Skip to content

feat(delegation): resolve company authority from eVault history and bind grants to record id and time - #1194

Merged
coodos merged 3 commits into
mainfrom
feat/delegation-history-authority
Oct 8, 2026
Merged

coodos merged 3 commits into
mainfrom
feat/delegation-history-authority

Conversation

@coodos

@coodos coodos commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

PR 3 of 5 for company signing delegation (replaces #1193). The eVault stays a plain store; verifiers decide authority from signatures and the eVault's version history (metaEnvelopeHistory).

  • Grant payload binds recordId and signedAt: a grant copied onto another record fails, and an older signed state can be told apart from a newer one. Writers pick the record id before signing (the eVault already allows creating under a chosen id). Still w3ds-grant/v1; nothing has shipped with it.
  • resolveBoard: directors over time from the Company record's history (the vault's manifest). First board signed by one of its own directors; later changes only by a sitting director. Unsigned, forged or outsider versions are skipped.
  • historyChainSource: each Role/Delegation resolves to its latest version that is validly signed for its id, not older than the previous valid one, keeps its immutable fields, and was signed by someone entitled when stored:
    • role, role assignment: a director;
    • re-delegation: the parent's delegate;
    • revoke: a director or the grantor.
      Revocation is final. Grants outlive a director's later removal. Vandalism or deletion doesn't change the result.
  • evaluateFromHistory: board, then the existing evaluateDelegation; checkDelegatedSignature is reused unchanged.
  • Cascade is implicit: a revoked or narrowed parent fails every child's chain at verify time; no writes needed.

Next: PR 4 wires this into packages/auth (verifyDelegatedSignature reading the company eVault over GraphQL) plus sign-request helpers.

Issue Number

Type of change

  • New (a change which implements a new feature)

How the change has been tested

53 vitest cases (16 new in history.spec.ts, in-memory history + fake verifier): board bootstrap and director-signed change; outsider and unsigned boards ignored; first board not signed by a member refused; delegation and narrowing re-delegation accepted end to end with checkDelegatedSignature; non-director grant and wrong re-delegator ignored; copied grant fails on id; older state written back ignored; forged revoke ignored, valid revoke final even after a later signed re-activation; delegate can't revoke; grants survive the grantor leaving the board, later ones don't; revoked role fails children; vandalism and deletion survived; immutable field change ignored; re-delegation cycle terminates; no board → nothing. Grant payload tests cover id and signedAt binding. tsc clean.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

@coodos

coodos commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 582d5392-d3b0-48e0-a219-64b1c7821342
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T10:47:55.447215Z 56ffd18 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0139a5d7dd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/delegation/src/history.ts Outdated
Comment thread packages/delegation/src/history.ts Outdated
Comment thread packages/delegation/src/history.ts
Comment thread packages/delegation/src/history.ts Outdated
…re revocation, scope cycle detection to the lookup path
@coodos

coodos commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5622b8c62d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/delegation/src/history.ts
Comment thread packages/delegation/src/history.ts
Comment thread packages/delegation/src/history.ts
Comment thread packages/delegation/src/history.ts
Comment thread packages/delegation/src/history.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 56ffd183b8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/delegation/src/history.ts
@coodos
coodos merged commit 276d2df into main Oct 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant