Skip to content

Release 2026.2.7.4 - #896

Merged
bencap merged 5 commits into
mainfrom
release-2026.2.7.4
Sep 28, 2026
Merged

bencap merged 5 commits into
mainfrom
release-2026.2.7.4

Conversation

@bencap

@bencap bencap commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

bencap and others added 5 commits September 23, 2026 14:23
…ation

A calibration could be published while its score set was still private, and the calibration READ rule
permitted any non-private calibration without consulting the score set. The variant routes under
/score-calibrations/{urn} check calibration READ only, so an unauthenticated caller holding the URN of
such a calibration received the private score set's variants, including every score and count column.
Any contributor could create and publish one, releasing data before the score set's owner did.

Close both halves. Publishing a calibration now fails with 400 while its score set is private, the
check that had been left commented out since calibrations were introduced. Calibration READ now also
requires READ on the score set, delegated to the score set's own rule, so calibrations already
published this way stop leaking on deploy, and writers that bypass the publish route (an admin move,
the calibration loader scripts) cannot reopen it. Denials are 404, matching the variant routes. This
also withholds a private calibration from its creator once they can no longer read the score set.

/score-calibrations/me returned every calibration a user had created with no permission check, so a
contributor removed from a private score set still received its calibrations' ranges and tmp URN. It
now filters on READ.

Existing rows are left as they are; clearing private and primary on public calibrations of private
score sets is a separate data fix.

Most of the test churn is fixtures that modelled the leaked state: calibrations published on
unpublished score sets, mock score sets with no private attribute, and dump score sets carrying a
published date with private left true.
…alysis-experiment-reuse

fix(score-sets): only reuse meta-analysis experiments the caller can add to
…exposed-via-public-calibrations

fix(permissions): require score set visibility to read a score calibration
@bencap bencap added the core: release A release PR label Sep 28, 2026
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 36477423694

Warning

No base build found for commit 1353dd4 on main.
Coverage changes can't be calculated without a base build.
If a base build is processing, this comment will update automatically when it completes.

Coverage: 88.81%

Details

  • Patch coverage: 17 of 17 lines across 5 files are fully covered (100%).

Uncovered Changes

No uncovered changes found.

Coverage Regressions

Requires a base build to compare against. How to fix this →


Coverage Stats

Coverage Status
Relevant Lines: 15568
Covered Lines: 13826
Line Coverage: 88.81%
Coverage Strength: 0.89 hits per line

💛 - Coveralls

@bencap
bencap merged commit c03c01d into main Sep 28, 2026
13 of 15 checks passed
@bencap
bencap deleted the release-2026.2.7.4 branch September 28, 2026 23:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core: release A release PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants