Skip to content

fix: harden IDEA authority, persistence and replay protection - #54

Merged
eybersjp merged 27 commits into
mainfrom
fix/idea-authority-hardening-v0.11.1
Oct 1, 2026
Merged

eybersjp merged 27 commits into
mainfrom
fix/idea-authority-hardening-v0.11.1

Conversation

@eybersjp

@eybersjp eybersjp commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Purpose

Complete Issue #51 by porting the still-required authority protections from historical PR #35 into the current post-v0.11.1 architecture without merging the obsolete branch.

Delivered

  • Explicit requirement provenance: USER_STATED / USER_CONFIRMED / AI_PROPOSED / RESEARCH_DERIVED / ASSUMED.
  • Fail-closed legal authority transitions: user-origin requirements are confirmed; AI/research/assumed candidates must be explicitly adopted.
  • Explicit PRODUCT_OWNER authority for requirement, question, scope, design and Idea Brief approval transitions.
  • Removed implicit Product Owner authority from suggestion promotion.
  • Journal-first discovery persistence with hash-chain validation and crash recovery.
  • Persisted one-question-at-a-time IDEA workflow.
  • Existing Numbered Decision Interface remains the numeric resolver.
  • Exact pending interaction fingerprint required for consumption.
  • Discovery/design source changes make a presented interaction stale.
  • Hash-chained, replay-proof interaction consumption receipts.
  • Product Owner-bound Design Authority applicability/disposition.
  • Canonical docs/01-concept/idea-brief.md source binding to artifact + discovery + design fingerprints.
  • Direct artifact edits invalidate authority.
  • CLI operations for state, next interaction, candidate/question recording, consumption, custom review, stale refresh and brief persistence.
  • Adversarial restart/replay/tamper/authority tests.
  • Package-consumer assertions and release-gate integration.
  • Command/agent/plugin-mirror documentation updated.

Acceptance target

  • IDEA-AUTH-001–016 behavior passes.
  • Existing numbered-decision tests pass after explicit-authority hardening.
  • Plugin mirror is synchronized.
  • Package dry-run includes the new runtime.
  • Full npm run release:validate passes on Ubuntu and Windows.
  • No current v0.11.1 reliability subsystem regresses.

Release discipline

No package version bump, tag or npm publication is included. Merge is implementation integration, not a claim that a new public release has been published.

Closes #51 after verification and merge.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e8ed987d6a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +457 to +464
const resolution = resolveDecisionInput({
input: selectedNumber,
activeMenu,
rootDir,
expectedStage: 'UNDERSTAND',
currentFingerprint: workflow.pendingInteraction.sourceFingerprint,
authority: 'Product Owner',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Resolve the menu only after the action commits

If the selected action fails after resolveDecisionInput—for example, the Idea Brief is edited after its approval prompt is presented—this call has already persisted the numbered menu as RESOLVED, while the workflow still retains the interaction as PENDING. A retry then fails with DK_DECISION_MENU_NOT_PENDING, and idea-refresh-stale cannot recover it because artifact edits do not change the discovery/design source fingerprint, leaving the workflow permanently stuck. Validate and commit the action before resolving the menu, or roll back/refresh the interaction when the action fails.

AGENTS.md reference: AGENTS.md:L18-L18

Useful? React with 👍 / 👎.

Comment on lines +167 to +169
const expected = discovery.requirements.filter((req) =>
['CONFIRMED', 'ADOPTED'].includes(req.resolutionState) && req.scopeDisposition === 'MUST'
);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Validate every approved scope section before persistence

The discovery-to-brief comparison only selects MUST requirements. Consequently, a confirmed or adopted requirement classified as SHOULD or FUTURE can be omitted or replaced with - None in its corresponding section, yet the Brief can still be persisted and approved as current. This silently drops Product Owner-approved scope from the canonical artifact consumed by downstream stages; validate those dispositions against Preferences (Should) and Future Ideas as well.

Useful? React with 👍 / 👎.

Comment on lines +605 to +609
const cleared = persistWorkflow(rootDir, workflow, {
status: 'ACTION_REQUIRED',
customInstruction: null,
pendingInteraction: null,
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Apply custom input before clearing its review checkpoint

In the documented CLI flow, completing a custom response merely deletes customInstruction without applying it to the unresolved question or requirement. ensurePendingIdeaInteraction therefore immediately recreates the same interaction, while the original custom answer has already been consumed and its menu resolved. Because no CLI operation updates or resolves that existing discovery item from customText, users selecting Custom are trapped in a loop and their Product Owner answer never affects authoritative state.

Useful? React with 👍 / 👎.

@eybersjp
eybersjp merged commit 40377ba into main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

IDEA authority hardening — port missing PR #35 protections to current architecture

1 participant