Skip to content

test: subflow fault chain in error-boundary-lab and morph-idm role header precedence - #25

Merged
yilmaztayfun merged 1 commit into
masterfrom
test/eb-subflow-fault-chain-morph-idm-header
Oct 1, 2026
Merged

yilmaztayfun merged 1 commit into
masterfrom
test/eb-subflow-fault-chain-morph-idm-header

Conversation

@yilmaztayfun

Copy link
Copy Markdown
Contributor

Summary

Two integration-test additions that were on the working tree:

  • error-boundary-lab — three-level SubFlow fault chain. New workflows eb-sf-root → eb-sf-mid → eb-sf-leaf, task eb-http-400-task (MockLab route answering 400) and SubFlowFaultChainTests. The leaf faults through a global abort, the mid faults the same way, and the root's global notify rule routes it to r-error-end. The root completes with its incident resolved (hasActiveIncident=false, the resolved row stays in history). That explains the preprod report "subflow got HTTP 400, main flow ended in error-end, no incident on the main flow": the incident was resolved, not lost.
  • authorization-chain-lab — morph-idm role resolution. MorphIdmProviderTests updated to the 2026-09-25 decisions:
    • a request role header decides, and morph-idm is not asked;
    • authorize's role query parameter behaves like the header;
    • provider failures resolve to an empty role set, which a role-bound deny still refuses.

READMEs and the TEST-SCENARIOS.md rows record the runs and their evidence.

Not included (local tool state)

  • partner.link.json: only an import timestamp changed.
  • credit.link.json: a local link file with an absolute path.
  • .vnextstudio/.../account-opening.json: a key from a local run.

Test evidence

Recorded in the two READMEs:

  • SubFlowFaultChainTests: 5/5 green against the locally built runtime.
  • morph-idm suite: 9/9 green.
  • Remaining authorization reds match the known master reds exactly.

🤖 Generated with Claude Code

…ader precedence

error-boundary-lab gains a three-level SubFlow chain (eb-sf-root -> eb-sf-mid ->
eb-sf-leaf): the leaf's HTTP task gets a 400 and faults through a global abort,
the mid faults the same way, and the root's global notify rule routes it to
r-error-end. SubFlowFaultChainTests pins that the root completes with its
incident resolved (history keeps it), which is the preprod "no incident on the
main flow" report explained rather than a loss.

authorization-chain-lab MorphIdmProviderTests follow the 2026-09-25 decisions:
a request role header decides and morph-idm is not asked, the authorize role
query parameter behaves like the header, and provider failures resolve to an
empty role set that a role-bound deny still refuses. READMEs and the
TEST-SCENARIOS index rows record the runs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@yilmaztayfun
yilmaztayfun requested review from a team September 28, 2026 20:26
@coldtea-pr-lens

Copy link
Copy Markdown

◈ PR Lens

Note

The title starts with test:, so PR Lens left this pull request undrawn. Comment @pr-lens draw to draw it

github.comment.notice: false in .github/pr-lens.yml turns this note off

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 90d18cb6-f7da-42f1-b921-e138135843c1


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yilmaztayfun yilmaztayfun self-assigned this Oct 1, 2026
@yilmaztayfun
yilmaztayfun merged commit a846c5b into master Oct 1, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant