Repository navigation
Connect the real exercise workflow and source-backed scoring - #23
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
💡 Codex Review
hubcys/src/v2/ReadinessApp.jsx
Line 511 in bd2b068
This button is rendered for every member who can open the exercises index, including participants, observers, auditors, facilitators, and evaluators, but authorization.ts grants exercise:create only to organization administrators and readiness leads. Those users are therefore sent into a creation flow whose setup request always returns 403; return a can_create_exercise capability from the index or conditionally render the action from the authoritative role/grant information.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Scope
Connect the six-section HubCyS application to the existing server-authorized exercise engine. This is working application functionality, not a separate mock-data preview.
Verification
connected-exercise-workflow.Visual review
Screenshots come from the actual application, not the standalone review fixture. The local test uses an isolated demo Firebase project and does not touch customer data.
Follow-up and production status
Leave this PR open and unmerged for review. Production was not changed by this work.
Live Firebase/Vercel activation and authoritative membership provisioning remain unverified. The connected Firebase administration tool failed before returning data; no production users were silently granted permissions and no customer records were migrated.
This PR does not finish findings/remediation/retest/reporting or persist historical score runs. Exercises remain in review after observations, and current-evidence scores are not organization-wide readiness. Participant statements do not prove technical execution on real systems.
Details:
docs/v2/exercise-workflow.md.