Skip to content

feat(zotero): add authenticated Zotero 10 transport - #17

Draft
seonghobae wants to merge 23 commits into
autoresearch/zotero-multilingual-abstentionfrom
autoresearch/zotero10-authenticated-transport
Draft

feat(zotero): add authenticated Zotero 10 transport#17
seonghobae wants to merge 23 commits into
autoresearch/zotero-multilingual-abstentionfrom
autoresearch/zotero10-authenticated-transport

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Current source-scope and uncertain-write integration — 2026-09-06

Exact head 06d836a07fdb434683f88a31b45150a8a06f27f7 normally retains prior transport c88f9a34c1fc4e72e38cf66b1d2f3fcb305e560a and parent 84b27fb6b2563e0d4661905aa57702a0dde082ba. Original transport implementation is preserved while inheriting complete report/scope admission, required receipt binding and unknown-request semantics.

Independent review requested executor+HTTP coverage: 97cce5a, strengthened by 29a3771, composes synthetic authenticated transport with a failed POST followed by fully matching observed metadata. Exactly one POST, complete submitted request and observation, retained proposal digest, continued uncertainty and no applied/inverse operations are asserted. No real Zotero port/key or live mutation is used. Existing proxy and wire-contract tests are preserved.

Local validation:123tests/19suites including3doctests; strictClippy,rustdoc,fmt,CI-contract,diff and unchangedcoverage gate.226/226functions,2022/2022normalizedregions,354/354normalizedbranches. RawLLVM2508/2560lines,3799/3880regions,314/354branches is not100%. Static review is not independent GitHub approval.

OPEN Draft behind existing stack. No hostedGREEN,protectedmerge,release,peer-authentication,live write/recovery or actual paper decisions claimed. PR18 then PR19 must inherit all scope/unknown-request fields without converting audit JSON to authority. Previous body below is historical; post-read completion/rollback inference is superseded.

Latest bounded-read integration checkpoint

Exact head c88f9a34c1fc4e72e38cf66b1d2f3fcb305e560a normally merges parent 044018cef4e5d3e919b278a1cfebe56857863601 while retaining previous child cf93f5323d97e718c8ff986c8e780bfaa26fb765. Base remains autoresearch/zotero-multilingual-abstention. The #9 whole-snapshot elapsed-time repair and its RED/GREEN evidence are inherited without reverse-merging later features or discarding predecessor deltas.

This exact head passes Rust 1.98.0 locked workspace tests=100 suites=19, including doctests and excluding filtered subprocess duplicates, strict all-target Clippy, warnings-denied rustdoc, formatting, the existing CI contract and diff checks. Log: /private/tmp/conceptweave-deadline-pr17-20260906.log. Intermediate coverage is not inferred from owner/final-endpoint coverage. No new dependency, actual paper read/decision, Zotero mutation or authority issuer was used.

Draft and protected prerequisites remain. Local tests are not hosted GREEN, independent approval, merged/released source or evidence for another head. Earlier checkpoints below are retained history, not the current head.

Verified local approval-order repair — 2026-09-06 checkpoint

Exact head: autoresearch/zotero10-authenticated-transport@cf93f5323d97e718c8ff986c8e780bfaa26fb765. Exact base: autoresearch/zotero-multilingual-abstention@873c46b7dcf2930a98cf7ef7ff8bdcbcf04f17d5.

Original planner owner #13 preserves regression 505e111c993d8269e5b7b9e17a25a5ce20f8606e and repair 8a684882005085d8b3cb47812e185975084e0475. Every existing local request/mode/item/metadata check finishes before the external approval verifier. Invalid requests invoke it zero times; valid complete requests invoke it exactly once. Local validation errors intentionally precede approval denial. Deterministic operations and complete before/after/rollback metadata are unchanged.

This exact head passed locked Rust 1.98.0 workspace tests (97 tests / 19 unfiltered suites, doctests included), strict all-target Clippy, formatting, warnings-denied rustdoc, CI contract and diff checks before normal push. Normal parent integration retains both the prior child and verified parent as ancestors. Coverage from another stack head is not attributed to this head.

Keep Draft behind the existing prerequisite stack. This is local verification, not hosted current-head GREEN, independent approval, protected merge or release. No later full-text feature was reverse-merged into an earlier owner. Full-text-aware write admission, authentic decisions and independent authority remain separate gaps; no real Zotero/model request, label, approval or write was performed for this repair.

