Files
nucleic-purpose-classifier/data/sol-6.jsonl
T
2026-07-29 23:45:26 -07:00

176 lines
47 KiB
JSON

{"prompt":"Design an authorization architecture for enterprise workspaces with organization roles, project grants, temporary elevation, service accounts, and policy simulation. Cover evaluation semantics, auditability, cache invalidation, emergency access, migration from the current role table, and rollout gates. Deliver an RFC, not implementation.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.93,"slice":"core","lang":"en"}
{"prompt":"Before changing the login service, outline a migration from session cookies to sender-constrained tokens. Include browser compatibility, key lifecycle, refresh behavior, compromised-device recovery, gradual enrollment, and rollback.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.91,"slice":"boundary","lang":"en"}
{"prompt":"Add PKCE validation to the OAuth callback","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.51,"slice":"core","lang":"en"}
{"prompt":"CI failure from the release branch:\n\n```text\nworkflow=publish-web run=9918472 attempt=2\njob=build-static runner=ubuntu-26.04\nnode=24.4.1 pnpm=10.14.0\ncache restored key=next-4b8102\nnext build: compiled successfully\ncollecting page data...\nError: ENOENT: no such file or directory, open '.next/server/app/(legal)/terms/page_client-reference-manifest.js'\nroute groups found: (app), (legal), (marketing)\nretry with cache disabled: PASS\nretry with same cache: FAIL\ncache archive includes `.next/server/app/(legal)` but excludes files matching `*client-reference-manifest*`\n```\n\nDetermine why the restored incremental cache expects a manifest that the cache action excluded and whether the cache key or Next.js build reuse is responsible.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.77,"slice":"pasted-context","lang":"en"}
{"prompt":"Build the React `AccessRequestDrawer` with requested scopes, justification, expiry, approver timeline, loading states, and keyboard-safe focus management.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.63,"slice":"core","lang":"en"}
{"prompt":"Plan and implement passkey authentication for the customer portal. Start with a design covering registration, discoverable credentials, cross-device flows, account recovery, attestation policy, existing MFA, session binding, browser support, observability, and rollout. Then add WebAuthn endpoints, credential storage, UI integration primitives, and conformance tests. The security and recovery design is the primary deliverable.","purpose":"planning","secondary":"backendImpl","mixed":true,"difficulty":0.98,"slice":"mixed","lang":"en"}
{"prompt":"Enable `STRICT_CSP_REPORTING`","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.08,"slice":"core","lang":"en"}
{"prompt":"Extract duplicated permission checks from the REST and GraphQL middleware into one evaluator while preserving decisions, errors, logs, and latency metrics.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.67,"slice":"core","lang":"en"}
{"prompt":"Implement `/internal/jwks/status` with active key IDs, activation times, expiry, and last successful publication.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.47,"slice":"boundary","lang":"en"}
{"prompt":"make login feel premium","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.42,"slice":"vague-eval","lang":"en"}
{"prompt":"Find why Safari occasionally loops between `/login` and `/callback` after a successful identity-provider response.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.71,"slice":"core","lang":"en"}
{"prompt":"Explain how `PolicyEngine.evaluate` resolves an explicit deny against a project grant inherited through two groups. Do not modify code.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.58,"slice":"core","lang":"en"}
{"prompt":"Security launch notes:\n\n```text\nFeature: administrator session controls\nAvailable actions: list active sessions, revoke one, revoke all except current\nSession metadata: approximate location, browser family, created time, last activity\nLocation is derived from IP and may be wrong\nRevocation propagates through Redis pubsub; fallback TTL is 15 minutes\nService-account sessions do not appear in this UI\nSupport must not claim revocation is instantaneous\nAudit events: session.revoked and sessions.revoked_all\nMobile clients before 8.4 may show one failed refresh before returning to login\n```\n\nTurn this into administrator-facing documentation with clear limitations, privacy wording, action descriptions, audit behavior, and troubleshooting for delayed revocation.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.48,"slice":"pasted-context","lang":"en"}
{"prompt":"Align the SSO provider logo with the input labels","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.13,"slice":"boundary","lang":"en"}
