Skip to content

Harden S360 Reporter against decommissioned-scope recovery + finish ADAL header cleanup - #453

Open
shahzaibj wants to merge 2 commits into
masterfrom
shjameel-microsoft-glowing-eureka
Open

Harden S360 Reporter against decommissioned-scope recovery + finish ADAL header cleanup#453
shahzaibj wants to merge 2 commits into
masterfrom
shjameel-microsoft-glowing-eureka

Conversation

@shahzaibj

Copy link
Copy Markdown
Contributor

What

Hardens the s360-reporter skill so the decommissioned ADAL Android service tree can never re-enter scope, and finishes removing ADAL from the report header (a gap left after PR #451).

Why

PR #451 removed ADAL from the fetch scope, but a teammate re-ran the skill and ADAL items still reappeared. Root cause was not the fetch: a stale pasted "last week" report (4 active ADAL bugs owned by a manager) tripped the Step 1e "don't mark active items resolved" continuity guard, and the agent "recovered" ADAL by re-adding the ADAL service GUID to team.json serviceIds and the manager alias to aliases. Removal-by-omission alone was not robust against agent reasoning, so this adds a hard, code-level denylist.

Changes

  • merge-items.js — new DECOMMISSIONED_SERVICE_IDS denylist (ADAL GUID 937cdc57-1253-4b55-878e-5854368926a2):
    • Sanitizes any team.json serviceIds override that tries to re-add the GUID (emits a WARN).
    • isTeamRelevant() early-returns false for decommissioned TargetIds (blocks the Person-targeted path).
    • New svcScoped filter drops service-query items targeting a decommissioned service tree.
  • SKILL.md — new "Decommissioned Scope" section, Step 0b exclusion note, and a critical Step 1e decommissioned-scope guard so stale-report items are classified decommissioned/out-of-scope (never resolved, never auto-closed, never linked).
  • generate-report.js / report-template.md — remove the leftover "AuthN SDK - ADAL Android" entry from the report header (completes PR Remove ADAL service tree from S360 Reporter skill, Fixes AB#3697739 #451).

Verification

  • Unit test against a fixture: all three leak paths (service-query, tenant-pattern, Person-targeted) drop ADAL.
  • Adversarial re-add test reproducing the teammate's exact mechanism (ADAL GUID back in serviceIds, manager in aliases, ADAL TargetIds in both queries): output contained only the 2 legit items; all three defenses fired and serviceIds collapsed 2 -> 1.

We no longer monitor the AuthN SDK - ADAL Android service tree (937cdc57-1253-4b55-878e-5854368926a2). Removed it from DEFAULT_SERVICE_IDS and tenant patterns in merge-items.js, the Target Services table and query examples in SKILL.md, and the report header service chips in generate-report.js and report-template.md.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
A stale pasted last-week report could pull the removed ADAL service tree back into scope: the Step 1e week-over-week guard treated still-active ADAL items as false-resolved and recovered them by re-adding the ADAL GUID via team.json serviceIds override + the manager alias. Add a hard DECOMMISSIONED_SERVICE_IDS denylist in merge-items.js (strips the GUID from overrides; drops ADAL items from both service and person queries) and a decommissioned-scope guard in SKILL.md Step 0b/1e so removed-service items are excluded from the diff, never reported resolved, and never recovered.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
@shahzaibj
shahzaibj requested a review from a team as a code owner July 28, 2026 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant