docs: refresh post-merge product gap baseline - #610
Conversation
|
Warning Review limit reachedNext included review available in 50 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| Protected main now calls the ADR 0109 OIDC return helpers before | ||
| `signinRedirect`; #600 and #605 delivered the repair through the protected | ||
| gate. The authenticated-only `accessToken` narrowing remains present. |
There was a problem hiding this comment.
🔍 Stale OIDC-defect prose contradicts refreshed delivery record
The refresh at product-technical-gap-baseline.md and the delivery table (product-technical-gap-baseline.md) now show #600/#605 merged and the OIDC repair delivered. The untouched sentence at product-technical-gap-baseline.md still says the defect remains until #605 passes the gate and main is not a release candidate. These lines sit outside the diff but now contradict the new state.
Was this helpful? React with 👍 or 👎 to provide feedback.
Outcome
Refreshes the non-identifying baseline after the protected merge wave. It records current protected-main SHA, all five open PR exact heads, confirmed merge SHAs for #608/#605/#600/#493/#468, the delivered OIDC repair, and the remaining buyer-facing isolation-copy follow-up.
Verification
uv run --extra dev pytest -q tests/test_documentation_hygiene.py— 5 passedgit diff --checkThis document distinguishes protected-main delivery, non-default stack history, branch-local verification, and runtime acceptance. It contains no private records or credentials.