Skip to content

Connect the real exercise workflow and source-backed scoring - #23

Merged
mekado11 merged 1 commit into
mainfrom
feat/v2-exercise-workflow
Sep 23, 2026
Merged

mekado11 merged 1 commit into
mainfrom
feat/v2-exercise-workflow

Conversation

@mekado11

Copy link
Copy Markdown
Owner

Scope

Connect the six-section HubCyS application to the existing server-authorized exercise engine. This is working application functionality, not a separate mock-data preview.

  • Create a ransomware exercise from authorized members and an organization context snapshot.
  • Schedule, start, pause/resume and end the response phase; release three clearly simulated injects.
  • Assigned employees record responses with server timestamps, evidence digests and idempotent receipts.
  • Assigned evaluators accept independent, source-backed observations.
  • Open the existing evidence drill-down to inspect the deterministic result and original response evidence.
  • Preserve existing routes, customer data, RBAC boundaries and feature gates.

Verification

  • V2 typecheck and scoped lint pass.
  • 68 domain tests and 34 security/client tests pass.
  • 20 emulator tests pass, including actual React application login and UI against real API handlers and Firebase emulators.
  • Full connected test: six separately authenticated employees, 18 recorded responses, three accepted observations, 29 audit events, deterministic current-evidence score 67.
  • Negative checks cover wrong-tenant evidence, modified source content, wrong phase/type, self-review, unauthorized grading, duplicate acceptance and retry replay.
  • Production build passes; existing large legacy-bundle warning remains.
  • Desktop facilitator/evidence and mobile participant screenshots inspected. CI uploads them as connected-exercise-workflow.

Visual review

Screenshots come from the actual application, not the standalone review fixture. The local test uses an isolated demo Firebase project and does not touch customer data.

Follow-up and production status

Leave this PR open and unmerged for review. Production was not changed by this work.

Live Firebase/Vercel activation and authoritative membership provisioning remain unverified. The connected Firebase administration tool failed before returning data; no production users were silently granted permissions and no customer records were migrated.

This PR does not finish findings/remediation/retest/reporting or persist historical score runs. Exercises remain in review after observations, and current-evidence scores are not organization-wide readiness. Participant statements do not prove technical execution on real systems.

Details: docs/v2/exercise-workflow.md.

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hubcys Ready Ready Preview Sep 23, 2026 11:02am UTC

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review


P2 Badge Hide exercise creation from unauthorized members

This button is rendered for every member who can open the exercises index, including participants, observers, auditors, facilitators, and evaluators, but authorization.ts grants exercise:create only to organization administrators and readiness leads. Those users are therefore sent into a creation flow whose setup request always returns 403; return a can_create_exercise capability from the index or conditionally render the action from the authoritative role/grant information.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mekado11
mekado11 added this pull request to stack #26 September 23, 2026 17:43
@mekado11
mekado11 merged commit 5301a81 into main Sep 23, 2026
5 checks passed

This branch was successfully deployed

1 active deployment
Preview — bd2b0687 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant