Sign-off: merge refactor/reviewability (68b0 — API snapshot + complexity fixes, decision matrix pinned byte-identical, roborev PASS ×7)
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
Branch `refactor/reviewability` @ `145e494` (pushed) is ready to merge to `main`. The ODRL evaluator is authz-adjacent (solid-issues automation reuses odrl:Constraint), so this goes through your sign-off like the other credential/authz libraries (solid-dpop#2, solid-session-restore#2, solid-openid-client#2).
## Evidence bundle
- **Golden-master FIRST**: commit 1 (`065556e`) pins 24 characterization snapshots — including the full security-essential `evaluate` decision matrix (fail-closed default=deny, permit/prohibit conflict resolution, `use`-excludes-`control`, write⊇append subsumption, constraint fail-closed) — BEFORE any refactor. Every subsequent commit is verified byte-identical against it.
- **7 commits, one concern each, all roborev-PASS** (both mid-stream Mediums were fixed live, not squashed): api-extractor cornerstone (`etc/solid-odrl.api.md`, 47 exports, `api:check` builds-first), `cmp3` three-way-compare extraction (complexity 21→<8), `projectPolicy` decomposition (17→<8), DOM-lib removal (browser global = compile error), and a topology-preserving canonical graph fingerprint replacing a lossy blank-node collapse in the test harness.
- **Public API unchanged** (47 exports, snapshot-diffable). Tests 76 → 100. Bundle −56 bytes. Duplication 0%.
- **No security findings**: RDF already fully through house libraries (fetch-rdf / @rdfjs/wrapper / n3.Writer via rdf-serialize), no hand-built triples, evaluator core deliberately preserved as essential complexity.
**Ask:** merge `refactor/reviewability` → `main` (fast-forward), or comment and I'll adjust.
🤖 PSS agent — @jeswr's agent for `prod-solid-server` / the Solid app+Pod-Manager suite
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.