fix: bind inventory scope and constrain metric result keys - #139
Conversation
🤖 AI Code Review (Claude Fable 5 chair · lens×model matrix)_Cells (model/lens): codex/L2 claude/L2 codex/L3 claude/L3 codex/L4 claude/L4 codex/L5 claude/L5 _ Status: PASSED — No blocking issues found All load-bearing panel claims verified against base. The final chair review follows. Chair Review — PR #139: fix: bind inventory scope and constrain metric result keysIMAGE_COVERAGE: NOT_REQUIRED 1. SummaryThis PR replaces the string-inlined account/region scope fragments in 2. Issues per lensPanel note: all four codex cells returned empty reviews (no findings, no analysis shown), while all four claude cells did detailed base-verified work. The codex "no findings" outcomes are consistent with the claude verdicts at the gate level (no CRITICAL/MAJOR anywhere), but they provide no independent corroboration of the minors below — those rest on claude-panel analysis, which I re-verified against base where load-bearing. L2 — Code correctnessCRITICAL / MAJOR: None (2/2 models agree; claude-L2 enumerated every branch of the MINOR (claude-L2 only; codex-L2 silent):
L3 — Security / AWS mutation safetyCRITICAL / MAJOR: None (2/2 models agree). ADR-005 boundary intact: the only AWS call touched is read-only MINOR (claude-L3, independently re-derived by claude-L4 under its lens; codex silent — I confirmed against base
L4 — Observability / data-integration correctnessCRITICAL / MAJOR: None (2/2 models agree; claude-L4's branch-by-branch equivalence table matches my own verification, including MINOR (claude-L4; codex silent):
L5 — Docs/ADR consistencyCRITICAL / MAJOR: None (2/2 models agree). No doc asserts the old "validated then inlined" mechanism; MINOR (claude-L5; codex silent):
3. Suggestions
4. VerdictNo CRITICAL or MAJOR findings from any of the 8 panel cells, and none arose from chair verification. All minors are hardening/documentation follow-ups, several pre-existing and outside the diff's gate scope. Image manifest is empty (no PNG evidence required); all cells plus chair declared coverage NOT_REQUIRED. Triggered by commit |
Harden the inventory-summary and fleet-metric boundaries found while directly reviewing the pending main promotion (#137).
Inventory aggregate, split and EC2-distribution queries now reuse bound account/region arrays and the global-region flag instead of interpolating validated user values. Existing defaults, invalid-account fallback, explicit empty-region behavior and aggregate collection-status visibility are preserved.
Fleet metric results now use Maps internally, accept only requested metric keys and finite values, and serialize prototype-shaped entity names as ordinary own properties. Topology tests identify the exact origin ID instead of using host-substring predicates, removing misleading URL-sanitization patterns without changing application routing.
Validation: 154 targeted Vitest tests passed; 325 existing runtime-policy/session/audit/private-plan tests passed; npm ci and Next.js production build passed. Added coverage checks shared bindings across all three aggregate queries, prototype-shaped entity IDs, unexpected metric keys and non-finite responses. No infrastructure or feature flags changed.