Skip to content

fix(api): enforce create-only response fields on POST actions - #77

Merged
chen21019 merged 1 commit into
mainfrom
verification/orchestration-engine-0.183.333
Oct 3, 2026
Merged

chen21019 merged 1 commit into
mainfrom
verification/orchestration-engine-0.183.333

Conversation

@chen21019

Copy link
Copy Markdown

Fix the shared read-on-create-only response boundary: only POST creation (no action) can return these fields; POST lifecycle actions are redacted. All three wrapper callers share the actual dispatch distinction. Preserve true first-secret delivery, ordinary readable fields, null-redaction representation, v1/v2 role schemas and account authorization. Bump the numeric component to 0.183.333 and align README/compatibility/candidate note. Local focused checks: 19 tests, zero failures/errors/skips (14 new cases and five adjacent controls). Independent limited source review found no confirmed bypass/regression. Exact-source CI and immutable publication are pending. Existing failed QA receipts remain HOLD; native QA8080 lifecycle and full role matrix are not claimed complete. No database/proxy/authentication changes.

@chen21019
chen21019 requested a review from a team as a code owner October 3, 2026 06:42
@chen21019
chen21019 force-pushed the verification/orchestration-engine-0.183.333 branch from 9276f06 to 0d94f7d Compare October 3, 2026 06:50
@chen21019
chen21019 merged commit 098df29 into main Oct 3, 2026
7 checks passed
@chen21019
chen21019 deleted the verification/orchestration-engine-0.183.333 branch October 3, 2026 06:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant