Skip to content

Audit every operator publish of a city reply (#138) - #117

Merged
theobong merged 1 commit into
mainfrom
fix/publish-audit
Sep 24, 2026
Merged

theobong merged 1 commit into
mainfrom
fix/publish-audit

Conversation

@theobong

Copy link
Copy Markdown
Member

Part of civfix/issue-tracker#138

What changed

Every time an operator publishes a city reply, the audit log gets exactly one entry naming that operator. This now includes a reply from a verified sender whose posting to the chat had not finished. The entry reads "Published a city reply" instead of "Published a withheld city reply". Admin.

Before you start

  • Where: staging (admin.civfix.dev) after the main push
  • Sign in as: operator
  • Size: 224 counted lines, 112 of them tests: the entry is written in the same step that finishes the reply, so the publish action, the background retry and the tests that pin one entry per publish change together

Verify

Staging cannot receive a city's email reply, so there is no reply to publish there, and no admin screen shows the audit log; "Not covered" says how it was checked.

Regression

Reading a mail thread — [Admin]

  1. Open "Mail", stay on "Outreach" and open a thread — Expect: it opens as before.

Replies waiting for review — [Admin]

  1. Click "Inbox", then "Needs review" — Expect: the list loads as before, or reads "Nothing to review" when nothing is held back.

Not covered

  • Publishing a city reply and its audit entry. Checked by the automated suites: publishing a held-back reply, or a verified reply still waiting to post, writes one entry naming the operator; two operators publishing at once, or a retry, still leave one entry; a reply finished by the background retry gets none.

@theobong
theobong merged commit b9390b1 into main Sep 24, 2026
3 checks passed
@theobong
theobong deleted the fix/publish-audit branch September 24, 2026 01:29
@greptile-apps

greptile-apps Bot commented Sep 24, 2026

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

Safe to merge.

What we checked:

  • A focused real-Postgres check validated atomicity, retry, operator-attribution, and concurrent publication, and it confirmed the prior change updated effects_applied_at without a coupled audit write. T-Rex
  • The executable API contract harness was run against both the prior and changed revisions; the changed revision preserved anonymous, non-operator, and CSRF rejection behavior while returning successful publication responses for authorized verified-pending and withheld replies, and it wrote one operator-attributed publication audit per published reply; the focused endpoint and service regression suite passed all 12 tests. T-Rex
  • Before capture showed the parent implementation updated effects_applied_at without transaction or audit coupling, and after capture the authored validation script passed all atomicity, retry, attribution, and concurrency assertions. T-Rex
  • The exact authored admin publish contract source was used for runtime captures, and the results indicate that actor propagation reaches the audit write without altering responses or authorization gates, with the audit input forwarded through the relevant routes. T-Rex

Reviews (1) · Last reviewed commit: "Audit the operator who publishes a verif..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant