Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
7c477be
deps(deps): bump jackson-bom.version from 2.22.1 to 2.22.2
dependabot[bot] Aug 24, 2026
b0e3e80
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
228160c
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
4b5537f
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
07ea297
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
f688339
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
4093ba3
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
6c5f85b
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
8c54c5c
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
db26968
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Sep 30, 2026
cbbedaf
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
d7cef79
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
39dc197
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
6009953
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
3e9ba61
fix(security): patch Jackson denial-of-service CVEs
seonghobae Oct 1, 2026
bf121df
docs(gaps): bind Jackson repair to exact evidence
seonghobae Oct 1, 2026
7d0e62b
merge: consume canonical Jackson security owner #503
seonghobae Oct 1, 2026
5d27441
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
a0cfe28
fix(security): restore canonical Jackson owner delta after concurrent…
seonghobae Oct 1, 2026
19795e9
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
020ba5f
fix(security): preserve owner repair after second concurrent revert
seonghobae Oct 1, 2026
9805038
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
abd49b3
docs(rca): record repeated Jackson owner rollback on #661
seonghobae Oct 1, 2026
2238060
fix(security): restore owner tree after third concurrent rollback
seonghobae Oct 1, 2026
a486ce3
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
1ed453a
fix(security): restore owner evidence after fourth concurrent rollback
seonghobae Oct 1, 2026
586bfc9
🎨 Palette: 입력 폼의 필수 항목에 명시적인 (required) 텍스트 추가
seonghobae Oct 1, 2026
7858763
fix(security): transfer complete #661 delta to stable successor
seonghobae Oct 1, 2026
802b309
docs(rca): record complete #661 successor handoff
seonghobae Oct 1, 2026
0a51f00
docs(governance): mark #662 Ready for review admission
seonghobae Oct 1, 2026
b1905cf
test: carry forward exact required-label regression
seonghobae Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .jules/palette.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,6 @@
## 2026-07-13 - Async Table Actions UX
**Learning:** Adding explicit loading and disabled states to table action buttons that invoke asynchronous processes helps prevent redundant API calls and visually assures the user that their request is being handled.
**Action:** Consistently apply `disabled` state and `Loading...` text changes to inline table action buttons linked to async workflows, and carefully preserve underlying DOM structures with `Array.from(btn.childNodes)` during the loading cycle to avoid rendering regressions.
## 2026-09-30 - Add explicit text (required) to field label
**Learning:** Required form fields need explicit text `(required)` inside the label for accessibility, rather than using styled asterisks. When doing so inside a CSS grid container like `.field-label`, the text needs to be wrapped in a `<span>` to prevent `display: grid` from forcing elements onto separate tracks.
**Action:** Use explicit `(required)` text wrapped in `<span>` for required fields in CSS grids.
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@

### Security

- Jackson BOM을 `2.22.3`으로 올려 `jackson-databind`의 무제한 type-id 캐시 성장(CVE-2026-91776)과 이차 시간 forward-reference 해석(CVE-2026-91777)을 수정했습니다. 만료된 GHSA-5jmj-h7xm-6q6v OSV 예외를 제거하고 SBOM·제3자 고지문을 새 의존성 그래프와 함께 갱신했습니다.
- `GET /api/v1/convert/jobs/{jobId}/download`가 리소스 조회 전에 전용 `artifact:read` 권한을 검증하고, PDF 저장소 접근 전에 작업의 tenant 소유권을 확인하도록 강화했습니다. `job:read`만으로는 문서 바이트를 읽을 수 없으며, 인증 누락·권한 누락·교차 tenant UUID 접근은 각각 fail closed 처리되고 교차 tenant 요청은 리소스 존재를 숨기는 `404`를 반환합니다.
- Maven XML 테스트 보고서 검증기는 각 `testsuite`의 `tests`, `skipped`, `failures`, `errors` 속성을 모두 필수 증거로 요구합니다. 누락된 결과 수를 암묵적으로 0으로 간주하지 않고 fail closed 처리하며, 각 속성 누락 회귀 테스트를 추가했습니다.
- Maven XML 테스트 보고서 검증기는 UTF-8만 허용하고 UTF-8 BOM은 수용하며, NUL 바이트·DTD·엔터티 선언을 파싱 전에 거부합니다. UTF-16 같은 대체 인코딩으로 위험 선언을 바이트 검사에서 숨기는 우회와 외부 엔터티 읽기·엔터티 확장형 서비스 거부를 회귀 테스트로 차단했습니다.
Expand Down
10 changes: 5 additions & 5 deletions docs/legal/2026-07-03-third-party-attribution.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,11 +14,11 @@ CycloneDX SBOM. It is engineering evidence, not legal advice.
| Component | Version | License metadata | Package URL |
| --- | --- | --- | --- |
| com.fasterxml.jackson.core:jackson-annotations | 2.22 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.22?type=jar` |
| com.fasterxml.jackson.core:jackson-core | 2.22.1 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1?type=jar` |
| com.fasterxml.jackson.core:jackson-databind | 2.22.1 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1?type=jar` |
| com.fasterxml.jackson.datatype:jackson-datatype-jdk8 | 2.22.1 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.22.1?type=jar` |
| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | 2.22.1 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.22.1?type=jar` |
| com.fasterxml.jackson.module:jackson-module-parameter-names | 2.22.1 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.22.1?type=jar` |
| com.fasterxml.jackson.core:jackson-core | 2.22.3 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.3?type=jar` |
| com.fasterxml.jackson.core:jackson-databind | 2.22.3 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.3?type=jar` |
| com.fasterxml.jackson.datatype:jackson-datatype-jdk8 | 2.22.3 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.22.3?type=jar` |
| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | 2.22.3 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.22.3?type=jar` |
| com.fasterxml.jackson.module:jackson-module-parameter-names | 2.22.3 | Apache-2.0 | `pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.22.3?type=jar` |
| com.fasterxml:classmate | 1.7.3 | Apache-2.0 | `pkg:maven/com.fasterxml/classmate@1.7.3?type=jar` |
| commons-logging:commons-logging | 1.4.0 | Apache-2.0 | `pkg:maven/commons-logging/commons-logging@1.4.0?type=jar` |
| io.micrometer:micrometer-commons | 1.15.12 | Apache-2.0 | `pkg:maven/io.micrometer/micrometer-commons@1.15.12?type=jar` |
Expand Down
88 changes: 88 additions & 0 deletions docs/product-technical-gap-baseline.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
# Clearfolio Product and Technical Gap Baseline

## Goal and loop

Clearfolio is the ContextualWisdomLab document-viewer bounded context. Its buyer
quality loop is review → root-cause repair → exact-head validation → ordinary
merge. A queued, skipped, stale-head, or fail-closed Check is not passing.

## Current product and technical boundary

- **Product responsibility:** submit documents asynchronously, expose conversion
status, render same-origin PDF artifacts, and enforce tenant-scoped access.
- **Runtime boundary:** Spring WebFlux controllers delegate validation,
conversion, state, artifact, authorization, and audit work to their owning
services and repositories; no cross-service database access is authorized.
- **Supply-chain boundary:** Maven dependency policy, CycloneDX SBOM, license
policy, third-party attribution, Trivy, OSV, Semgrep, and CodeQL provide
fail-closed release evidence.

## PRD and TRD acceptance baseline

| Evidence | Acceptance rule | Status |
| --- | --- | --- |
| Product behavior | `mvn -B --no-transfer-progress verify`; zero test failures, errors, or skips; production line and branch coverage 100% | Required on exact repair head |
| Public contract | Java 21 compilation and public Javadocs complete with warning and deprecation budget 0 | Required on exact repair head |
| Supply chain | Trivy/OSV/SAST report no actionable finding; committed SBOM and attribution match the resolved dependency graph | #503 Security `36824043955` and SAST `36824043968` GREEN |
| Review admission | Independent approval and all required terminal Checks bind to the current head | Not yet satisfied |

## Gap and action ledger

| Gap | Exact evidence and RCA | Action | Status |
| --- | --- | --- | --- |
| Jackson denial-of-service exposure | clearfolio#660 head `2a6b0b621e075da224210c0ca78db344af5dea52`, Security run `36778995059`, Trivy job `110104143035`: CVE-2026-91776 and CVE-2026-91777 in `jackson-databind` 2.22.2 | Repair canonical dependency owner #503 with Jackson 2.22.3, a downgrade regression test, refreshed SBOM/attribution, and removal of the expired OSV exception | Resolved at source commit `3e9ba61e1aa2a903e920cf832f9daa5467f2e166`; CI `36824043863`, Security `36824043955`, SAST `36824043968`, and fuzz `36824043977` GREEN |
| Historical evidence drift | #503 review found its original one-file 2.22.2 bump left SBOM, attribution, POM rationale, and expired ignore stale | Keep dependency version and buyer evidence in one PR; run attribution/license drift checks | Resolved; both review threads closed and local evidence contracts GREEN |
| #661 consumer security integration | #661 predecessor `600995328dc03d53a63e7b67d3b8c9501f3baa17`, Security `36798597036`, Trivy `110167652487`, reported CVE-2026-68497, CVE-2026-91776, CVE-2026-91777, CVE-2026-19032, and CVE-2026-83557 in Jackson 2.22.1 | Ordinary-integrate the complete #503 owner set while preserving the required-field accessibility controller and test | Integrated in tree `83d7f78f405f317b6c9beabf5a3aed1cff889485`; Security `36829111902`, CI `36829111991`, SAST `36829111823`, and fuzz `36829111945` GREEN on predecessor integration head |
| Repeated concurrent owner rollback on #661 | Commits `5d27441771689395358109d735e16d2ea9bbe30e` and `19795e9f645a6a731ad3db869ec441d58f7d9786` each reverted the same eight owner paths to Jackson 2.22.1, restored the expired OSV exception, deleted this baseline, and removed downgrade contracts. Security runs `36829505965` and `36829843477` failed; Trivy job `110262678487` reproduced all five findings. | Preserve both commits in ordinary history; restore the exact #503 blob set in follow-ups `a0cfe28fb971963d6fa03075f50b86a3ea54bd69` and `020ba5fd789dd45c7b985657e994e09ab04148ab`; move the unstable PR to Draft and require a fresh exact-head validation cycle | Owner tree restored; #661 remains Draft and merge HOLD. Cancelled fuzz/CodeQL runs are not passing evidence. |
| Merge admission | #503 is Ready after product/security/fuzz validation; its Draft CodeQL run `36824043888` was skipped. #661 is Draft after repeated concurrent rollback. | Obtain non-cancelled exact-head fuzz and CodeQL verdicts plus independent approval after the branch is stable, then ordinarily integrate | Hold |

## Decision traceability

The selected repair is the upstream Jackson 2.22.3 patch line, released
2026-09-21 with fixes for both CVEs. Ignoring the findings, weakening Trivy, or
retaining the expired OSV exception was rejected because each would preserve a
buyer-visible denial-of-service risk or conceal stale evidence. A new duplicate
dependency PR was rejected because #503 already owns the Jackson version delta.
Concurrent commits are preserved in ordinary history; only their proven
security-owner rollback is counteracted, and the PR remains Draft until its
single-writer and exact-head evidence are stable.

## References

FasterXML. (2026, September 21). *Jackson release 2.22.3*.
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.22.3


## Successor handoff — 2026-10-01

The original #661 writer repeated the identical eight-path Jackson downgrade five
times at `5d27441771689395358109d735e16d2ea9bbe30e`,
`19795e9f645a6a731ad3db869ec441d58f7d9786`,
`980503850cff4f4a5e0d6bbf7e11b51e609f528f`,
`a486ce3e001f312f8b60d70ecbdc572c5336d11c`, and
`586bfc9a4a3436653e0488cae55fa4b34b22e525`. Direct repair on that
branch could not remain authoritative. Ready successor #662 at
`78587632e979de03895d9a9e49ad86bd0a3f85db` carries every valid accessibility
and canonical-owner delta, preserves all five concurrent commits in ordinary
history, and restores tree `41b7c5a757c449769bfacfa67ccfc27f05e37bb9`.
The predecessor remains open Draft as evidence. Successor #662 is Ready only
for review admission; merge remains HOLD until exact-current-head Checks are
terminal and an independent approval exists.


## #663 carryover — 2026-10-02

Draft #663 exact `2b49634cfabc00d888ef2e14a23a865f5d4c5f85` independently
reproduced the Jackson 2.22.1 scanner failure and repaired its POM to 2.22.3, but
that partial repair duplicated canonical owner #503 and omitted its regenerated
SBOM, attribution, expired-exception removal, and cross-artifact drift contract.
Those owner paths remain authoritative in successor #662.

The #663 production UI blob
`d55dfd56f8a9709b999b0c722d5dc75d4f13d479` is byte-identical to #662.
Its stricter response regression, which asserts the complete label and span
structure, is carried forward here. The standalone string-search dependency test
is superseded by `DependencyPolicyTest`, which parses the POM and binds Jackson
2.22.3 to the SBOM and attribution evidence. #663 remains open until this
successor head receives exact-head verification; retirement is permitted only
after that complete carryover is verified.
Loading
Loading