Skip to content

fix(account-clusters): verify CRUD and expose read-only permissions #128

Description

@chuanxu742-glitch

Account-cluster increment completed locally on codex/plugin-navigation-performance.

Starting HEAD: 32bcb3d96933e3e7b15689855432570f6d85f67b.
Integrated HEAD: 696e69a3720b6199f704e93eddf169b3907095d5. Not pushed; this issue remains open for repository publication/follow-up.

Delivered:

  • Verified cluster/member CRUD against the actual local backend and migrated disposable SQLite database.
  • Added server-derived workspace.can_manage_configuration and read-only controls for viewer/operator, with server write enforcement unchanged.
  • Fixed expanded-cluster deletion refetch and removed deleted member queries from cache.
  • Fixed draft loss during background refresh while retaining explicit permission revocation behavior.
  • Cleared authentication-bound query cache on identity/anonymous/development transitions; browser regressions prove same-document fresh-cache and pending-request isolation.
  • Expanded workspace-local slug coverage and documented prebuilt smoke-test prerequisites.

Evidence:

  • Targeted backend suite: 24 passed (--no-cov); expanded cross-workspace slug case independently passed afterward.
  • Disposable Alembic upgrade succeeded; single head l9m0n1o2p3q4.
  • Frontend production builds, typecheck and targeted lint passed; full ESLint had 0 errors and one preexisting unrelated hooks warning.
  • Independent OMP Sol corrective review: PASS, 7/7 browser contracts passed.
  • Final integrated real-browser cluster/member CRUD passed with no HTTP errors/page errors; actual viewer/operator reads and hidden write controls passed, direct writes returned403.
  • Real integration used local bootstrap auth and SQLite with backend lifespan disabled; external OIDC, PostgreSQL and full scheduler/browser-pool startup were not covered.

Execution and cleanup:

  • Orca1.4.197, OMP18.1.10; implementation OMP GPT-5.6-Luna High, independent review OMP GPT-5.6-Sol launched with High.
  • Bounded rework was required for initial registry design and a browser test that reloaded the document; coordinator corrected the test after ownership transfer.
  • Both E-drive temporary worktrees were integrated and removed through Orca; actual directories absent, test ports3137/3138/8137 closed, no worker processes remain. Original user terminals preserved.
  • External-terminal accounting retains historical entries despite confirmed terminal close; no corresponding live terminal remains.
  • Local evidence retained under E:/myide/orca-workspaces/account-cluster/verification-1149. Automatic approval rejected recursive retired-next-cache deletion with blocked by policy, so that cache remains outside the repository.

Credential association/lifecycle, workspace switching, real health checks and scheduling remain outside this increment; configuration status does not imply runtime health.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions