Files
llm-wiki/docs/superpowers/specs/2026-07-18-keycloak-branch-note-consistency/lanes/lane-05-semantic-risk-sample.md
T

5.8 KiB

Keycloak Semantic Edge Risk Sample

이 lane은 valid reference occurrence 647건 전체가 아니라 lane finding 중 고위험 후보 20건을 표본 대조했다. 실제 D 또는 § edge는 9건이었고 11건은 내부 모순, D-id 없는 비교, self-reference여서 NOT_AN_EDGE로 분리했다.

Counts

Classification Count
CONSISTENT 2
STALE_SUMMARY 1
CONTRADICTION 1
RESTATED_FOREIGN_DECISION 5
NOT_AN_EDGE 11

Edge Verdicts

Lane ID Citing → owner Ref Verbatim evidence Verdict Action
L1-F02 account-linking-spa-ux:119 → account-linking-sub-vs-email:152 D3 Citing: “orphan 거부 메커니즘은 owner 브랜치 D3(역시 needs-confirmation)에서 추적” / Owner: “Account Console self-service unlink lockout 방지는 Keycloak 엔진이 서버에서 이미 강제” STALE_SUMMARY Citing을 server guard 확인 및 release-tag 재확인 필요라는 한 줄로 갱신.
L1-F03 account-linking-spa-ux:117 → idp-mappers-claim-to-role:120 D2 Citing은 email_verified=true와 Attribute Importer와 custom step을 위임하면서 복제하고, owner D2도 같은 mechanism을 결정한다. RESTATED_FOREIGN_DECISION Citing에는 owner D2 pointer와 linking trust gate consume 한 줄만 남김.
L1-F05 account-linking-sub-vs-email:154 → google-claim-attribute-mapping:130 D3 Citing과 owner가 IMPORT와 FORCE의 값 및 local edit 대 Google 최신성 조건을 함께 보유한다. RESTATED_FOREIGN_DECISION Takeover와 Sync Mode가 직교한다는 한 줄과 owner pointer만 유지.
L1-F08 docker-compose-stack:236 → single-ec2-no-google:197 D3 Citing은 KC_HOSTNAME, issuer-uri, host network 또는 extra_hosts를 복제하고 owner D3도 같은 bundle을 결정한다. RESTATED_FOREIGN_DECISION Docker note는 issuer/network wiring을 consume한다는 한 줄로 축소.
L1-F14 federation-spa-zero-change:130 → internal-spa-direct-no-google:281 D3 양쪽이 iss, signature, exp, aud 4종 backend validation을 같은 의미로 사용한다. CONSISTENT 이 edge에는 조치 없음. 정확한 audience 값은 별도 L4-F08에서 처리.
L2-F03 google-claim-attribute-mapping:130 → idp-mappers-claim-to-role:119 D1 Citing의 role freshness 목적 FORCE 요약이 owner D1의 최신 정보 반영 FORCE와 양립한다. CONSISTENT 적용 범위는 owner에서 명확화하되 edge summary 수정은 없음.
L2-F09 internal-spa-direct-no-google:342 → spa-token-storage-tradeoff:140 D1 Hub와 owner가 access memory와 refresh secure HttpOnly cookie 조합을 같은 값으로 결정한다. RESTATED_FOREIGN_DECISION Hub는 storage owner D1 pointer와 의존 한 줄만 유지.
L3-F15 public-domain-tunneling:106,169 → single-ec2-google-federation:238 D3 Parent D3와 child D1이 Cloudflare 우선, ngrok 차선의 provider 순서를 각각 normative decision으로 둔다. RESTATED_FOREIGN_DECISION Parent를 provider order owner로 두고 child는 운영 detail만 소유.
L4-F03 single-ec2-no-google:182 → vanilla-js-spa-pkce:124 D1 Citing: “manual fetch와 crypto.subtle 기반 PKCE 구현 우선” / Owner: “oidc-client-ts 우선 채택, manual PKCE는 비교 학습용 별도 단계” CONTRADICTION Owner D1을 실행 순서 정본으로 두고 citing의 manual-first를 historical learning order로 격하.

NOT_AN_EDGE

Lane ID Evidence Reason
L1-F01 authentication-authorization-contract:73,169 자신의 D3와 같은 문서 raw-role 설명의 불일치이며 foreign edge가 아니다.
L1-F07 bff-vs-spa-direct:130,165 같은 문서 요약 matrix와 D5의 불일치다.
L1-F10 edge-forwardauth-google-federation:145 대 edge-forwardauth-no-google:112 cross-doc 비교는 가능하나 target D 또는 § reference가 없다.
L1-F11 edge-forwardauth-no-google:167,227 같은 문서의 선택축과 implementation table 문제다.
L2-F05 idp-brokering-google-client:81 대 google-redirect-uri-policy:167 값은 다르지만 consumer에 owner D6 reference가 없다.
L3-F01 nginx-auth-request-integration:101,163 같은 문서 body-forwarding 설명의 불일치다.
L3-F11 refresh-token-rotation:159 대 refresh-rotation-and-logout:124 두 D-row의 중복 관찰이지만 연결 문구에 target D-id가 없다.
L3-F12 refresh-token-rotation:67 대 refresh-rotation-and-logout:61 destination wikilink와 D-id가 없는 범위 위임이다.
L3-F13 refresh-token-rotation:127 대 refresh-rotation-and-logout:120 Max Reuse 정책 사이에 D 또는 § reference edge가 없다.
L3-F16 single-ec2-google-federation:239,301 같은 parent 내부 bundle과 D-id 없는 detail 위임의 ownership 문제다.
L4-F08 role-mapping:38,115 대 audience-validator:156 값 drift는 있으나 packet의 D4는 role-mapping 자신의 RBAC D4라 유효 foreign D4 edge가 아니다.

Reconciliation with adversarial review

Semantic edge 판정과 finding 존속 판정은 목적이 다르다. 예를 들어 L4-F03 edge 문구는 CONTRADICTION이지만 citing 자체가 DECISION_DRIFT를 표시하고 owner를 정본으로 인정하므로 적대 리뷰는 독립 priority에서 REJECT했다. 원문을 고칠 때는 여전히 stale active 문구와 D-row를 수거하는 것이 맞다.

Limits

  • literal reference 647건과 logical edge 298건 중 고위험 후보 20건만 선택했다.
  • 20건 중 edge verdict가 가능한 것은 9건이었다.
  • 전체 logical edge 의미 대조는 별도 사용자 확인 후 20건 이하 lane으로 나눠야 한다.
agent: wiki-consistency-auditor
verdict: not-ready
blocking: 1
should_fix: 6
advisory: 0
agent: wiki-consistency-auditor
found: 20
processed: 9
dropped: 11
dropped_reason: NOT_AN_EDGE