits
If the selected action fails after resolveDecisionInput—for example, the Idea Brief is edited after its approval prompt is presented—this call has already persisted the numbered menu as RESOLVED, while the workflow still retains the interaction as PENDING. A retry then fails with DK_DECISION_MENU_NOT_PENDING, and idea-refresh-stale cannot recover it because artifact edits do not change the discovery/design source fingerprint, leaving the workflow permanently stuck. Validate and commit the action before resolving the menu, or roll back/refresh the interaction when the action fails.
AGENTS.md reference: AGENTS.md:L18-L18
Useful? React with 👍 / 👎.
| const expected = discovery.requirements.filter((req) => | ||
| ['CONFIRMED', 'ADOPTED'].includes(req.resolutionState) && req.scopeDisposition === 'MUST' | ||
| ); |
There was a problem hiding this comment.
Validate every approved scope section before persistence
The discovery-to-brief comparison only selects MUST requirements. Consequently, a confirmed or adopted requirement classified as SHOULD or FUTURE can be omitted or replaced with - None in its corresponding section, yet the Brief can still be persisted and approved as current. This silently drops Product Owner-approved scope from the canonical artifact consumed by downstream stages; validate those dispositions against Preferences (Should) and Future Ideas as well.
Useful? React with 👍 / 👎.
| const cleared = persistWorkflow(rootDir, workflow, { | ||
| status: 'ACTION_REQUIRED', | ||
| customInstruction: null, | ||
| pendingInteraction: null, | ||
| }); |
There was a problem hiding this comment.
Apply custom input before clearing its review checkpoint
In the documented CLI flow, completing a custom response merely deletes customInstruction without applying it to the unresolved question or requirement. ensurePendingIdeaInteraction therefore immediately recreates the same interaction, while the original custom answer has already been consumed and its menu resolved. Because no CLI operation updates or resolves that existing discovery item from customText, users selecting Custom are trapped in a loop and their Product Owner answer never affects authoritative state.
Useful? React with 👍 / 👎.
Purpose
Complete Issue #51 by porting the still-required authority protections from historical PR #35 into the current post-v0.11.1 architecture without merging the obsolete branch.
Delivered
docs/01-concept/idea-brief.mdsource binding to artifact + discovery + design fingerprints.Acceptance target
npm run release:validatepasses on Ubuntu and Windows.Release discipline
No package version bump, tag or npm publication is included. Merge is implementation integration, not a claim that a new public release has been published.
Closes #51 after verification and merge.