Summary
Contract expects 401/403 on sensitive routes; workflow only runs pytest.
Impact: Production user/operator failure on Osmantic/ODS main
Files:
.github/workflows/dashboard.yml
tests/contracts/test-dashboard-auth-contract.sh
Repro
On a production-like Osmantic/ODS main checkout:
- Hit the failure mode described in Summary (severity: High).
- Observe the broken behavior / incorrect exit / missing guard from the root cause above.
- Confirm no overlapping open PR (dedup: No open issue. No open PR.).
Fix
Implement a minimal, distro-/path-correct fix in the listed files (no scope creep).
- Address the root cause directly (do not paper over with
|| true / broad catches).
- Prefer resolving runtime values from the environment/repo (like
apt-cache madison) over hardcoding distro-specific version strings when the same bug class applies.
- Add a regression test under
ods/tests/ (or matching suite) that fails without the fix and passes with it.
Context
Filed from Desktop issues.md entry #38 via one-click scout pipeline.
Rationale: Unfiled Desktop issues.md #38 (no GitHub issue yet)
Summary
Contract expects 401/403 on sensitive routes; workflow only runs pytest.
Impact: Production user/operator failure on Osmantic/ODS main
Files:
.github/workflows/dashboard.ymltests/contracts/test-dashboard-auth-contract.shRepro
On a production-like Osmantic/ODS main checkout:
Fix
Implement a minimal, distro-/path-correct fix in the listed files (no scope creep).
|| true/ broad catches).apt-cache madison) over hardcoding distro-specific version strings when the same bug class applies.ods/tests/(or matching suite) that fails without the fix and passes with it.Context
Filed from Desktop
issues.mdentry #38 via one-click scout pipeline.Rationale: Unfiled Desktop issues.md #38 (no GitHub issue yet)