This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/agent-team/agent_team/confluence
Adam Moussa ed8e9a13ab fix(agent-team): close Confluence macro-loss + harden write authz (security-review)
Resolve the security-review BLOCKER and the confirmed authz/info findings on
the Confluence-writer node:

- BLOCKER (data-loss): _page_has_macros fail-OPENed (real ConfluenceClient has
  no page_has_macros/ADF methods) so every live write fell through to a
  wholesale storage-body PUT that drops Mermaid macros — the page-1540098
  diagram-loss class. Add count_storage_macros + a real ConfluenceClient
  .page_has_macros (storage-body detection); make _page_has_macros FAIL CLOSED;
  and add _assert_macros_preserved as the final backstop: refuse any storage
  write whose body carries fewer macros than the live page.
- AUTHZ-CONF-01: add an opt-in AGENT_TEAM_CONFLUENCE_ALLOWED_PAGE_IDS allowlist
  enforced server-side before a live update (model-derived page_id).
- AUTHZ-CONF-02: stop silently picking the first accessible Confluence site;
  require CONFLUENCE_CLOUD_ID when multiple resolve.
- INFO: 'applied' now fail-honest (defaults False, not True) on a missing attr.

+10 regression tests; full suite 1612 passed; ruff clean.
2026-06-25 11:18:01 -04:00
..
__init__.py feat(agent-team): Confluence-writer node (draft -> approve gate -> write) 2026-06-25 10:56:48 -04:00
client.py fix(agent-team): close Confluence macro-loss + harden write authz (security-review) 2026-06-25 11:18:01 -04:00
mermaid.py feat(agent-team): Confluence-writer node (draft -> approve gate -> write) 2026-06-25 10:56:48 -04:00