Resolve the security-review BLOCKER and the confirmed authz/info findings on the Confluence-writer node: - BLOCKER (data-loss): _page_has_macros fail-OPENed (real ConfluenceClient has no page_has_macros/ADF methods) so every live write fell through to a wholesale storage-body PUT that drops Mermaid macros — the page-1540098 diagram-loss class. Add count_storage_macros + a real ConfluenceClient .page_has_macros (storage-body detection); make _page_has_macros FAIL CLOSED; and add _assert_macros_preserved as the final backstop: refuse any storage write whose body carries fewer macros than the live page. - AUTHZ-CONF-01: add an opt-in AGENT_TEAM_CONFLUENCE_ALLOWED_PAGE_IDS allowlist enforced server-side before a live update (model-derived page_id). - AUTHZ-CONF-02: stop silently picking the first accessible Confluence site; require CONFLUENCE_CLOUD_ID when multiple resolve. - INFO: 'applied' now fail-honest (defaults False, not True) on a missing attr. +10 regression tests; full suite 1612 passed; ruff clean. |
||
|---|---|---|
| .. | ||
| confluence | ||
| db | ||
| nodes | ||
| transport | ||
| __init__.py | ||
| api.py | ||
| billing.py | ||
| ci_fetcher.py | ||
| ci_gate.py | ||
| ci_watcher.py | ||
| coordinator.py | ||
| dashboard.py | ||
| deadline_timer.py | ||
| decisions.py | ||
| dispatcher.py | ||
| draft_pr_monitor.py | ||
| github_app.py | ||
| graph.py | ||
| invoker.py | ||
| invoker_multi.py | ||
| ledger.py | ||
| operator_cli.py | ||
| recovery.py | ||
| responder.py | ||
| resume_worker.py | ||
| state_store.py | ||
| status_page.py | ||
| task_model.py | ||
| topology.py | ||