fix(api): refuse out-of-scope objects with 404 on the two P2-2b deviations - #403
Open
jwvanderstam wants to merge 1 commit into
Open
jwvanderstam wants to merge 1 commit into
jwvanderstam wants to merge 1 commit into
Conversation
…tions
GET /api/conversations/{id}/documents and GET /api/chunks/{chunk_id}/annotations
answered 200 with an empty payload for an object outside the caller's scope, where
P0-1's acceptance asks for 404. Neither disclosed anything; this is a contract fix.
- get_conversation_document_filter returns None when no conversation is in scope,
making the route's existing 404 branch reachable; chat.py coalesces to [].
- The annotations route resolves the chunk through the scoped get_chunk_by_id first.
- _DISCLOSES_NOTHING is now empty; the refusal matrix covers 45 routes.
- Unit test for the annotations 404.
Also corrects status drift: P2-2 marked done in ROADMAP, the Sprint 16 row updated,
and the REMEDIATION_PLAN banner's P2 rows brought up to date.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What
P2-2b's over-the-wire matrix found two routes that answer 200 with an empty payload for an object outside the caller's scope, where P0-1's acceptance asks for 404. Neither disclosed data. Both scoped correctly, so this is a contract fix, not a leak being closed.
GET /api/conversations/{id}/documents:get_conversation_document_filternow returnsNonewhen no conversation is in scope. That makes the route's existingif filenames is None404 branch reachable (it was dead). The one internal caller,src/services/chat.py, coalesces to[], so retrieval stays unfiltered as before.GET /api/chunks/{chunk_id}/annotations: resolves the chunk through the already-scopedget_chunk_by_idfirst, and returns 404 when it isn't in scope._DISCLOSES_NOTHINGintest_object_authorization_over_the_wire.pyis now empty, and the refusal matrix covers 45 routes (was 43).test_list_chunk_annotations_is_404_for_a_chunk_outside_scope.Status drift corrected
Verification
ruff,mypy,bandit: clean locally.unit-tests,integration-tests) is the first run of both the new unit test and the matrix change.🤖 Generated with Claude Code