Earlier coordinates and status claims below are historical.

Prior PR description, retained without discarding evidence

Current source-integrity note — 2026-09-05

  • Exact head: autoresearch/zotero10-authenticated-transport@d1e88ad309848cba9cb8028d2b5f04bcab067837.
  • Exact base: autoresearch/zotero-multilingual-abstention@61ff1e2653dc2adf9c770f3f474a6019d0e7640e.
  • This head inherits PR feat(research): add steward golden-set evaluation #10 root e7d4e59f1b55b5954c5f8436527bc96e7ef2fb13 through ordinary merge ancestry. The source-snapshot digest binds complete captured raw provider JSON and the actual typed classifier inputs; source evidence and derived proposals retain separate identities.
  • GoldenSetApproval.proposal_digest is required and binds the complete proposal records used for evaluation. The current proposal digest is checked before the caller-owned governance verifier. Do not backfill old receipts: regenerate evidence and obtain a new approval bound to the reviewed evidence.
  • Keep Draft. This note does not claim current exact-head hosted GREEN, independent approval, protected merge, live Zotero mutation, or governed publication. Root, predecessor, and terminal-stack local test evidence is not transferred as per-PR hosted evidence.

Earlier heads, runtime snapshots, campaign counts, and verification statements below are historical notes, not current acceptance evidence.

Historical PR notes — original text retained

Outcome

Add the ConceptWeave-owned Zotero 10+ Local API transport required by Issue #8 without claiming a live write. The adapter keeps the user-granted key private, pins the server partition, rejects redirects, bounds reads, and uses one-item POST so library and item versions are checked atomically. Stable reads distinguish library-wide and object versions; write responses must prove the exact key, advanced versions, collections and typed tags, while lost responses remain subject to the existing reconciliation receipt path.

Current exact stack — 2026-09-05

  • base: multilingual abstention test(zotero): verify multilingual abstention safety #16 autoresearch/zotero-multilingual-abstention@d02d0f98ed5a2799a5735a6499b4f3eb66220611;
  • exact head: 47e86b5e4dc51b32d9f756db35cc7ca18ea8f2c2;
  • Draft/open/mergeable; current non-force ancestry preserves transport semantics while adopting current test(zotero): verify multilingual abstention safety #16/Foundation lineage;
  • predecessor RED/repair, workspace, coverage and review evidence remains lineage evidence and is not current protected exact-head GREEN without fresh terminal workflows.

Remaining boundary

The locally observed installation is Zotero 9.0.6. Approved live Zotero 10 write, partial-failure and rollback evidence remains incomplete; this PR contains no key and performs no live mutation during tests. #18 adds the explicit authorization/threat-model boundary and remains the dependent security gate.

Keep Draft behind #16 and the full predecessor stack. No descendant evidence may back-prove this exact transport head.

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@seonghobae

Copy link
Copy Markdown
Contributor Author

@codex review

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Non-force restack PR #17 onto PR #16 current head. Preserve the authenticated transport delta while carrying PR #15's current receipt/execution RED contracts through the prerequisite chain; no production repair or predecessor GREEN is claimed.
seonghobae added a commit that referenced this pull request Sep 4, 2026
Non-force restack PR #18 onto PR #17 current head. Preserve authorization, threat-model, SECURITY, TRD and bibliography repairs while carrying PR #15's current receipt/execution RED contracts through ancestry; no predecessor GREEN is claimed.
# Conflicts:
#	docs/TRD.md
#	docs/adr/0007-reviewed-zotero-write-plan.md
#	docs/product-technical-gap-baseline.md
Non-force two-parent restack onto current multilingual/write-execution parent. Preserve the Zotero 10 transport delta while inheriting the repaired Foundation CI contract and current receipt lineage.

Signed-off-by: Seongho Bae <me@seonghobae.me>

Copy link
Copy Markdown
Contributor Author

Current-stack correction (2026-09-05): exact base #16 a4ae22cb1779aeaef8832a32da33e859f2b107bc; exact head 6dc17bea8b16e49d62b1ab75f76a8525061c7946. Transport semantics and the existing provider-risk boundary are preserved; older body SHAs are historical.

# Conflicts:
#	crates/conceptweave-zotero/src/lib.rs
…ty safety

Preserve original transport and parent fixes. Resolve documentation by retaining transport contracts and replacing obsolete causal inference descriptions, without changing authentication or write authority.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant