fix(access): merge public production access rollout into main - #282
fix(access): merge public production access rollout into main#282BigSimmo wants to merge 20 commits into
Conversation
The golden retrieval set was 100% lexical fast-path (embedding_skipped_rate=1.0), so it could not measure whether a re-index changes vector/embedding retrieval quality. - forceEmbedding option on searchChunksWithTelemetry (SearchChunksArgs): bypasses every lexical text-fast-path so retrieval always exercises the embedding/vector stage. Diagnostic/eval-only; folded into the search cache key; never set on production paths. - eval-retrieval.ts: per-case `forceEmbedding` field + a global `--force-embedding` flag. - 10 `vector-*` cases (psychiatric monographs: PTSD, OCD, panic, anorexia, GAD, Tourette, postnatal, bipolar, ADHD, opioid) with forceEmbedding=true. Each is a clinical query that must be answered by vector retrieval of the right monograph — verified live at document_recall@5=1.0, content_recall@5=1.0, all via strategy=hybrid (embedding used). Rationale: forcing embedding is the correct instrument for re-index measurement — you want to measure the vector index directly, not have a lexical shortcut mask a regression. Wording alone can't reliably force the vector path (the fast-path is driven by emergent lexical-match strength), so the flag makes these probes deterministic. Live golden eval: 34/34 pass (24 existing + 10 new), no regression. verify:cheap green (980). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Wire forceEmbedding through eval runners and retrieval cache keys, bypass coverage/lexical shortcuts when forced, and add golden-case failure metrics so vector regressions cannot hide behind text-fast-path or cache hits.
- Degrade invalid bearer tokens to anonymous scope instead of 401 - Allow public document read routes (list, detail, signed-url, search, images) - Align registry routes with medications/differentials auth-signal short-circuit - Let DocumentViewer load public sources without requiring sign-in - Add regression tests and update access-control expectations
Create missing retrieval-support indexes (trgm, composite btree, partial miss log) that were absent or only present under legacy names on live. Update search_schema_health() to accept verified functional equivalents during rollout. Set search_path for pg_trgm gin_trgm_ops in extensions. Verified on linked project: search_schema_health() ok=true, missing=[].
…board Delete post-extraction dead code left in the monolith and trim unused imports. Also fix minor lint issues in favourites-hub, visual-evidence, and services-navigator.
…rdening fix(access): complete public retrieval scope and production access hardening
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This pull request has been ignored for the connected project Preview Branches by Supabase. |
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
BigSimmo
commented
Jul 5, 2026
Superseded by #274 (merged to main). The access rollout stack is already on main; rebase any follow-up work directly onto main. |
Pull request was closed
Summary
Merges the completed content-access review rollout into
main, reconciled with setup-status hotfix (#277).Access & privacy
RAG retrieval
Follow-up fixes on this PR
document_uploadrate-limit bucket (fixes typecheck)$dollar-quote delimiters in20260705210000migration +schema.sqlVerification
npm run typecheck— PASS locally on merge branchpublic-access-deep,private-access-routes,owner-scope)npm run check:production-readiness— PASSnpm run check:document-label-governance— PASSnpm run verify:cheap— CI pending / local blocked by parallel worktree churn20260705210000— apply blocked by RPC return-type drift (see Notes)Clinical Governance Preflight
sjrfecxgysukkwxsowpy)Notes
Live migration:
20260705210000_retrieval_owner_filter_sentinel.sqlstill needs apply.supabase db push --include-allfails atmatch_document_chunks_textwithcannot change return type of existing function— live RPC bodies have drifted from the migration snapshot. Needs a targeted reconcile migration (drop + recreate or no-op repair) before anonymous RAG sentinel is active in production.Gitleaks: CI flags pre-existing
data/medications-snapshot.jsonentries from upstream history; not introduced by this PR.