potiuk commented on PR #160:
URL: https://github.com/apache/solr-mcp/pull/160#issuecomment-5016592330

   @adityamparikh — thank you, this is exactly the review that turns an 
inferred model into a maintainer-owned one. Every §14 answer confirmed, with 
several precision points we couldn't have gotten from public artefacts alone.
   
   On our side:
   
   1. I'll push the **disclosure-address fix** now — aligning `SECURITY.md` to 
`[email protected]` to match `THREAT_MODEL.md` §1. Good catch.
   2. I'll **hold the fold-in** of your answers into `THREAT_MODEL.md` — 
flipping every `*(inferred)*` to `*(maintainer)*` and incorporating your 
precision notes (the streamable-HTTP **stateless** posture; the `permitAll()` + 
per-entry-point `@PreAuthorize("isAuthenticated()")` enforcement model; routing 
read-only / per-tool-role hardening to #66; and the "query-parser 
expressiveness and resource bounds are Solr's responsibility" position from the 
#122/#127 closures) — until @epugh / @janhoy have had the review you asked for. 
Once they weigh in I'll push the revision so it's merge-ready.
   
   The enrollment and merge call is the Solr PMC's, as you note. Thanks again — 
this is the model working as intended: we draft, you correct, the project owns 
it.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to