Skip to content

fix(data-integrity): fail closed on invalid runtime editable state #252

Description

@seonghobae

Current authoritative state

This buyer-visible standalone edit-authority defect is repaired on canonical Draft PR #201 / branch fix/atomic-controlled-sync-200, the active single-writer lane for src/components/CwlEditor.tsx. Protected shipped truth and frozen v0.6.0 source candidate remain main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is f582e7cfd423cc2f55b2a2adc36a6201186b31ba.

Fresh live comparison is 19 commits ahead / 0 behind from protected main across exactly eight standalone-editor source/test paths. Prior snapshots naming 43d4f00c7cae657c54f8fd9c97d41a315bfbb350 or 343d4132574f4cb20eb561928df034154609bab7 as current are predecessor state and their evidence does not transfer. Do not create another writer for this path.

Protected-main behavior still lacks this active-PR repair. #201 production accepts only omitted/default or exact runtime booleans for editable before editor/accessibility/frame construction and rejects every other runtime value with stable payload-redacted RangeError diagnostics. Explicit true, explicit false, controlled/uncontrolled document semantics, transaction-policy atomicity, read-only keyboard/UI behavior, SSR/hydration, accessibility metadata, native-form behavior, and package consumers remain preserved. The same single-writer lane owns adjacent standalone runtime contracts for hideToolbar, value, defaultValue, and formResetValue without moving host transport/auth/persistence/tenancy/model authority into Inkspan.

The current source also drains an active local compositionend before revoking edit authority with editor.setEditable(false), and defers a controlled host value received during composition until composition ends, applying only the latest host value. src/components/CwlEditor.editabilityComposition.test.tsx and src/components/CwlEditor.controlledValueComposition.test.tsx machine-check those lifecycle boundaries. #380 remains the stacked browser-harness/test owner.

RED → GREEN lineage

  • RED a28bde93b230af732cb5759c64ffbc97b67bc3e8: hosted CI 31555746505 proves runtime editable="false" was accepted; Security 31555746518 and SAST 31555746504 succeeded on that RED head.
  • Predecessor 43d4f00c7cae657c54f8fd9c97d41a315bfbb350 carried the finite runtime repair after protected-main synchronization.
  • Current exact head f582e7cfd423cc2f55b2a2adc36a6201186b31ba preserves that repair and carries the same-owner composition transition/deferred-controlled-value corrections. Predecessor workflow/review evidence does not transfer.

Exact-current-head evidence

For unchanged exact head f582e7cfd423cc2f55b2a2adc36a6201186b31ba against protected main@3b38ead2d00f44eb578d0689087b9293b3dabe1e:

  • CI 32654492013: completed / success; exact-head checkout, 150 test files / 843 tests, 100% aggregate instrumented statement/branch/function/line coverage, package verification, and demo build passed;
  • Security Scan 32654492010: aggregate success but non-passing for merge/release acceptance because jobs consumed synthetic PR-merge source 4ffa57cd216d7b1ec7212fad297f86fa863d0909 and Dependency Review was skipped; existing foreign repair owner is .github PR #897;
  • SAST Semgrep 32654492044: aggregate success but non-passing for merge/release acceptance because the scan consumed synthetic PR-merge source 4ffa57cd216d7b1ec7212fad297f86fa863d0909; existing foreign exact-source repair owner is .github PR #941;
  • submitted formal review state: one predecessor-head Cursor COMMENTED review on 9fd9a281073da390409ed368fcc9311c8d501411, explicitly non-approving;
  • qualifying exact-head approving reviews: 0;
  • unresolved inline review threads: 0;
  • GitHub reports the Draft mergeable.

Repository CI success is not qualifying independent approval and cannot cure synthetic-source, skipped, absent, predecessor, status-only, or model-only evidence.

Integration boundary

The technical defect is repaired on #201 but remains unshipped while the Draft is unmerged. Keep #201 Draft/unmerged while #118 owns exact protected v0.6.0 tag/publication/provenance/digest operational acceptance and while qualifying independent latest-push approval plus every then-applicable exact-source governance/workflow gate remain incomplete. Any head/base/ruleset movement requires fresh exact evidence; do not self-approve, weaken gates, transfer predecessor evidence, move protected main, or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: accessibilityAccessibility and assistive-technology supportarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions