Skip to content

test(ooda): harden retention, security, and real QuestDB E2E #104

Description

@1012839419a-alt

Parent: #96

Status: ready-for-agent

What to build

Close the QuestDB/OODA release boundary with retention, early deletion, security hardening, observability, and full-system verification. Analysis Snapshot projections default to 30-day retention and may be deleted early by an authorized operator, while authoritative receipts, Findings, proposal evidence, and source facts remain intact.

Exercise the complete authenticated browser path against a production build and a disposable QuestDB 10.0.1 runtime: Observe a completed Run range, Orient with curated analysis, Decide by saving a Finding, and Act by reaching the existing proposal confirmation boundary. Validate both the optional-enabled and QuestDB-absent product states.

Acceptance criteria

  • Every Analysis Snapshot has a default 30-day retention deadline and an authorized early-delete operation.
  • Expiry or early deletion removes only disposable QuestDB rows and marks the authoritative receipt without deleting source facts, Findings, or proposal evidence.
  • Cleanup is idempotent, scoped to one snapshot, and reports bounded redacted outcomes.
  • Logs, receipts, QuestDB rows, API responses, and browser output contain none of the forbidden free-form fields or connection secrets.
  • Default application startup, production build, migrations, Workflow replay, acquisition execution, and existing Agent Control flows pass without QuestDB.
  • The optional profile passes health, export, aggregate, failure-isolation, deletion, and cleanup checks against QuestDB 10.0.1.
  • A real authenticated Playwright test proves Observe to Orient to Decide to Act up to proposal confirmation through the normal UI and public APIs.
  • Disabled, unavailable, unhealthy, expired, deleted, stale-revision, and authorization-denied states are covered by automated tests.
  • CI runs the cheap contract suite by default and provides an isolated integration lane for the disposable QuestDB test.
  • Operator documentation covers enablement, readiness, retention, deletion, troubleshooting, and the non-authoritative security boundary.

Blocked by

#100, #101, #102, #103

Verification evidence

  • Production build and full regression output.
  • Disposable QuestDB integration test output with teardown proof.
  • Real Playwright trace/screenshot/video for the OODA path.
  • Two-axis standards/spec review with all blocking findings resolved.
  • CI status for the delivery pull request.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions