potiuk commented on PR #160: URL: https://github.com/apache/solr-mcp/pull/160#issuecomment-5016592330
@adityamparikh — thank you, this is exactly the review that turns an inferred model into a maintainer-owned one. Every §14 answer confirmed, with several precision points we couldn't have gotten from public artefacts alone. On our side: 1. I'll push the **disclosure-address fix** now — aligning `SECURITY.md` to `[email protected]` to match `THREAT_MODEL.md` §1. Good catch. 2. I'll **hold the fold-in** of your answers into `THREAT_MODEL.md` — flipping every `*(inferred)*` to `*(maintainer)*` and incorporating your precision notes (the streamable-HTTP **stateless** posture; the `permitAll()` + per-entry-point `@PreAuthorize("isAuthenticated()")` enforcement model; routing read-only / per-tool-role hardening to #66; and the "query-parser expressiveness and resource bounds are Solr's responsibility" position from the #122/#127 closures) — until @epugh / @janhoy have had the review you asked for. Once they weigh in I'll push the revision so it's merge-ready. The enrollment and merge call is the Solr PMC's, as you note. Thanks again — this is the model working as intended: we draft, you correct, the project owns it. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
