Skip to content

SP-1173: decide CUI marking from the cover response status - #414

Merged
Dennis Woditsch (dwoditsch) merged 4 commits into
feat/SP-1173-cui-marking-directory-exportsfrom
feat/SP-1173-cui-cover-response-semantics
Aug 13, 2026
Merged

SP-1173: decide CUI marking from the cover response status#414
Dennis Woditsch (dwoditsch) merged 4 commits into
feat/SP-1173-cui-marking-directory-exportsfrom
feat/SP-1173-cui-cover-response-semantics

Conversation

@dwoditsch

@dwoditsch Dennis Woditsch (dwoditsch) commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Description

Stacked on #413. Addresses changes from here

The CUI cover call now decides the outcome by status code only. resolvedCuiMarking.categories is no longer read anywhere, and there is no unclassified artifact: marked content is always classified. The CLI recognises 403 and 200, and treats everything else, including 204, as a failure.

Cover response Outcome Example (list packages --json)
403 — feature flag disabled Unmarked, unchanged packages.json
200 Classified + PDF cover CUI - packages.zip containing packages.json and CUI_Cover_Sheet.pdf
204, any other status, transport failure, or a 200 without a usable cover page Command errors, nothing written

What changed against the previous behaviour:

Cover response Before After
403 Unmarked Unmarked (unchanged)
204 Unmarked Command errors
200 Unclassified without categories, classified with them Always classified + PDF cover

CuiApi returns a disabled / classified decision instead of a nullable cover body, and CuiFileService switches on it. isClassified, every category check, and the Unclassified - prefix are gone. Failures fail closed: the command errors and no artifact is left behind.

docs/cui-marking.md is updated to match.

Relevant links

Checklist

  • I have self-reviewed this PR
  • I have tested the change and proved that it works in different scenarios
  • I have updated docs if needed

Note

Medium Risk
Behavior change for teams that previously got unmarked output on 204 or Unclassified - on 200 without categories; marking is compliance-sensitive but scope is limited to export/write paths with broad test coverage.

Overview
CUI disk marking now follows only the cover API HTTP status, aligned with backend changes. 403 still means no marking; 200 always produces classified output (CUI - … plus CUI_Cover_Sheet.pdf). 204, other statuses, transport errors, and 200 without a usable cover page fail closed—the command errors and writes nothing.

The CLI drops Unclassified - … artifacts and no longer reads resolvedCuiMarking.categories. CuiApi.getCuiMarking() returns a DISABLED / CLASSIFIED decision; CuiFileService branches on that. docs/cui-marking.md and tests are updated (including default CUI mock 403 instead of 204).

Reviewed by Cursor Bugbot for commit 49ee9f4. Bugbot is set up for automated code reviews on this repo. Configure here.

The cover response categories no longer take part in the decision: 403
leaves the artifact untouched, 204 marks it Unclassified, and 200 marks
it CUI and attaches the cover sheet. Anything else fails the command
without writing output.

Includes-AI-Code: true
Co-authored-by: Cursor <cursoragent@cursor.com>
Unclassified is now reached through 204 and classified through 200, so
the specs drop the category fixtures. The shared mock answers 403 so
unrelated tests keep their original filenames.

Includes-AI-Code: true
Co-authored-by: Cursor <cursoragent@cursor.com>
The command specs only exercised classified writes, so the 204 branch
was reached by the unit spec alone. Each artifact shape now has an
unclassified case, and a failing cover call is asserted to abort the
command without producing a file.

Includes-AI-Code: true
Co-authored-by: Cursor <cursoragent@cursor.com>
Marked content is always classified, so the CLI recognises only 403 and
200. A 204 is no longer a use case and now fails the command like any
other unusable answer, leaving no output behind.

Includes-AI-Code: true
Co-authored-by: Cursor <cursoragent@cursor.com>
@sonarqubecloud

Copy link
Copy Markdown

@dwoditsch
Dennis Woditsch (dwoditsch) merged commit d950acc into main Aug 13, 2026
8 checks passed
@dwoditsch
Dennis Woditsch (dwoditsch) deleted the feat/SP-1173-cui-cover-response-semantics branch August 13, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants