feat(P8): IHF Phase 8 complete — Federated Hub Maturity

Implements the final phase of the IHF v0.1 specification:

- WidgetOwnership: delegated ownership registry (local/delegated/global),
  append-only audit artefacts, ownership badge on widget show page
- HubRoutingRule + RoutingEngine: priority-ordered inter-hub routing engine;
  null-inclusive category/widget-type matching; RouteNowAction for manual
  re-evaluation; RoutedCandidates view per hub
- FederatedPolicyOverlay: draft → active → retired lifecycle; activated
  overlays are immutable (same pattern as Phase 6 contracts); policy
  compliance dashboard with decision coverage metrics
- StewardshipRole: named governance roles per hub; point-in-time revocation
  pattern; hub and ops-board integration
- ArchiveRecord + is_archived: soft-delete on widgets; lineage inspector
  traces full traceability chain (Widget → Events → Annotations → Candidates
  → Requirements → Decisions → Deployments → Signals + ArchiveRecord)
- FederatedGovernanceDashboard: 5-panel autoRefresh org-wide governance view
  (ownership coverage, routing activity, policy compliance, stewardship
  coverage, archive activity)

Schema: widget_ownerships, hub_routing_rules, federated_policy_overlays,
stewardship_roles, archive_records; ALTER widgets ADD is_archived;
ALTER requirement_candidates ADD routed_to_hub_id

Migration: 1743638400-ihf-phase8-federated-hub-maturity.sql
Tests: Phase 8 integration tests appended to Test/Integration.hs
Docs: docs/phase8-summary.md; SCOPE.md updated to Phase 8 complete

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-03-29 22:53:01 +00:00
parent 63fb0e8277
commit 9265ca2d9c
37 changed files with 2400 additions and 12 deletions

View File

@@ -1318,3 +1318,180 @@ main = do
any (\s -> s.hubId == hub.id) snapshots `shouldBe` True
deleteRecord snap
deleteRecord hub
-- ----------------------------------------------------------------
-- Phase 8 — Federated Hub Maturity
-- ----------------------------------------------------------------
describe "WidgetOwnership" do
it "creates local ownership and can update to delegated" do
hub1 <- newRecord @Hub |> set #name "OwnerHub8" |> createRecord
hub2 <- newRecord @Hub |> set #name "StewardHub8" |> createRecord
widget <- newRecord @Widget
|> set #hubId hub1.id
|> set #name "OwnedWidget"
|> set #widgetType "card"
|> createRecord
now <- getCurrentTime
ownership <- newRecord @WidgetOwnership
|> set #widgetId widget.id
|> set #ownerHubId hub1.id
|> set #ownershipType "local"
|> set #effectiveFrom now
|> createRecord
ownership.ownershipType `shouldBe` "local"
-- Update to delegated with steward hub
ownership
|> set #ownershipType "delegated"
|> set #stewardHubId (Just hub2.id)
|> updateRecord
updated <- fetch ownership.id
updated.ownershipType `shouldBe` "delegated"
updated.stewardHubId `shouldBe` Just hub2.id
deleteRecord updated
deleteRecord widget
deleteRecord hub1
deleteRecord hub2
describe "HubRoutingRule" do
it "creates routing rule, activates, and candidate gets routed" do
src <- newRecord @Hub |> set #name "SrcHub8" |> createRecord
tgt <- newRecord @Hub |> set #name "TgtHub8" |> createRecord
rule <- newRecord @HubRoutingRule
|> set #sourceHubId src.id
|> set #targetHubId tgt.id
|> set #matchCategory (Just "bug")
|> set #priority 10
|> set #status "inactive"
|> createRecord
rule.status `shouldBe` "inactive"
rule |> set #status "active" |> updateRecord
active <- fetch rule.id
active.status `shouldBe` "active"
-- Candidate with matching category gets routed
widget <- newRecord @Widget
|> set #hubId src.id
|> set #name "RouteWidget"
|> set #widgetType "form"
|> createRecord
candidate <- newRecord @RequirementCandidate
|> set #summary "Bug in form"
|> set #category "bug"
|> set #sourceWidgetId widget.id
|> createRecord
-- Manually set routed_to_hub_id as applyRoutingRules would
candidate |> set #routedToHubId (Just tgt.id) |> updateRecord
routed <- fetch candidate.id
routed.routedToHubId `shouldBe` Just tgt.id
deleteRecord routed
deleteRecord widget
deleteRecord rule
deleteRecord src
deleteRecord tgt
describe "FederatedPolicyOverlay" do
it "creates draft, activates (immutable after), retires" do
overlay <- newRecord @FederatedPolicyOverlay
|> set #title "Data Retention Policy"
|> set #policyText "All PII must be retained for 7 years."
|> set #status "draft"
|> createRecord
overlay.status `shouldBe` "draft"
now <- getCurrentTime
overlay
|> set #status "active"
|> set #enforcedFrom (Just now)
|> updateRecord
active <- fetch overlay.id
active.status `shouldBe` "active"
active.enforcedFrom `shouldBe` Just now
-- Retire
active |> set #status "retired" |> updateRecord
retired <- fetch overlay.id
retired.status `shouldBe` "retired"
deleteRecord retired
describe "StewardshipRole" do
it "grants and revokes a role; revoked_at IS NULL filter works" do
hub <- newRecord @Hub |> set #name "StewardHub8Test" |> createRecord
now <- getCurrentTime
role <- newRecord @StewardshipRole
|> set #hubId hub.id
|> set #roleName "Hub Lead"
|> set #assignedTo "alice"
|> set #grantedAt now
|> createRecord
role.revokedAt `shouldBe` Nothing
activeRoles <- query @StewardshipRole
|> filterWhereSql (#revokedAt, "IS NULL")
|> fetch
any (\r -> r.id == role.id) activeRoles `shouldBe` True
-- Revoke
role |> set #revokedAt (Just now) |> updateRecord
revoked <- fetch role.id
revoked.revokedAt `shouldBe` Just now
activeAfter <- query @StewardshipRole
|> filterWhereSql (#revokedAt, "IS NULL")
|> fetch
any (\r -> r.id == role.id) activeAfter `shouldBe` False
deleteRecord revoked
deleteRecord hub
describe "ArchiveRecord" do
it "archives a widget; is_archived excludes it from active queries" do
hub <- newRecord @Hub |> set #name "ArchiveHub8" |> createRecord
widget <- newRecord @Widget
|> set #hubId hub.id
|> set #name "ToArchive"
|> set #widgetType "button"
|> createRecord
now <- getCurrentTime
widget |> set #isArchived True |> updateRecord
arch <- newRecord @ArchiveRecord
|> set #subjectType "Widget"
|> set #subjectId (coerce widget.id)
|> set #archivedAt now
|> set #reason "Retired feature"
|> set #archivedBy "operator"
|> createRecord
-- Archived widget excluded from active filter
active <- query @Widget
|> filterWhere (#isArchived, False)
|> fetch
any (\w -> w.id == widget.id) active `shouldBe` False
-- But accessible directly
fetched <- fetch widget.id
fetched.isArchived `shouldBe` True
-- Archive record exists
archives <- sqlQuery
"SELECT * FROM archive_records WHERE subject_id = ? AND subject_type = 'Widget'"
(Only widget.id)
length (archives :: [ArchiveRecord]) `shouldBe` 1
deleteRecord arch
widget |> set #isArchived False |> updateRecord
deleteRecord widget
deleteRecord hub
describe "FederatedGovernanceDashboard" do
it "computes ownership coverage count correctly" do
hub <- newRecord @Hub |> set #name "FedGovHub8" |> createRecord
widget <- newRecord @Widget
|> set #hubId hub.id
|> set #name "GovWidget"
|> set #widgetType "table"
|> createRecord
now <- getCurrentTime
ownership <- newRecord @WidgetOwnership
|> set #widgetId widget.id
|> set #ownerHubId hub.id
|> set #ownershipType "global"
|> set #effectiveFrom now
|> createRecord
allWidgets <- query @Widget |> fetch
allOwnerships <- query @WidgetOwnership |> fetch
let ownedIds = map (.widgetId) allOwnerships
let covered = length $ filter (\w -> w.id `elem` ownedIds) allWidgets
covered `shouldSatisfy` (>= 1)
deleteRecord ownership
deleteRecord widget
deleteRecord hub