Commit Graph

34 Commits

Author SHA1 Message Date
ryan 3b24d248a7 docs(autoresearch): proposals for the five deferred architectural items 2026-08-29 19:32:35 +08:00
ryan 350bd422f5 chore(autoresearch): log iter 35 2026-08-29 19:31:41 +08:00
ryan db9d12f8c9 chore(autoresearch): log iter 34 2026-08-29 19:20:50 +08:00
ryan 578b4618ce chore(autoresearch): log iter 33 2026-08-29 19:15:27 +08:00
ryan 6e5ed979e4 chore(autoresearch): log iter 32 2026-08-29 19:05:17 +08:00
ryan 22a491ff37 chore(autoresearch): log iter 31 2026-08-29 18:57:29 +08:00
ryan 53fc3a81dc chore(autoresearch): log iter 30 2026-08-29 18:51:56 +08:00
ryan f29ac19673 chore(autoresearch): log iter 29 2026-08-29 18:46:21 +08:00
ryan 4412093d05 chore(autoresearch): log iter 28 discard 2026-08-29 18:42:44 +08:00
ryan 8b746e1d0e chore(autoresearch): log iter 27 2026-08-29 18:34:01 +08:00
Ryan 53ae3007d0 fix(cordis): fail-closed auth guards for user/message_gateway/admin (#1)
* autoresearch iter 23: fail-closed auth guarding for user/message_gateway

Both plugins resolve contracts.AuthService in Apply to build their route
middleware, but declared only DBService in Inject(). The kernel gates a
plugin's Apply solely on declared deps, and cmd/app.go registers user
before auth, so user mounted first, core.Inject failed, and loginMW
silently degraded to a pass-through closure — leaving /api/v1/user
change-password, profile and access-tokens unguarded. message_gateway
was saved only by its later list position.

Declare AuthService in Inject() for both, and pin the property with a
reconcile-level test that mirrors production registration order and
asserts the real auth middleware reaches the route table.

* autoresearch iter 24: make auth middleware fallbacks fail closed

user, message_gateway and admin each fell back to a c.Next() closure when
contracts.AuthService could not be resolved, so a route would be served as
if authenticated. For admin this is reachable at runtime: OnDispose calls
service.ResetServices(), which nils the global the per-request guard reads,
so requests still in flight during dispose bypass authorization entirely.

Add ginutil.AuthUnavailable() and bind every fallback to it, with a test
that drives each plugin's registered guard without an auth service present
and asserts the request is aborted rather than passed through.

* chore(autoresearch): log iter 23 (fail-open auth ordering, proven)

* autoresearch iter 24 follow-up: let staticcheck infer the auth guard type

* docs(autoresearch): log iters 24-25 and lessons 9-11 (declared-dep bug class, gate discipline)
2026-08-29 11:21:04 +08:00
ryan 6011effade chore(autoresearch): log iter 22 (debt 79 -> 54) 2026-08-29 09:55:24 +08:00
ryan b6f2221280 chore(autoresearch): log iter 21 2026-08-29 09:41:30 +08:00
ryan 9c0f31fad0 chore(autoresearch): log iter 20
Note: iter 20's commit also captured an in-flight edit to
docs/superpowers/plans/2026-08-29-cordis-config-extension.md belonging to a
concurrent session, because it used 'git add -A'. Content is intact; later
iterations stage explicit paths only.
2026-08-29 09:35:50 +08:00
ryan ae8bbd98f8 chore(autoresearch): log iter 19 2026-08-29 09:24:33 +08:00
ryan 020ebebfaa chore(autoresearch): log iter 18 2026-08-29 09:12:03 +08:00
ryan d80f9d209b chore(autoresearch): log iter 17 2026-08-29 09:03:54 +08:00
ryan 84946977bf chore(autoresearch): log iter 16 (perf, contract batch) 2026-08-29 08:52:18 +08:00
ryan 5df282f296 chore(autoresearch): log iter 15 (perf, proven) 2026-08-29 08:45:21 +08:00
ryan 2654eb6e2c chore(autoresearch): correct iter 14 log (debt held at 79, kept via proven-fix gate) 2026-08-29 08:39:53 +08:00
ryan 45bf1d8933 chore(autoresearch): log iter 14 2026-08-29 08:39:38 +08:00
ryan 00ab727791 chore(autoresearch): log iter 12 (debt 80 -> 79) 2026-08-29 08:35:26 +08:00
ryan 2c8020188d chore(autoresearch): log iter 11 (debt 84 -> 80) 2026-08-29 08:33:56 +08:00
ryan 643bfca996 chore(autoresearch): log iter 10 (debt 87 -> 84, errorlint 12 -> 0) 2026-08-29 08:30:33 +08:00
ryan f7fd980429 chore(autoresearch): log iter 9 (debt 89 -> 87) 2026-08-29 08:27:21 +08:00
ryan a529700ed3 chore(autoresearch): log iter 8 (proven bug fix, debt held at 89) 2026-08-29 08:24:09 +08:00
ryan 03f48a9a80 chore(autoresearch): log iter 7 (debt 92 -> 89) 2026-08-29 08:21:24 +08:00
ryan bf364f4036 chore(autoresearch): log iter 6, distinguish compile-level from assertion-level proof 2026-08-29 08:17:59 +08:00
ryan 58c34ad5c1 chore(autoresearch): log iter 5 (4 bare goroutines hardened, gate widened) 2026-08-29 08:13:17 +08:00
ryan 57b39f7fcf chore(autoresearch): log iter 4 (proven bug fix, debt held at 93) 2026-08-29 08:08:16 +08:00
ryan 5b84fd906d chore(autoresearch): log iter 3 (debt 95 -> 93) 2026-08-29 08:03:26 +08:00
ryan 4e6209bf61 chore(autoresearch): log iter 2 (debt 100 -> 95) 2026-08-29 07:59:39 +08:00
ryan edf0c0e934 chore(autoresearch): log iter 1 (debt 102 -> 100, proven fix) 2026-08-29 07:57:10 +08:00
ryan 5971e2a9ed chore(autoresearch): re-baseline harness on pinned real-risk yardstick
The committed golangci gate now reports 0 issues, so the previous
lint_issues metric was saturated and could no longer measure progress.
Measure debt against an immutable .auto/lint.ref.yaml snapshot that adds
analyzers for genuine defects (panics, error unwrapping, dead stores,
missing enum cases, method ordering, suppression hygiene) while excluding
cosmetic churn (tagliatelle, wrapcheck). Guard enforces build, vet, tests,
the Cordis architecture gate, and anti-cheat floors: the yardstick cannot
be edited, the project gate may only be strengthened, nolint directives may
only shrink, and no test may disappear.
2026-08-29 07:52:03 +08:00