Skip to content

fix(data-integrity): validate standalone native-form reset documents #271

Description

@seonghobae

Current authoritative state

This standalone native-form reset-document runtime defect is repaired on the existing canonical single-writer Draft PR #201 / branch fix/atomic-controlled-sync-200. Protected shipped truth and the frozen v0.6.0 source candidate remain exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is f582e7cfd423cc2f55b2a2adc36a6201186b31ba.

The original statement that the active lane stores formResetValue without runtime validation is historical RCA, not current active-PR behavior. Current CwlEditor accepts exactly undefined or a string for formResetValue and rejects every other runtime value before hooks, editor construction, hidden-field wiring or reset-listener registration through the stable payload-redacted RangeError('editor form reset value must be a string when provided'). Omitted behavior, exact empty and Unicode reset documents, mode-aware reset parsing, reset callback ordering, policy-aware mutation/rollback, SSR/hydration, controlled/uncontrolled behavior and native-form serialization remain preserved.

Prior issue snapshots naming 43d4f00c7cae657c54f8fd9c97d41a315bfbb350 or 343d4132574f4cb20eb561928df034154609bab7 as current are predecessor prose. Live #201 is 19 commits ahead / 0 behind protected main across exactly eight branch-owned standalone-editor paths and additionally carries same-owner composition transition/deferred-controlled-value corrections consumed by stacked browser-assurance PR #380; those later repairs do not broaden the reset-document contract.

TDD lineage / exact-current-head evidence

Test-only RED 2fe2ce9ba0071953b879f562c4cffed08e5ff1de, CI 31590376623, passed typecheck/browser/Office and existing valid cases while the new defined non-string formResetValue assertion failed. The subsequent production repair added the exact undefined|string validation before downstream form/editor lifecycle work.

For unchanged exact current head f582e7cfd423cc2f55b2a2adc36a6201186b31ba against protected main@3b38ead2d00f44eb578d0689087b9293b3dabe1e:

  • CI 32654492013: completed / success; exact-head checkout, 150 test files / 843 tests, 100% aggregate instrumented statement/branch/function/line coverage, package verification, and demo build passed;
  • Security Scan 32654492010: aggregate success but non-passing for merge/release acceptance because jobs consumed synthetic PR-merge source 4ffa57cd216d7b1ec7212fad297f86fa863d0909 and Dependency Review was skipped; existing foreign repair owner is .github PR #897;
  • SAST Semgrep 32654492044: aggregate success but non-passing for merge/release acceptance because the scan consumed synthetic PR-merge source 4ffa57cd216d7b1ec7212fad297f86fa863d0909; existing foreign exact-source repair owner is .github PR #941;
  • formal review state: one predecessor-head Cursor COMMENTED review on 9fd9a281073da390409ed368fcc9311c8d501411, explicitly non-approving;
  • qualifying exact-head approving reviews: 0;
  • unresolved inline review threads: 0;
  • GitHub reports the Draft mechanically mergeable.

Repository CI success is technical evidence only and cannot cure synthetic-source, skipped, absent, predecessor, status-only, or model-only evidence.

Ownership / integration boundary

This is Inkspan-local document/form validation only. Hosts retain form routing, transport, authentication, authorization, tenancy, durable persistence, credentials, migration, retention, deployment, durable audit and model policy.

The defect is active-PR repaired behavior only and is not protected-main shipped truth. Keep this issue open until #201 integrates under then-live governance. Keep #201 Draft/unmerged while #118 owns exact protected v0.6.0 publication/provenance acceptance and while qualifying independent latest-push approval plus every then-applicable exact-source workflow/governance gate remain incomplete. Any branch-head or live-base movement invalidates predecessor evidence; do not create a competing CwlEditor writer, self-approve, weaken gates, transfer predecessor evidence, move protected main or fabricate release identity.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions