Add account-derived LineageWeave RP profile - #100
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughADR-0009 기반 ChangesLineageWeave OIDC 프로필
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: ⚪ Minimal · up to The PR adds the account-derived LineageWeave relying-party profile and supporting validation and documentation changes; no actionable merge-blocking risk remains beyond normal checks and review. Sequence Diagram(s)sequenceDiagram
participant Client as lineageweave-web
participant Keyverse
participant App as Downstream application
Client->>Keyverse: PKCE S256 authorization request
Keyverse->>Client: audience, role, org, workspace claims 포함 토큰 발급
Client->>App: 토큰 전달
App->>App: issuer, signature, expiry, audience 검증
App->>App: org/workspace ABAC 후 client-role RBAC 적용
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
6d29501 to
694f406
Compare
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current headcf4dbb9d708a8807dcbdebdbd415aaa545fc956b. -
Head SHA:
cf4dbb9d708a8807dcbdebdbd415aaa545fc956b -
Workflow run: 31749531869
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (20 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (20 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (18 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (18 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (8 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (8 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage evidence job did not run or did not publish coverage evidence. Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (21 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (21 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (18 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (18 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (8 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (8 files)"]
R4 --> V4["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current headcf4dbb9d708a8807dcbdebdbd415aaa545fc956b. -
Head SHA:
cf4dbb9d708a8807dcbdebdbd415aaa545fc956b -
Workflow run: 31752898033
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (20 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (20 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (18 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (18 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (8 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (8 files)"]
R4 --> V4["targeted test run"]
Superseded by later exact-head success evidence on cf4dbb9. All inline findings are resolved, and this request-changes review contained no current code defect; it reflected only an earlier coverage-evidence run failure.
|
@cwl-noema-review |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head43e76072992d1490ebf8d84a62701d83fb096952. -
Head SHA:
43e76072992d1490ebf8d84a62701d83fb096952 -
Workflow run: 31798992590
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (21 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (21 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (18 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (18 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (8 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (8 files)"]
R4 --> V4["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head43e76072992d1490ebf8d84a62701d83fb096952. -
Head SHA:
43e76072992d1490ebf8d84a62701d83fb096952 -
Workflow run: 31798992590
-
Workflow attempt: 2
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (21 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (21 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (18 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (18 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (8 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (8 files)"]
R4 --> V4["targeted test run"]
|
@opencode-agent @cwl-noema-review Please perform a fresh independent review anchored to exact current head |
|
@opencode-agent @cwl-noema-review Please perform a fresh independent review anchored to exact current head |
|
@opencode-agent @cwl-noema-review Please perform a fresh independent review anchored to exact current head |
|
@opencode-agent @cwl-noema-review Please perform a fresh independent review anchored to exact current head |
|
@opencode-agent @cwl-noema-review Please perform a fresh independent review anchored to exact current head |
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
|
Current-head documentation/gap-baseline review request: please re-review commit |
|
Correction: the exact full current head is |
|
Exact-head evidence refresh pushed at Updated |
|
Exact-head baseline refresh pushed at The product/technical baseline and doctoring record now point to PR #103's final documentation-synchronized head |
|
@opencode-agent Please submit a fresh independent review bound only to exact current head |
|
Exact-head documentation update: the gap baseline and doctoring evidence now reflect the live 14-PR inventory, #111's normal branch update, and current Checks. Review only current HEAD |
|
Exact-head update: the live gap snapshot correction is now at current HEAD |
|
Exact-head update: the live gap baseline now records the normal #110/#106/#105/#104 branch updates and #109 lockfile merge verification. Current HEAD is |
Summary
lineageweave-webKeycloak relying-party profile with account-derived role, organization, and workspace claimsWhy
LineageWeave must authenticate real Keyverse accounts; company and PU are account attributes, not login identities. This keeps the issuer-side contract bounded while leaving tenant/resource ABAC and downstream token validation mandatory.
Validation
uv run ruff check app tests toolsuv run interrogate .uv run python -m compileall -q app tests toolsuv run coverage run --branch --source=app -m pytest -quv run coverage report --show-missing --fail-under=100(100%)uv build --out-dir distmake validate-realmRuntime evidence still required
The local workspace has no actual Keyverse deployment configuration or real-account access path. Before production routing, perform private Keyverse apply, confidential credential placement, and controlled real-account login/tenant/role lifecycle acceptance as listed in ADR-0009.
Summary by CodeRabbit
새 기능
문서
버그 수정
테스트