Skip to content

fix: content pipeline hardening and access constraints - #1

Merged
daddia merged 11 commits into
mainfrom
fix/content-pipeline-hardening
Jul 31, 2026
Merged

fix: content pipeline hardening and access constraints#1
daddia merged 11 commits into
mainfrom
fix/content-pipeline-hardening

Conversation

@daddia

@daddia daddia commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Constrain anonymous content reads to published docs; require PAYLOAD_SECRET in production
  • Harden monitor/planner/studio/calibration paths (pagination, queue caps, positioningHash, severe-miss demotion)
  • Add generated Payload types, review-state updates, and docs alignment for R11/R12

Test plan

  • Confirm gates (content-qa) passes on this PR
  • Spot-check access regression tests and calibration/studio/planner tests locally if needed
  • Merge via GitHub once checks are green (do not push directly to main)

daddia added 11 commits July 31, 2026 22:40
Payload's draft query param does not hide drafts; open read ACL leaked staged content over REST.
runLevelsEngine no longer applies a second −2 while the miss remains in-window.
Lets content-monitor compare CMS docs against the current positioning hash.
Avoid silently truncating the weekly invariant check at 200 docs per collection.
A hand-edited queue.yaml without cap no longer disables the promotion gate.
Keep the local/dev fallback; fail closed if production boots without a secret.
support-triage is planned not registered; R11/R12 are enforced; tasks status matches the library.
@github-actions

Copy link
Copy Markdown

Content QA

Gate run failed before producing a report — see the workflow logs.

@daddia daddia self-assigned this Jul 31, 2026
@daddia
daddia merged commit 5bf1d1f into main Jul 31, 2026
2 of 4 checks passed
@daddia
daddia deleted the fix/content-pipeline-hardening branch July 31, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant