Problem/Motivation
The published moderation path prevents agent publication, but an already-published entity without a moderation workflow can currently be edited in place. That mutates live content while bypassing the human-publication invariant. The correct governed behavior is denial or creation of a forward revision that remains unpublished until a human acts.
Proposed resolution
Cover already-published unmoderated entities in the publish-state enforcement path. Agent-originated changes must never mutate the live revision in place.
Acceptance criteria
- An agent cannot edit an already-published unmoderated entity in place.
- If the entity type supports forward revisions, the change is saved only as a new unpublished
- If a safe forward revision cannot be created, the write is denied with a stable reason code.
- Human/operator publication remains the only publication path.
- Tests cover moderated and unmoderated content, published and draft starting states, revisionable and
- Evidence records the attempted action, target version, result, and resulting revision when one is
revision and the live revision remains unchanged.
non-revisionable entities, translations, and retries.
created.
Related history
This is distinct from the closed moderated-content publish-bypass fixes; those fixes remain closed.
User interface changes
None required beyond a clear denial/revision result for callers and operators.
Comments
Comment #2
jmcerdaPublic working mirror: GitHub #107.
Drupal.org remains the authority for this work item; implementation discussion and pull-request linkage may occur in the mirror.
Comment #3
jmcerdaImplementation is up for review on the public working mirror: https://github.com/Wilkes-Liberty/mcp_sentinel/pull/119
Summary: a governed agent edit of an already-published unmoderated entity no longer mutates the live revision. Revisionable types store the edit as an unpublished forward (non-default) revision — the live default revision is unchanged and stays published, with an evidence row naming both revisions. Types that cannot carry a forward revision are refused with a stable message (422 on validated seams; aborted save plus an evidence row on the unvalidated seam). Go-live denials, pure takedown, moderated content, composite children, and ungoverned traffic are unchanged.
Nine new kernel tests (redirect, evidence, retries, translations, unvalidated seam, takedown, non-revisionable denial and abort, ungoverned); full module suite green (486 tests / 4152 assertions); PHPCS and PHPStan clean.
Comment #4
jmcerdaMerged to 1.x: https://github.com/Wilkes-Liberty/mcp_sentinel/pull/119 (merge 09e5d37573c58a6ebf88a24e86422de078e82c55). Ships in the next release.
A governed agent edit of an already-published unmoderated entity no longer mutates the live revision. Revisionable types store the edit as an unpublished forward (non-default) revision — the live default revision is unchanged and stays published, and an evidence row names both revisions. Types that cannot carry a forward revision are refused with a stable message: a 422 on validated seams, an aborted save plus an evidence row on the unvalidated seam. Go-live denials, pure takedown, moderated content, composite children, and ungoverned traffic are unchanged.
Coverage: nine new kernel tests (redirect, evidence payload, retries, translations, unvalidated seam, takedown, non-revisionable denial and abort, ungoverned); full suite 486 tests / 4180+ assertions green on Drupal 10.6 and 11.3 in CI.