Skip to content

fix(channel-edge): reject unbound attachments - #956

Merged
dotnetpower merged 5 commits into
mainfrom
fix/issue-303-attachment-startup
Sep 14, 2026
Merged

dotnetpower merged 5 commits into
mainfrom
fix/issue-303-attachment-startup

Conversation

@dotnetpower

Copy link
Copy Markdown
Owner

Summary

  • reject Slack and Teams attachment turns before queue admission while protected ingestion is unavailable
  • fail channel-edge startup before dependency allocation when FDAI_CHANNEL_ATTACHMENTS_ENABLED=1 has no production ingestor binding
  • stop direct attachment-bearing queue records before durable claim or semantic publication and align Operator filename safety with the shared safe-leaf contract
  • reconcile four English/Korean owners and mirrored ledgers with the post-decomposition implementation state

Safety posture

This is a fail-closed availability correction, not an attachment enablement or authority promotion. The capability remains unavailable by default, no vendor fetcher or document-service handoff is added, and no provider, approval, or executor identity is introduced.

Critique and validation

  • completed 12 bounded critique axes covering config strictness, pre-allocation failure, Slack and Teams authentication precedence, metadata safety, URL stripping, queue bypass, durable ownership, lifecycle readiness, error redaction, service isolation, documentation truth, and local/deployed parity
  • fixed two reproducible Medium defects: silent attachment loss and unsafe Operator attachment leaf names; no accepted finding above Low remains in this package
  • route-selected channel-edge and service-migration suite: 198 passed, 1 existing PostgreSQL integration skip because FDAI_ADMIN_DATABASE_URL was unset
  • Ruff format/check and strict mypy on six production modules: passed
  • decision-boundary coverage, independent-service boundaries, design routes/impact, roadmap tracking, document size, punctuation, readable Hangul, Korean quality, and translation parity: passed

Remaining #303 scope

Private Slack/Teams fetchers, a versioned handoff to agent-owned document ingestion, ordered citation return, EN/KO OCR fixtures and <=2% CER evidence, authenticated provider approval/rejection actors, and one-revision apply/health/acknowledgement/disable/rollback receipts remain open. No live provider or deployment evidence is claimed.

Refs #303

@dotnetpower
dotnetpower enabled auto-merge (squash) September 14, 2026 05:35
@dotnetpower
dotnetpower merged commit 6526fe5 into main Sep 14, 2026
23 checks passed
@dotnetpower
dotnetpower deleted the fix/issue-303-attachment-startup branch September 14, 2026 11:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant