Skip to content

fix(api): refuse out-of-scope objects with 404 on the two P2-2b deviations - #403

Open
jwvanderstam wants to merge 1 commit into
mainfrom
fix/p2-2b-deviations-404
Open

jwvanderstam wants to merge 1 commit into
mainfrom
fix/p2-2b-deviations-404

Conversation

@jwvanderstam

Copy link
Copy Markdown
Owner

What

P2-2b's over-the-wire matrix found two routes that answer 200 with an empty payload for an object outside the caller's scope, where P0-1's acceptance asks for 404. Neither disclosed data. Both scoped correctly, so this is a contract fix, not a leak being closed.

  • GET /api/conversations/{id}/documents: get_conversation_document_filter now returns None when no conversation is in scope. That makes the route's existing if filenames is None 404 branch reachable (it was dead). The one internal caller, src/services/chat.py, coalesces to [], so retrieval stays unfiltered as before.
  • GET /api/chunks/{chunk_id}/annotations: resolves the chunk through the already-scoped get_chunk_by_id first, and returns 404 when it isn't in scope.
  • _DISCLOSES_NOTHING in test_object_authorization_over_the_wire.py is now empty, and the refusal matrix covers 45 routes (was 43).
  • New unit test: test_list_chunk_annotations_is_404_for_a_chunk_outside_scope.

Status drift corrected

Verification

  • ruff, mypy, bandit: clean locally.
  • The fast suite was not run locally. This machine has no Python 3.12 environment with the app's dependencies installed. CI (unit-tests, integration-tests) is the first run of both the new unit test and the matrix change.

🤖 Generated with Claude Code

…tions

GET /api/conversations/{id}/documents and GET /api/chunks/{chunk_id}/annotations
answered 200 with an empty payload for an object outside the caller's scope, where
P0-1's acceptance asks for 404. Neither disclosed anything; this is a contract fix.

- get_conversation_document_filter returns None when no conversation is in scope,
  making the route's existing 404 branch reachable; chat.py coalesces to [].
- The annotations route resolves the chunk through the scoped get_chunk_by_id first.
- _DISCLOSES_NOTHING is now empty; the refusal matrix covers 45 routes.
- Unit test for the annotations 404.

Also corrects status drift: P2-2 marked done in ROADMAP, the Sprint 16 row updated,
and the REMEDIATION_PLAN banner's P2 rows brought up to date.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant