Harden S360 Reporter against decommissioned-scope recovery + finish ADAL header cleanup - #453
Open
shahzaibj wants to merge 2 commits into
Open
Harden S360 Reporter against decommissioned-scope recovery + finish ADAL header cleanup#453shahzaibj wants to merge 2 commits into
shahzaibj wants to merge 2 commits into
Conversation
We no longer monitor the AuthN SDK - ADAL Android service tree (937cdc57-1253-4b55-878e-5854368926a2). Removed it from DEFAULT_SERVICE_IDS and tenant patterns in merge-items.js, the Target Services table and query examples in SKILL.md, and the report header service chips in generate-report.js and report-template.md. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
A stale pasted last-week report could pull the removed ADAL service tree back into scope: the Step 1e week-over-week guard treated still-active ADAL items as false-resolved and recovered them by re-adding the ADAL GUID via team.json serviceIds override + the manager alias. Add a hard DECOMMISSIONED_SERVICE_IDS denylist in merge-items.js (strips the GUID from overrides; drops ADAL items from both service and person queries) and a decommissioned-scope guard in SKILL.md Step 0b/1e so removed-service items are excluded from the diff, never reported resolved, and never recovered. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Hardens the
s360-reporterskill so the decommissioned ADAL Android service tree can never re-enter scope, and finishes removing ADAL from the report header (a gap left after PR #451).Why
PR #451 removed ADAL from the fetch scope, but a teammate re-ran the skill and ADAL items still reappeared. Root cause was not the fetch: a stale pasted "last week" report (4 active ADAL bugs owned by a manager) tripped the Step 1e "don't mark active items resolved" continuity guard, and the agent "recovered" ADAL by re-adding the ADAL service GUID to
team.jsonserviceIdsand the manager alias toaliases. Removal-by-omission alone was not robust against agent reasoning, so this adds a hard, code-level denylist.Changes
merge-items.js— newDECOMMISSIONED_SERVICE_IDSdenylist (ADAL GUID937cdc57-1253-4b55-878e-5854368926a2):team.jsonserviceIdsoverride that tries to re-add the GUID (emits a WARN).isTeamRelevant()early-returns false for decommissionedTargetIds (blocks the Person-targeted path).svcScopedfilter drops service-query items targeting a decommissioned service tree.SKILL.md— new "Decommissioned Scope" section, Step 0b exclusion note, and a critical Step 1e decommissioned-scope guard so stale-report items are classifieddecommissioned/out-of-scope(neverresolved, never auto-closed, never linked).generate-report.js/report-template.md— remove the leftover "AuthN SDK - ADAL Android" entry from the report header (completes PR Remove ADAL service tree from S360 Reporter skill, Fixes AB#3697739 #451).Verification
serviceIds, manager inaliases, ADAL TargetIds in both queries): output contained only the 2 legit items; all three defenses fired andserviceIdscollapsed 2 -> 1.