mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
Every mutating work-session route keyed off session_id alone after the role gate, so any developer could commit into / abandon / complete a peer's active session (breaking the single-active-WorkSession invariant and stranding that task) and any PM could merge any cell's PR — the REST surface bypassed the verb layer's active-claimant gate entirely. Add a shared _assert_ownership guard: dev ops require session.agent_id to be the caller; PM merge_pr requires a cell PM to own the session's task cell (main PM / CEO / board coordinate every cell), 404 for a missing session. merge_pr took merged_by from the request body, so any PM could record a PR merge under another agent's id, corrupting the merge audit trail the completion/CEO-approval chain and metrics rely on. Drop the body param and stamp the authenticated caller's agent_id as merged_by (the MergePRRequest schema is gone with it). Tests: a second dev's token hitting a peer's /commits and /abandon -> 403 (session left active); a foreign-cell PM -> 403, same-cell PM -> 200; a spoofed body merged_by is ignored and the persisted row records the PM.