test(observability-map): add an unguarded sensitive canary route - #4484
test(observability-map): add an unguarded sensitive canary route#44841stvamp wants to merge 1 commit into
Conversation
|
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Observability mapAs of 19/100 over 413 measured of 428 entry points (base 19, no change) What this PR changed
FIX FIRST
AUDIT 3 of 50 sensitive mutations record an actor. 47 without one. What the score is made ofReport only, nothing here gates the merge. The rules and their reasons: internal-packages/observability-map/README.md. |
a681f21 to
1cd8d80
Compare
Throwaway PR to verify the observability-map CI comment reports a regression. Not for merge.
1882f9f to
2263035
Compare
1cd8d80 to
d3ce17d
Compare
|
Test complete. All four states of the delta rule confirmed on the real runner, plus the stale-comment gap this exposed (fixed in 042c9c3) and its reconcile path. Closing; branch deleted. |
Throwaway. Case 2 of 3 in an end-to-end check of the observability-map CI
comment: adding a sensitive route with no auth guard should be reported as a
regression and should reach the top of FIX FIRST.
Locally verified: new entry, sensitive, score 0, fails auth-boundary,
request-context and audit-trail. Global stays 19, because one route in 412
cannot move the rounded mean; the signal is the row, not the headline.
Do not merge. Will be closed once the CI behaviour is observed.
This is part 3 of 4 in a stack made with GitButler: