feat: add evidence-bound product semantic catalog - #692
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-head audit found and fixed an authorization gap at d8c3251: a visible post could previously return a product span whose evidence_post_id referred to a private post outside the reader scope. The post-detail query now applies the shared source eligibility predicate and account ABAC to every evidence post before returning the mention. A real PostgreSQL/OIDC regression inserts a hidden cross-entity evidence post and proves it is omitted. Product-focused integration/unit checks: 10 passed. The broader documentation pin failure on this stack is inherited from the parent divergence now being reconciled in #693, not suppressed here. |
…to codex/pr692-restack
…nto codex/pr692-restack
Outcome
Evidence
Stacked on #688; no canonical runtime mutation.