Originally created by: pyy3
Fixes the konsolidat security + design findings raised in review (#23–#31).
profiles.yml: env-driven TLS (CLICKHOUSE_SECURE/VERIFY) + a prod target that defaults to secure; dev stays plaintext loopback.docker-compose.yml: weak :- password defaults → required :? vars (ADMIN / DB_ROOT / CLICKHOUSE); ClickHouse ports bound to loopback by default (CLICKHOUSE_BIND); deploy.sh no longer echoes the admin password to stdout (it's already saved to a chmod-600 .credentials). .env.example updated.security-architecture.md: reconcile the isolation claims with what the bundled compose actually ships (new Deployment profiles section) + add a source-connector security section.$filter cursor rendered via odata_filter_literal so a tampered state value can't inject OData syntax.check_connection messages (pure auth_error_message); raw server body only at debug level.429/5xx with Retry-After-aware backoff.cross_company is configurable (spec.yaml, default true).spec.yaml: mark tenant_id / client_id airbyte_secret (defence in depth).taskpane.js ↔ epm_batch contract drift (it wrapped the body in {queries}, used fiscal_year, and read message as an array). Now: bare array, year key, reads message.values. Added docs/reference/epm-formula-protocol.md (contract SoT) + tests/test_epm_client_parity.py.docs/reference/semantic-layer.md; updated the stale "remove-cube" tests to assert the intended architecture.Connector unit tests: 43 passed (28 baseline + 15 new, no monkeypatching). Root doc/cleanup/parity: 24 passed (the 4 pre-existing cube-removal failures are now resolved per the keep-Cube decision).
Note: opened from a fork by an account with read-only access to grynn-in. The Office.js add-in change is contract-aligned but not runtime-tested (no Excel in the environment).
🤖 Generated with Claude Code
Closes [#23]. Closes [#24]. Closes [#25]. Closes [#26]. Closes [#27]. Closes [#29]. Closes [#30]. Closes [#31].
Tickets: #23
Tickets: #24
Tickets: #25
Tickets: #26
Tickets: #27
Tickets: #29
Tickets: #30
Tickets: #31
Tickets: #35
Originally posted by: pyy3
Update (self-review): Restructured into two commits so the runtime-untested change is isolated:
24b39d9— security + design + docs (#23–#27, [#29]–#31, [#28] docs). Fully tested here (connector 43, root 22). Independently green — verified at this commit withtaskpane.jsuntouched.4f08662— thetaskpane.jsepm_batchcontract fix + parity test (#28). The only change that couldn't be exercised without Excel — please smoke-test the add-in's budget refresh before merging this commit.Also fixed during review:
profiles.ymlTLS now uses literal-booleandev/prodtargets (the earlier Jinja== 'true'rendered to the string"False", which dbt-clickhouse would treat as truthy).Related
Tickets:
#28Tickets:
#29Originally posted by: pyy3
Split update: [#28] (the
=EPM()Office.js client fix + protocol doc + parity test) has been moved to its own PR [#35] — it's the one change that needs an Excel smoke-test. This PR (#34) no longer touchestaskpane.jsand is fully tested here (connector 43 + root 22). The two PRs are independent (no shared files).Related
Tickets:
#28Tickets:
#35Ticket changed by: grynn-in