chore: make the CLI Lighthouse-only; drop the trial connection - #46
Conversation
The CLI is for Lighthouse (MAHE Manipal). The Brightspace trial was only a test sandbox, so its code leaves the product: - Remove the 'trial' connection, every --site option (instructor/student groups, auth import-session) and the trial-only gate on instructor previews. Instructor previews become a Lighthouse instructor feature; an account without preview rights is refused before any write (the attempt listing or the missing Start control stops it). - connection.active_connection() returns Lighthouse. A private _override lets an out-of-repository harness point tests at a sandbox; it must use its own cookie directory, and such clients never refresh or migrate authentication. - JSON output drops the always-'lighthouse' "site" field (assessment envelopes, preview results, import-session). - Old trial cookies and checkpoints under sites/ are ignored, never migrated; origin binding still rejects foreign-origin artifacts. - Replace the trial evidence log docs/assessment-coverage.md with the generic docs/quiz-protocol.md; README examples use Lighthouse only. - Tests use the Lighthouse origin or a synthetic sandbox.example override. Refs #25 #31 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
There was a problem hiding this comment.
Your organization has used all 50 credits included in the free plan this billing period. To keep receiving reviews, upgrade your plan.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Droid encountered an error —— View job |
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Trial connection removed —
connection.pyreplacesconnection_for(site)/SUPPORTED_SITESwith aLIGHTHOUSEconstant andactive_connection(); every--siteoption (instructor/studentgroups,auth import-session) is gone, and a repo-wide sweep finds no leftoverconnection_for,hetrynow,trial, or--sitereferences in code, tests, docs, or CI config. - Private test-harness seam — the module-global
_overrideis fail-closed inactive_connection()(HTTPS origin + its owncookie_dirrequired), which structurally guarantees an override can never equalLIGHTHOUSE, soLighthouseClientalways forces_read_only_authfor it; the CDP-refresh/cookie-persistence guard atlighthouse_cli/api.py:491confirms such clients never refresh or migrate auth. - Preview becomes an instructor feature on Lighthouse — the trial-only
PreviewWorkflowgate is removed; accounts without preview rights are refused before any write (attempt-listing failure aborts with "nothing was started", missing Start control raisesPreviewRefusedError), verified against the code path. - Breaking
--jsonchange — the always-"lighthouse""site"field is dropped from assessment envelopes, preview results, andimport-sessionoutput; intentional and documented in the PR body and README. Worth a release note if any external script consumes this output. - Storage and docs — old trial cookies/checkpoints under
sites/are ignored rather than migrated (left in place, sealed);docs/assessment-coverage.mdis deleted and replaced by the genericdocs/quiz-protocol.md, which correctly points to the old evidence log's git history. - Tests — the new
sandboxfixture drives the_overrideseam; new/changed tests genuinely pin the new behavior (override validation, origin binding in both directions, the dropped--siteCLI surface, checkpoint origin binding) rather than asserting tautologies.
Full local gate on this checkout passes: ruff, mypy, lint-imports, deptry, xenon, check_secrets.py, and pytest (1582 passed) — matching the validation section.
openai-compatible/glm-5.3 | 𝕏
Code Review SummaryStatus: 1 Issue Found | Recommendation: Address before merge Overview
Issue Details (click to expand)SUGGESTION
Previous findings — resolved in `8fdca9c`
Files Reviewed (5 files)
Fix these issues in Kilo Cloud Previous Review Summary (commit 6b3a1d8)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 6b3a1d8)Status: 2 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (18 files)
Notes
Reviewed by glm-5.3-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
From Kilo and MiMo reviews of 6b3a1d8: - Accept only a plain https://host override origin (no credentials, port, path, query, fragment or non-canonical case). - Grant auth refresh/migration only to the built-in Lighthouse connection object; any override, even one equal in value to Lighthouse, is read-only. - README: drop the leftover 'Both default to Lighthouse.'
|
Droid encountered an error —— View job |
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
Since the prior review of 6b3a1d8, one commit (8fdca9c) tightens the private connection override seam, responding to the Kilo/MiMo review feedback.
- Tightened override origin validation —
connection.pyadds_is_plain_https_origin(), accepting exactlyhttps://host: credentials, ports, paths, queries, fragments, and non-lowercase hosts are all rejected, and six new parametrized cases pin each rejection path. - Identity-based auth-refresh rights —
LighthouseClientnow grants refresh/migration only to the built-inLIGHTHOUSEobject (is notrather than dataclass value equality), so even a value-identical connection copy stays read-only.test_only_the_built_in_lighthouse_object_may_refresh_authcovers both a monkeypatched value-equal copy and a validating override naming Lighthouse's origin, and genuinely fails if the check reverts to!=. Verified this is the only connection-equality privilege decision in the codebase; the otheractive_connection()consumers (quiz_preview_session.py,session_import.py) only read.origin/.cookie_dir. - Housekeeping — README drops the stale "Both default to Lighthouse." sentence and updates the JSON envelope example;
.secrets.baselineshifts line numbers only, with no entry changes.
Full local gate on this checkout: ruff, mypy, pytest (1588 passed, +6 new cases), and scripts/check_secrets.py all green.
| View workflow run | Using openai-compatible/glm-5.3 | 𝕏
openai-compatible/glm-5.3 | 𝕏
| def _is_plain_https_origin(origin: str) -> bool: | ||
| """``https://host`` exactly: no credentials, port, path, query or fragment.""" | ||
| parts = urlsplit(origin) | ||
| return (parts.scheme == "https" and bool(parts.hostname) and parts.port is None |
There was a problem hiding this comment.
SUGGESTION: parts.port can raise on a malformed port instead of failing closed
For an override origin like https://sandbox.example:abc or https://sandbox.example:99999, evaluating parts.port raises ValueError from urllib.parse ("Port could not be cast to integer value as 'abc'" / "Port out of range 0-65535") instead of returning False, so active_connection() propagates urllib's raw message rather than its curated one. The clause is also redundant: the final origin == f"https://{parts.hostname}" equality already rejects any origin containing a port, so dropping parts.port is None removes the raise path entirely while keeping the validation fail-closed. Low impact - _override is a trusted test-harness seam and the exception type is unchanged - but a port typo in a harness config would surface an unfamiliar error.
| return (parts.scheme == "https" and bool(parts.hostname) and parts.port is None | |
| return (parts.scheme == "https" and bool(parts.hostname) |
Reply with @kilocode-bot fix it to have Kilo Code address this issue.

Summary
Makes the CLI Lighthouse-only: MAHE Manipal's Brightspace. The D2L trial was a test sandbox, so its code leaves the product. Diff: +246 / −484.
trialconnection and every--siteoption (theinstructor/studentgroups andauth import-session), plus the trial-only gate on instructor previews.connection.active_connection()returns Lighthouse. A private_overridelets an out-of-repository harness point tests at a sandbox. The override must use its own cookie directory, and such clients never refresh or migrate authentication."lighthouse""site"field is dropped from assessment envelopes, preview results andimport-sessionoutput.sites/are ignored and never migrated. Origin binding still rejects foreign-origin artifacts, both ways; there are tests for each direction.docs/assessment-coverage.mdis replaced by the genericdocs/quiz-protocol.md, and README examples use Lighthouse only.Validation
8fdca9c: ruff, mypy, lint-imports, deptry, xenon andcheck_secrets.pyall pass; pytest reports 1588 passed.Follow-ups
--dry-run, resolved destination output) will be ported separately; fix: bind assignment submissions to selected site #28 and Bind assignment submission to an explicit site or session #25 then close.Review evidence (head
6b3a1d8, fixes in8fdca9c)Kilo's two suggestions are fixed, each pinned by a test that fails without the fix:
https://hostorigin;