SSOT 대시보드:
- 한신대 기술분석 PDF(19쪽) 정합성 분석 + 이번 세션 발견 섹션 추가
- 섹션 폴드아웃(접기)·상단 목차(드릴다운)·모두 펼치기/접기 — 내용 보존, 레이아웃만 정리
페르소나 반응 강화('저항·반응 조절' 핵심 차별):
- PersonaCard.triggers(역린) 필드 + CCD 핵심상처 파생 역린 블록
- L0에 무례·모욕·조롱 시 현실적 동맹 균열 반응 지침
버그·성능 수정(라이브/E2E로 포착):
- 게이트웨이 페르소나 격리: --append-system-prompt를 --system-prompt(교체)로 + --exclude-dynamic-system-prompt-sections (내담자 캐릭터 붕괴·개발맥락 누출 차단)
- RAG: 임베더 동기 로드(약 7-13초)를 _warm_rag_caches 백그라운드 warm으로(세션 생성 블로킹 회귀 수정)
- voice TTS RMS 데드힌트 제거, init_state OpennessParams 파라미터객체화
- 한국어 PII(날짜·금액·주소) 마스킹 보강
- 레이아웃 시각 게이트: 폼 컨트롤 값 스크롤 오탐 제외(7/7)
검증: 백엔드 84/84, E2E 42(데스크톱 27·모바일 11·아바타 4), 시각 게이트 7/7
29 lines
1.4 KiB
Markdown
29 lines
1.4 KiB
Markdown
# Postgres RLS/Audit Smoke
|
|
|
|
Use this only against a local or disposable dev Postgres database initialized from
|
|
`infra/db/init/*.sql`. The checker writes temporary fixture learners, sessions,
|
|
turns, and audit rows, then removes only rows tagged with its unique run id.
|
|
|
|
## Run
|
|
|
|
Use the non-owner app role created by `infra/db/init/99_app_role.sh`; do not use
|
|
`postgres`, a superuser, a `BYPASSRLS` role, or a table owner.
|
|
|
|
```powershell
|
|
$env:VIGNETTE_RLS_AUDIT_DSN = "postgresql://vignette_app:vignette_app@127.0.0.1:5432/vignette"
|
|
C:\Users\encep\AppData\Local\Programs\Python\Python311\python.exe scripts\check-postgres-rls-audit.py --write-fixtures
|
|
```
|
|
|
|
The script intentionally ignores `DATABASE_URL`. Without an explicit smoke DSN
|
|
and `--write-fixtures`, it prints prerequisites and exits nonzero.
|
|
|
|
## Checks
|
|
|
|
- Learner A can read their own session, but cannot read learner B's session or turns.
|
|
- Instructor visibility is scoped to `app.current_cohort`.
|
|
- An evaluator-only turn is hidden from learner/client/counselor AI context and visible to evaluator AI.
|
|
- Instructor and admin read paths can insert `audit.audit_log` `read_session` rows.
|
|
|
|
Any proof that cannot be made from the current schema or connection role is not
|
|
reported as passed. Default exit code is nonzero for failures or skipped proof;
|
|
use `--allow-skips` only when intentionally probing a partial local schema.
|