Repository navigation
Orchestration Engine v0.183.333
Fixes create-only response fields being exposed again by POST lifecycle actions.
The shared dispatcher predicate now identifies creation only as POST without
an action. All three response-wrapper callers use that predicate; method-only
legacy constructors fail closed. Ordinary schema-readable fields are unchanged.
API Key first creation still delivers its generated secret; later reads,
updates, removal and POST actions cannot replay schema create-only values.
Exact CI source: 0d94f7d879d314235e582a7f4062914a27b82709.
PR77 was merged as 098df297375799c561cea8a356247a9e18667e53;
the built source and merged main have the same Git tree.
Security CI37104364692 and CodeQL37104364689 passed. Actual unit evidence has
273 suites / 1,164 tests, zero errors, failures or skips, including 14 new cases.
All 62 required named regressions and the 16 frozen role schemas were read back.
The exact official WAR completed isolated JDK25.0.3/H2 startup with exit 0,
no network, no ports and no platform data or Docker socket mounts.
Artifact/build-image Critical and High findings are zero. Four existing CodeQL
Medium findings remain; this is not a zero-risk claim.
WAR: 87,700,715 bytes, SHA256
8c42c0982cbc2f4569fa265ad320b341551758cb4fc0bc6d79ba06d70e20d328.
Six exact CI-derived assets include a portable SHA256 checksum.
Server packaging and native browser/API-key role validation remain pending.
This component release is not full resource/role matrix acceptance.
No persisted-data migration, proxy change or runtime patch is needed.
Use the new immutable Server image after its packaging and QA gates; preserve
existing deployment settings and prior image for rollback. Rolling back this
component restores the POST-action create-only response defect.