Repository navigation
docs(qa): approvals checklist — opening notifies approvers (approval.requested); the token-door item re-pointed after sys_approval_token left the data API (#22631, QA half) - #22656
Merged
objectstack-fleet[bot] merged 1 commit intoOct 10, 2026
Conversation
…requested); token-door item re-pointed after sys_approval_token left the data API approvals.notification-deep-link (revision 5): the knownGaps entry that said opening a request notifies nobody is removed, the source note names approval.requested in the emitting topic set, step 2 and the fixture note say the opening is a second notification source; the fixtures stay on remind/reassign and the revision-4 row stands as history. approvals.email-action-token-door (revision 2): sys_approval_token answers 404 OBJECT_API_DISABLED to every caller on every data-API verb, so the token-row oracles move to the act door's outcome pages, the request's action history and the two pinned integration tests; the mint clause is scored by test. The expiry leg's only recipe was backdating expires_at over the data API; nothing else drives expiry (ttlMs is not REST-reachable and the plugin threads no clock), so it is recorded in knownGaps as blocked(fixture) with the pinned 'expired' reason as its oracle. Co-authored-by: Claude <[email protected]> Claude-Session: https://claude.ai/code/session_01RdnZdPZH9ByduzPRWuH9tN
This was referenced Oct 10, 2026
objectstack-fleet
Bot
deleted the
claude/issue-22631-qa-checklist-approval-requested
branch
October 10, 2026 10:04
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #22631
Clause-②: no
The non-governed half of #22631:
docs/qa/platform-checklist/areas/approvals.jsononly. Two items move. The deep-link item stops saying that opening a request notifies nobody, becauseopenNodeRequestpublishesapproval.requestedto each concrete approver on the slate the request opens on since PR #22625 (e8c6666870). The token-door item is re-pointed after PR #22633 (86da194919, #22616) closedsys_approval_tokento the automatic API. The Tier H half (ADR-0043 and the automation skill) is PR #22652. #22631 remains open until both PRs land.Dispatched by the
domain:skillsseat PM, sessionsession_01RdnZdPZH9ByduzPRWuH9tN. Claim6095805515, triage6095381775, token-door note6095140961, remedy6095111901on #22616.docs/qa/**isdomain:devx's surface, carried here under the cross-domain exception path the triage named.Measured first
origin/main3d0eeefathe file read as the card quotes:notifies NOBODY1 hit (:341),has no approval.opened member1 hit (:394),approval.opened3 hits (:341,:394, and the revision-4 history row at:400); controlapproval.reminder3 hits.packages/plugins/plugin-approvals/src/approval-service.ts:'approval.requested'is published at:3349insideopenNodeRequest(:2999), onethis.notify()per concrete approver onopenedOn;issueActionTokenshas one caller,:4815insideremind().sys-approval-token.object.ts:115–:116declaresapiEnabled: falseandapiMethods: []. PR fix(plugin-approvals)!: sys_approval_token, the action-link tokens, is no longer exposed through the automatic API (#22616) #22633's changeset says every data-API verb answers404 OBJECT_API_DISABLEDto every caller, the administrator included, and that "there is no replacement read, by design: a link's state is what its confirm page answers, and a decision taken through a link is recorded in the request's action history". So the remedy in 6095111901 holds in full, and nothing in the token-door item needed less than it says.ACTION_TOKEN_TTL_MS = 72h(:815);ttlMsis an option ofissueActionTokensonly (:4857), whichremind()calls without it; the service clock isopts.clockon the constructor (:1223,:1376), andapprovals-plugin.tsconstructsApprovalServicewithout one (:207ff.); the plugin's source reads noOS_TEST_*and noprocess.env. Nothing drives expiry through a public door. Theexpiredreason is pinned byapproval-service.test.ts("redeem: dead tokens — invalid, expired, decided request, reassigned slot":issueActionTokens(…, { ttlMs: 1 })under the fake clock), andRESULT_COPY.expiredinaction-link-pages.tsis the page that reason renders.sys_notificationstill declaresapiMethods: ['get', 'list'](packages/platform-objects/src/audit/sys-notification.object.ts:187), so the raw links are still read from the persisted reminder payload.GET /api/v1/approvals/requests/:id/actions(packages/rest/src/rest-server.ts:12762;rest-route-ledger.ts:444), which the item already used.What changed (17 anchored edits; the JSON re-parsed; no key reordered)
