Add gated submissions API and agent intake skill - #1776
Merged
Merged
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #1776 +/- ##
==========================================
+ Coverage 54.84% 54.89% +0.04%
==========================================
Files 314 314
Lines 12704 12717 +13
Branches 4006 4122 +116
==========================================
+ Hits 6968 6981 +13
Misses 5441 5441
Partials 295 295
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
JasonWildMe
marked this pull request as ready for review
September 24, 2026 20:13
dateIsInFuture compared submitted dates with the server JVM's local date, so a submitter who was already a calendar day ahead of the server (for example Australia or New Zealand against a UTC or U.S. Pacific host) had their legitimate same-day observation rejected as "in the future". On a UTC server this rejects Sydney's "today" for 10 hours a day; on a Pacific server, 17 hours. The same edge rejected New Year's Day while the server was still on December 31. Compare against the current date at UTC+14, the earliest civil calendar date on Earth, so any observer's local current date is accepted while genuinely future dates are still rejected. Instant-based checks (dateInMilliseconds) are unaffected. The shared helper also backs the legacy bulk importer, EncounterForm, EncounterPatchValidator and Encounter date setters, which all gain the same tolerance. An overload taking an explicit "today" makes the tests deterministic, replacing the previous test that depended on the server's local date. Reviewed by Codex; its test-determinism finding is addressed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Co-Authored-By: Codex <noreply@openai.com>
Validation reports turned every legacy bulk-import rejection into INVALID_VALUE "Value failed bulk-import validation". A future day or month was reported on Encounter.year, parse failures leaked Java exception text, and an unconfigured locationID produced two issues. An agent following the skill could only guess, and tended to "correct" a year that was right. INVALID_VALUE issues now carry an optional, additive reason (REQUIRED, REQUIRES_FIELD, UNPARSEABLE, OUT_OF_RANGE, FUTURE_DATE, NOT_CONFIGURED, INVALID) and a specific message, for example "'F' is not a configured sex value; use one of: unknown, male, female" or "2025-02 has no day 29". Where legacy validation replaced a supplied value's own error with a generic "required value", the original cause is recovered. A future date is reported on the year, month or day that is actually too late, judged against the UTC+14 date captured before legacy validation runs. The duplicate legacy location issue is suppressed only when INVALID_LOCATION was already reported for that row. Acceptance is unchanged: each legacy rejection still yields exactly one issue, and valid, normalizedRows and the digests the importer re-checks are untouched. Legacy bulk import messages are not modified. The skill documents reasons and says to check the source observation rather than change values to pass. Both OpenAPI copies describe reason as an open list, the contract checker asserts parity with the Java list, and tests run the real legacy validators so wording drift fails. Plan and code reviewed by Codex; its findings on recovering overwritten causes, future-date attribution (including a nonexistent day that is also in the future), bounded allowed-value lists and a fixed test clock with report-invariant checks are addressed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Co-Authored-By: Codex <noreply@openai.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Agents, partner apps and human users need durable uploads, validation previews and retry-safe import acceptance. This adds a disabled-by-default
/api/v3/submissionsresource alongside bulk import: draft, upload photos, supply JSON rows, validate, commit once, and retrieve source-row-to-record mappings. Existing bulk-import routes and defaults remain unchanged.New submissions default to detection followed by individual identification matching. Explicit
processing.mode=import-onlyskips both; saved submissions retain their original mode. Matching produces candidates for review, not automatic identity assignment.Enrollment and human access
submissions:writeafter password confirmation. The two token audiences remain separate.submissions.allowedUserIdsis ignored. Grant the role to existing pilot accounts during rollout. Global admission, commit and worker switches remain unchanged.Included
dispatchedreports handoff, not completed identification.Verification
Deployment
Apply SUBMISSION metadata (including nullable AI_STATE and AI_STARTED_AT for earlier pilot schemas), private staging mount/permissions and private global settings. Deploy the frontend build as well as the WAR. The WAR excludes WEB-INF/web.xml, so apply the servlet/Shiro mappings through the installation descriptor process. Restart after first enabling the worker. Assign api-submission to pilot accounts, then verify Data import token issuance, admission and role revocation before widening access.
Pilot runbook · Agent skill