Skip to content

HubCyS V2 Phase 1: validated readiness domain foundation - #19

Merged
mekado11 merged 1 commit into
mainfrom
feat/v2-domain-foundation
Sep 23, 2026
Merged

mekado11 merged 1 commit into
mainfrom
feat/v2-domain-foundation

Conversation

@mekado11

Copy link
Copy Markdown
Owner

Scope

Add the first isolated HubCyS V2 domain foundation following repository inspection. This is not a cosmetic redesign, a destructive rewrite, a live security remediation, or the complete V2 product.

  • Strict, separate V2 entity and command contracts with tenant ownership and explicit references.
  • Deterministic exercise/capability scoring with published expected-action/criterion manifests, retained scoring inputs, input digest, coverage, and truthful unknown/insufficient-evidence states.
  • Central authorization policy primitive covering membership, exercise assignments, action ownership, independent verification, and scoped provider/customer grants.
  • Exercise/remediation state invariant guards and persistent-gap detection across comparable exercises.
  • Isolated strict TypeScript test configuration and scoped CI workflow.

Preserved behavior

No changes to application screens, navigation, legacy records, Firestore/Storage rules, API handlers, current authentication/bootstrap, commercial entitlements, dependencies, or production deployment. No data migration runs with this PR. Base44 implementations remain retained.

Verification

  • npm run typecheck:v2: PASS.
  • npm run test:v2: PASS, 68 tests.
  • npm run build: PASS, existing frontend output unchanged.
  • git diff --check: PASS.
  • Existing root npm run lint: still fails with the same 23 baseline unused-import errors.
  • Existing root npm run typecheck: still fails with the same 2,991 baseline diagnostics.

Tests include tenant/reference mismatches, forged authority fields, invalid roles, provider grant expiry/revocation/scope, participant enrollment, unknown/advisory/legacy evidence exclusion, missing criterion manifest detection, score replay, completion versus verification, independent verifier checks, and persistent-gap comparability.

Integration and security limitations

These pure domain modules are not wired into existing endpoints or persistence. authorizeCommand is not token verification; its principal, memberships, grants, and assignments must come from authenticated server-side resolution, never browser payloads.

The remediation transition guard does not itself execute or validate an entire retest. A subsequent verification command must validate accepted outcomes, baseline/retest obligation mapping, context comparability, parent relationships and all finding obligations before recording verification.

Subsequent review units must implement actual server identity verification, authoritative memberships, Firestore/Storage policy with emulator coverage, transactional commands/audit/outbox, persistence, UI workflows, migration tooling and production-shaped end-to-end acceptance. No production-readiness or tenant-isolation-completion claim is made here.

Visual review

Not applicable: no UI or route changes. No new preview is required to review this domain-only unit.

Review gate

Leave open and unmerged for owner review. Production remains unchanged; merging/deploying and any data migration are separate actions.

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hubcys Ready Ready Preview Sep 23, 2026 8:37am UTC

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 877273c585

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread server/v2/scoring.ts
Comment on lines +124 to +126
for (const capability of scenario.capability_ids) {
if (!criteria.some(criterion => criterion.capability_id === capability && criterion.required)) {
throw new Error('CAPABILITY_HAS_NO_REQUIRED_CRITERIA');

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require criteria for every expected action

When a published scenario lists an expected action but no criterion references that action, all current validation passes because the manifest check validates only record IDs and this loop checks only capability-level coverage. calculateExerciseScore then ignores the unassessed action and can report scored with 100% coverage, overstating readiness. Require every expected action to have a criterion, or explicitly model actions that are intentionally non-scoring.

Useful? React with 👍 / 👎.

Comment thread shared/v2/contracts.ts
Comment on lines +228 to +229
completed_at: Instant,
}).strict().superRefine((record, ctx) => {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject verification completed before its creation

For malformed or imported records where completed_at precedes the inherited created_at, this schema accepts an impossible verification chronology, and transitionRemediation only rejects completion times later than the current request. Such a passing record can therefore verify or close an action despite predating its own creation; add a temporal refinement analogous to the one on Observation.

Useful? React with 👍 / 👎.

@mekado11
mekado11 added this pull request to stack #21 September 23, 2026 09:57
@mekado11
mekado11 merged commit 80f0183 into main Sep 23, 2026
5 checks passed

This branch was successfully deployed

1 active deployment
Preview — 877273c5 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant