Fix: re-adding a removed approval doesn't restore a not uuthorized acknowledgment SS #2980 - #5231
Conversation
…knowledgment SS #2980 Signed-off-by: Łukasz Gryglicki <lgryglicki@cncf.io> Assisted by [OpenAI](https://platform.openai.com/) Assisted by [GitHub Copilot](https://github.com/features/copilot) Assisted by [Claude](https://claude.ai)
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (12)
Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. WalkthroughThe pull request adds recovery of eligible employee acknowledgments when approval-list entries are re-added. It also corrects designee role detection when no project scope contains the role. ChangesApproval-list recovery
Designee role detection
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant UpdateApprovalList
participant SignatureRepository
participant UserLookup
participant GitHubOrganizationLookup
UpdateApprovalList->>SignatureRepository: Load removal-invalidated employee acknowledgments
UpdateApprovalList->>UserLookup: Resolve candidate acknowledgment users
UpdateApprovalList->>GitHubOrganizationLookup: Check organization membership when required
UpdateApprovalList->>SignatureRepository: Re-read corporate signature and restore eligible acknowledgment
Merge Risk: ⚪ Minimal · up to Re-adding approval-list entries restores acknowledgments that were invalidated only by the earlier removal. Deliberate invalidations remain unchanged. The fix also stops reporting a designee role when no project grants one. No outstanding issues were found. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 48.98% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 49 functions across 11 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Restoration remains vulnerable to a concurrent Approval List removal and does not recover GitLab-group-only acknowledgments.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Restores removal-invalidated employee acknowledgments when matching Approval List entries are re-added, and fixes CLA Manager designee detection.
Changes:
- Adds guarded acknowledgment restoration with strong reads and conditional writes.
- Adds comprehensive restoration and concurrency tests.
- Corrects false-positive CLA Manager designee results.
| File | Description |
|---|---|
docs/M3_ORG_LENS_API.md |
Documents restoration behavior and limitations. |
cla-backend-go/v2/cla_manager/service.go |
Fixes designee-role fallback result. |
cla-backend-go/v2/cla_manager/designee_test.go |
Tests designee-role resolution. |
cla-backend-go/signatures/service.go |
Orchestrates acknowledgment restoration. |
cla-backend-go/signatures/repository.go |
Adds candidate reads and conditional restores. |
cla-backend-go/signatures/mocks/mock_repo.go |
Regenerates repository mocks. |
cla-backend-go/signatures/dbmodels.go |
Classifies removal-only invalidations. |
cla-backend-go/signatures/approval_list_removal_test.go |
Extends the DynamoDB test harness. |
cla-backend-go/signatures/approval_list_readd_unit_test.go |
Tests restoration helpers and repository behavior. |
cla-backend-go/signatures/approval_list_readd_test.go |
Provides shared restoration fixtures. |
cla-backend-go/signatures/approval_list_readd_e2e_test.go |
Tests end-to-end re-add recovery. |
cla-backend-go/signatures/approval_list_readd_criteria_test.go |
Tests criteria, scale, and races. |
Files not reviewed (1)
- cla-backend-go/signatures/mocks/mock_repo.go: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


Fixes linuxfoundation/lfx-self-serve#2980, linuxfoundation/lfx-self-serve#3008.
cc @ahmedomosanya @mlehotskylf
Signed-off-by: Łukasz Gryglicki lgryglicki@cncf.io
Assisted by OpenAI
Assisted by GitHub Copilot
Assisted by Claude