Applies the document contract from
docs/plans/2026-08-20_stack-docs-flatten-and-alignment.md section 3, partially:
`kind` and `status` only. `parent` is deliberately held until the flatten in
section 4 lands, so that 127 documents do not have to be re-pointed by hand
when docs/fleet/NORTH_STAR.yaml moves to docs/NORTH_STAR.yaml.
Scope, measured on origin/next at 63069149:
127 live docs = all *.md under docs/ minus docs/archive/ minus docs/_old_structure/
104 stamped here
19 held operator judgement (plan section 9), worklist in the same PR
3 held the SUPERSEDED TASKS.md stamps, which cite the moving path
1 untouched docs/fleet/FLEET-DOCTRINE.md, already stamped in W1
Kinds applied: 54 guide, 34 record, 9 spec, 6 tracking, 1 projection.
Every row carries a confidence and a one-line rationale in the worklist.
Two collisions with the existing state, both flagged rather than resolved:
1. docs/README.md:150-160 already documents a front-matter convention
(title/type/audience/status/source_of_truth) with its own allowed values.
It is applied to 4 of 127 files. Its `status` vocabulary is
current|draft|deprecated|historical; the new contract's is active|superseded-by.
The key collides. This commit lets the new contract win and rewrites
`status: current` to `status: active` on those 4 files, keeping their other
legacy keys untouched. No code reads any of them: `git grep source_of_truth`
outside docs/ returns nothing. docs/README.md still prescribes the old
convention and is an operator row, so it is not edited here.
2. Two of the plan's 20 operator rows are YAML files, not markdown
(docs/fleet/examples/roster-v2.yaml, docs/openapi-tess.yaml), and the
contract's front-matter form has no defined meaning for a .yaml document.
That gap also applies to docs/fleet/NORTH_STAR.yaml, the source of truth
itself. Raised in the worklist.
A third row from the plan, docs/fleet/north-star.md, no longer exists: W1
renamed it to docs/fleet/FLEET-DOCTRINE.md.
Verification: 104/104 parse with the expected kind and status in front matter;
the check was shown to reject a wrong kind before it was trusted. The diff
removes 4 lines total, all of them `status: current`.
45 lines
3.3 KiB
Markdown
45 lines
3.3 KiB
Markdown
---
|
|
kind: record
|
|
status: active
|
|
---
|
|
|
|
# QA Report — Gateway Security Hardening
|
|
|
|
## Scope
|
|
|
|
- Chat HTTP auth guard hardening
|
|
- Chat WebSocket session validation
|
|
- DTO validation rules for chat and conversation payloads
|
|
- Ownership regression coverage for by-id routes
|
|
|
|
## TDD
|
|
|
|
- Required: yes
|
|
- Applied: yes
|
|
- Red step: targeted tests failed on socket session reshaping and DTO role/length mismatches
|
|
- Green step: targeted tests passed after runtime and DTO alignment
|
|
|
|
## Baseline Verification
|
|
|
|
| Command | Result | Evidence |
|
|
| ------------------------------------------------------------------------------------------------------------------------------ | ------ | --------------------------------------------- |
|
|
| `pnpm --filter @mosaicstack/gateway test -- src/chat/__tests__/chat-security.test.ts src/__tests__/resource-ownership.test.ts` | pass | 3 test files passed, 20 tests passed |
|
|
| `pnpm typecheck` | pass | turbo completed 18/18 package typecheck tasks |
|
|
| `pnpm lint` | pass | turbo completed 18/18 package lint tasks |
|
|
| `pnpm format:check` | pass | `All matched files use Prettier code style!` |
|
|
|
|
## Situational Verification
|
|
|
|
| Acceptance Criterion | Verification Method | Evidence |
|
|
| ------------------------------------------------------ | ---------------------------------------- | ------------------------------------------------------------------------------------------------ |
|
|
| Chat controller requires auth and current-user context | source assertion test | `chat-security.test.ts` checks `@UseGuards(AuthGuard)` and `@CurrentUser() user: { id: string }` |
|
|
| WebSocket handshake requires Better Auth session | unit tests for `validateSocketSession()` | null handshake returns `null`; valid handshake returns original session object |
|
|
| Conversation messages reject non-user/assistant roles | class-validator test | `system` role fails validation |
|
|
| Conversation messages enforce a 32k max length | class-validator test | `32_001` chars fail validation |
|
|
| Chat request payload enforces a 10k max length | class-validator test | `10_001` chars fail validation |
|
|
| By-id routes reject cross-user access | ownership regression tests | conversations, projects, missions, tasks each raise `ForbiddenException` for non-owner access |
|
|
|
|
## Residual Risk
|
|
|
|
- No live HTTP or WebSocket smoke test against a running gateway process was executed in this session.
|