approvals.notification-deep-link, revision 4 → 5knownGapsentry ("opening a request notifies NOBODY on this build — there is no approval.opened topic …") is removed. Six of the file's 18 items carry noknownGapskey, so the key goes rather than an empty array.sourcenote onapproval-service.ts#ApprovalServicenamesapproval.requestedon open (PR feat(plugin-approvals): opening an approval step tells each resolved approver (approval.requested) #22625) beside the nine sibling topics, every member inheriting the deep link.ref#22631).approvals.email-action-token-door, revision 1 → 2GET /api/v1/data/sys_approval_tokenread becomes the remind response'snotifiedcount and the new remind row on/:id/actions, with the instruction not to read the object through the data API and that its404 OBJECT_API_DISABLEDis the designed answer, not a finding./:idand/:id/actionsre-reads.expiredreason and theRESULT_COPY.expiredcopy, and record the leg asblocked(fixture).oracleapi→test, pointing atapproval-token-internal-hash.integration.test.tsandsys-approval-token-generic-door.integration.test.ts; the live half keeps thesys_notificationpayload read./:id/actions; the five-shape capture becomes four live shapes plus the pinned expired reason.knownGaps[1](expiry) is rewritten with the exact reason above;sourcegains the token object's closed declaration and the three test files; a revision-2 history row records all of it, including the two steps that had contradicted the door before PR fix(plugin-approvals)!: sys_approval_token, the action-link tokens, is no longer exposed through the automatic API (#22616) #22633 (the digest withheld since [security] The compliance ledger stores a JWT signing-key row's key material in its create snapshot, and an admin is served it through the ledger's by-id door while the key object itself declares no API door #21197;updatenever whitelisted).oracle/verify/evidenceshape, and everyoraclevalue is in the gate's set.Verification (all at
3f630d4dc)pnpm check:platform-checklistexit 1 (below);node scripts/check-doc-route-spelling.mjs --advisoryexit 0;pnpm check:corpus-claim-driftexit 0.check:platform-checklistis red onorigin/mainindependently of this diff. Its 7 problems are 5 inareas/access-security.json(ABSENT SYMBOL:protocol.ts#anonymousFormIntakeOrgScopeRefusal,#anonymousFormIntakeReopenRefusal,#envWideRawViewRows) and 2 inareas/attachments-storage.json(ABSENT SYMBOLattachment-access-hooks.ts#canEdit; SYMBOL ANCHORS LOST, 27 against a floor of 28). The same 7 problems come back verbatim on a tree whoseapprovals.jsonis byte-identical to3d0eeefa(the sibling worktree ataf35cd5be), and no problem namesapprovals.json. Origin:b389e4355(feat(metadata-protocol,runtime,service-automation,spec)!: the protocol refuses every organization-scoped write; an uninstall is environment-wide (ADR-0131 D6/D12) #22515) removed the twoprotocol.tssymbols, andce3d0ad41(fix(service-storage,plugin-audit,plugin-security)!: the attachment and comment parent gates judge a controlled_by_parent parent through its master #22513) reshapedcanEdit. Both files are outside this card's surface: reported to the seat, not touched here. Until they are repaired,Lint & Repo Gatesstays red on this PR for a reason this diff does not own.node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack(no paths; the change set is taken from the merge base) derived 13 commands. All 13 ran in the foreground, each exit captured before any pipe;--ranreconciliation: "13 derived, 13 run, 0 NOT-MEASURED, 0 UNRUN". 12 exit 0:check-ci-filter-parity,check-closing-keyword-parity(+ self-test),check-comment-mask-corpus,check:doc-formula-expressions(after its named prerequisite build through the verify lock, 4 of 4 tasks cached),check:cross-package-test-inputs,check:doc-authoring,check:driver-memory-census,check:gitlink-declared,check:nul-bytes,check:refd-timer-probe,check:watch-hint-literal. 1 exit 1:check:platform-checklist, above.pnpm lint(no lintable source touched) and package suites (no package touched).Changeset
Docs-only;
docs/qa/**ships in no package'sfiles[].skip-changesetis applied throughlabel-write.Acceptance notes
check:platform-checklistred onmain(above). Class (b): the checklist's symbol-anchor contract ("everypath#symbolcitation resolves; the per-file anchor count is shrink-never") is violated by two area files. Reach:pnpm check:platform-checklistonorigin/main3d0eeefaanswers exit 1 with 7 problems. Carrier: the seat. Dedupe words:access-security.json ABSENT SYMBOL anonymousFormIntakeOrgScopeRefusal,attachments-storage.json canEdit anchor floor 28.sourceentries added for the three test files are bare paths (no#symbolhalf), so the item's resolvable-anchor count does not shrink; its six existing anchors are kept.Generated by Claude Code