Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .changeset/20596-service-settings-provenance-anchors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
'@objectstack/service-settings': patch
---

Provenance comments in `service-settings` were re-anchored

Comment and docblock lines under `src/` that cited tracker numbers which no
longer resolve on GitHub now cite the commit in this repository's history that
decided the matter, and say in their own words what was decided. Comments
only: no type, schema, export, log or refusal text, or runtime behaviour changes.
Original file line number Diff line number Diff line change
Expand Up @@ -274,7 +274,7 @@ describe('aiSettingsManifest — embedder section', () => {
});

/**
* #11318 — the live-call hint an operator reads under "Test connection" in
* The card behind commit 99ccbb9c8: the live-call hint an operator reads under "Test connection" in
* Settings -> AI must carry the edition boundary the platform's own capability
* roster already records. `PLATFORM_CAPABILITY_PROVIDERS.ai` declares
* `edition: 'cloud'` ("no installable version in the open edition"), while the
Expand Down Expand Up @@ -336,7 +336,7 @@ describe('aiTestActionHandler — live-call hint carries the cloud boundary (#11
// `@objectstack/embedder-openai`, which IS built in this repo (8 path hits
// under `git ls-tree -r --name-only HEAD | grep -cF /embedder-openai/`, against
// 0 for `/service-ai/`), so that instruction is followable as written and stays
// a plain mount line. Asserted here, deliberately not edited — #11318 fences
// a plain mount line. Asserted here, deliberately not edited — commit 99ccbb9c8 fences
// this site out by name.
it('leaves the embedder hint a plain mount line — its package IS built here', async () => {
const r = await runTestEmbedder({ embedder_provider: 'openai', embedder_api_key: 'sk-test' });
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -614,7 +614,7 @@ describe('#15351 — decision 1 option A: a BROKEN tenancy service is an outage,
// and not endorsed: the settings route layer had no
// `isAuthzStoreUnavailableError` arm, so the branded 503 the seam raises
// was flattened into `500 INTERNAL_ERROR` by the same untyped `else` branch
// #13279's permission-store re-raise already reached. All four route
// commit 6a180e42d's permission-store re-raise already reached. All four route
// catches now RELAY the declared envelope instead.
//
// What THIS card owns is unchanged and still asserted: the outage is not a
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@
* specifier's declared `default`, with `source: 'default'` and `locked: false`,
* and no diagnostic of any kind, while the operator's saved row is never read.
*
* The write half (#10159 / PR #10251) could REFUSE, because an in-window write
* The write half (commit 1ec36b730, PR #10251) could REFUSE, because an in-window write
* has no correct outcome. A read does: a setting with genuinely no persisted row
* must answer the manifest default, and doing so at boot is ordinary. So the
* fix here is not a refusal — it is that the residual stops being silent.
Expand Down Expand Up @@ -299,7 +299,7 @@ describe('a settings read inside the pre-bind window warns', () => {
expect(reader.engineBoundAtReady).toBe(false);
// THE DEFECT, still observable: the read answered with the manifest default
// (`log`) while `sys_setting` held `twilio`. The fix does NOT change this —
// that is deliberate (#10159's fix left reads open on purpose) — so this
// that is deliberate (commit 1ec36b730 left reads open on purpose) — so this
// assertion is the reason the warning has to exist at all.
expect(reader.readAtReady).toBe('resolved:"log"');

Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.

/**
* Settings route-ledger conformance (#17062) — the guard every OTHER
* Settings route-ledger conformance (the issue behind commit 50b6f17d4) — the guard every OTHER
* `*-route-ledger.ts` in the tree pairs with a `*-route-ledger.conformance.test.ts`,
* missing here since the ledger itself landed at #7526.
*
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@
* asking which rows nobody claims (PENDING-GAPS §E; the gate is
* `packages/qa/dogfood/test/route-ledger-live-mount-parity.dogfood.test.ts`).
*
* WHAT GUARDS IT. Two layers, since #17062. The dogfood parity gate above
* WHAT GUARDS IT. Two layers, since commit 50b6f17d4. The dogfood parity gate above
* checks both directions too — a row here whose route the plugin stops
* mounting fails it, and any live mount without a row in the union of the
* ledgers it reads fails it — but only as part of a full boot, in a
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
*
* `SettingsServicePlugin`'s `verifiedContextFromRequest` re-raises
* `AuthzStoreUnavailableError` rather than returning an enforced-but-empty
* context the routes would read as a denial (#13279). But it is called as
* context the routes would read as a denial (commit 6a180e42d). But it is called as
* `await ctxOf(req)` from INSIDE each route's own `try`, so the brand was
* caught here and re-encoded: `message` survived, `code` and `status` did not —
* and those are the two a client branches on.
Expand Down
2 changes: 1 addition & 1 deletion packages/services/service-settings/src/settings-routes.ts
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ const defaultContext = (_req: IHttpRequest): SettingsContext => ({ enforced: tru
*
* `SettingsServicePlugin`'s `verifiedContextFromRequest` already re-raises the
* brand rather than returning an enforced-but-empty context the routes would
* read as a denial (#13279). But it is called as `await ctxOf(req)` from INSIDE
* read as a denial (commit 6a180e42d). But it is called as `await ctxOf(req)` from INSIDE
* each route's own `try`, so until now the brand was caught here and re-encoded
* — `message` survived, `code` and `status` did not, and those are the two a
* client branches on. The declared `503` / `SERVICE_UNAVAILABLE` never reached
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -304,7 +304,7 @@ export class SettingsServicePlugin implements Plugin {
enforced: true,
};
} catch (err) {
// [#13279] An unreachable permission store is an outage, not a
// [commit 6a180e42d] An unreachable permission store is an outage, not a
// caller with no permissions — re-raise it rather than returning an
// enforced-but-empty context the routes read as a denial.
if (isAuthzStoreUnavailableError(err)) throw err;
Expand Down
2 changes: 1 addition & 1 deletion packages/services/service-settings/src/settings-service.ts
Original file line number Diff line number Diff line change
Expand Up @@ -682,7 +682,7 @@ export class SettingsService {
* of a setting that genuinely has no persisted row must answer the manifest
* `default`, and that is an ordinary, common thing for a boot-time reader to
* do. Refusing it would turn a correct startup sequence into an error — which
* is why #10159's fix deliberately left reads open.
* is why commit 1ec36b730's write refusal deliberately left reads open.
*
* What is wrong is not the answer, it is that the answer was produced WITHOUT
* CONSULTING the store. In the window {@link loadRows} takes its `this.memory`
Expand Down
Loading