VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head c529022ddf
Evidence:
Exact PR/branch head verified: c529022ddf30e55d65caede5dfa9f81ede79665b.
PR CI green: ci/woodpecker/pr/ci pipeline 1710 success.
Reviewed TESS-M1-002 security boundary: provider IDs are explicit/non-replaceable; runtime scope is derived only from trusted server context and frozen before provider calls; blank actor/tenant/channel/correlation fails closed.
Capability checks gate provider side effects; audit writes occur before provider invocation and audit outage fails closed before side effects.
Termination requires an approval verifier consume an exact provider/session/actor/tenant/channel/correlation action before provider.terminate; default verifier denies all termination until durable approval is wired.
Audit records remain metadata-only and exclude message bodies, idempotency keys, and approval refs.
SEC-001 durable command approval flow is not modified by this PR; verified no command/chat command auth diff from base and current head retains command:approve, approvalId, and one-time actor/action-bound command authorization.
git diff --check clean; no secrets in the PR diff.
VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head c529022ddf30e55d65caede5dfa9f81ede79665b
Evidence:
- Exact PR/branch head verified: `c529022ddf30e55d65caede5dfa9f81ede79665b`.
- PR CI green: `ci/woodpecker/pr/ci` pipeline 1710 success.
- Reviewed TESS-M1-002 security boundary: provider IDs are explicit/non-replaceable; runtime scope is derived only from trusted server context and frozen before provider calls; blank actor/tenant/channel/correlation fails closed.
- Capability checks gate provider side effects; audit writes occur before provider invocation and audit outage fails closed before side effects.
- Termination requires an approval verifier consume an exact provider/session/actor/tenant/channel/correlation action before `provider.terminate`; default verifier denies all termination until durable approval is wired.
- Audit records remain metadata-only and exclude message bodies, idempotency keys, and approval refs.
- SEC-001 durable command approval flow is not modified by this PR; verified no command/chat command auth diff from base and current head retains `command:approve`, `approvalId`, and one-time actor/action-bound command authorization.
- `git diff --check` clean; no secrets in the PR diff.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Verification
Refs #707
VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head
c529022ddfEvidence:
c529022ddf30e55d65caede5dfa9f81ede79665b.ci/woodpecker/pr/cipipeline 1710 success.provider.terminate; default verifier denies all termination until durable approval is wired.command:approve,approvalId, and one-time actor/action-bound command authorization.git diff --checkclean; no secrets in the PR diff.