{"prompt":"Write a deployment guide for configuring OIDC through Helm, including issuer discovery, client secrets, redirect URLs, scopes, and validation checks.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.39,"slice":"core","lang":"en"}
{"prompt":"Implement the SCIM bearer-token rotation endpoint with overlap, revocation, audit events, and authorization tests, then document the request contract and safe rotation sequence for administrators.","purpose":"backendImpl","secondary":"writing","mixed":true,"difficulty":0.71,"slice":"mixed","lang":"en"}
{"prompt":"Map out a staged migration from repository-level GitHub Actions workflows to centrally governed reusable workflows, including exceptions, versioning, adoption metrics, and rollback.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.84,"slice":"core","lang":"en"}
{"prompt":"Rename `authzRes` to `authorizationResult` in `PolicyRoute.ts`.","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.05,"slice":"boundary","lang":"en"}
{"prompt":"Teach the token service to rotate refresh-token families atomically and detect reuse of an invalidated ancestor.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.72,"slice":"core","lang":"en"}
{"prompt":"Polish the MFA method cards","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.31,"slice":"core","lang":"en"}
{"prompt":"Bump `@simplewebauthn/server` to `13.2.2`","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.08,"slice":"core","lang":"en"}
{"prompt":"Rename `WhitelistMatcher` to `AllowlistMatcher` across source, tests, metrics, and dashboards while preserving configuration compatibility and behavior.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.64,"slice":"boundary","lang":"en"}
{"prompt":"Split `IdentityProviderService` into discovery, metadata validation, provisioning, and persistence components without changing its API contract.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.72,"slice":"core","lang":"en"}
{"prompt":"Ticket copied from the security backlog:\n\n```text\nAUTH-1827 — service account token exchange\nEndpoint: POST `/v2/token/exchange`\nInput: signed workload assertion plus requested audience\nRequirements:\n- validate issuer against tenant configuration\n- allow only configured audiences\n- maximum resulting lifetime 15 minutes\n- no refresh token\n- assertion IDs are single use for 20 minutes\n- tolerate 60 seconds of clock skew\n- emit audit event with issuer, subject, audience, and decision\n- private claims must not enter logs\n- expose accepted, rejected-by-reason, and replay metrics\n- support EdDSA and ES256; reject algorithm confusion\n```\n\nImplement the exchange endpoint, replay store, policy validation, audit event, metrics, and adversarial tests.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.87,"slice":"pasted-context","lang":"en"}
{"prompt":"Investigate why the React app loses its CSRF token after returning from the payment provider in a new tab.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.66,"slice":"core","lang":"en"}
{"prompt":"Create the role-comparison table and write a brief legend for inherited, direct, denied, and unavailable permissions. Include sticky headers, filtering, and screen-reader summaries.","purpose":"frontendImpl","secondary":"writing","mixed":true,"difficulty":0.67,"slice":"mixed","lang":"en"}
{"prompt":"Why does the login gateway preserve the original URL in a signed cookie instead of a query parameter? Explain the existing choice; nothing is broken.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.43,"slice":"core","lang":"en"}
{"prompt":"Rewrite the local setup section for running Keycloak, Mailpit, and the portal through Docker Compose.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.32,"slice":"core","lang":"en"}
{"prompt":"The authentication suite became flaky after enabling parallel tests:\n\n```text\nFAIL TestRefreshReuseRevokesFamily\nexpected status=401 actual=200\nfamily=fam_7ce current_generation=4\nrequest A token_generation=3 started=12:00:01.113\nrequest B token_generation=4 started=12:00:01.114\nrequest A reuse marker inserted at=12:00:01.128\nrequest B replacement issued generation=5 at=12:00:01.131\nrequest A family revoked at=12:00:01.139\nrequest B response sent at=12:00:01.142\n```\n\nDetermine whether the observed 200 is a test-ordering issue or a real race where a replacement escapes after reuse detection. Trace the transaction boundaries and revocation visibility.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.83,"slice":"boundary","lang":"en"}
{"prompt":"finish the SSO thing","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.49,"slice":"vague-eval","lang":"en"}
{"prompt":"Propose an authorization model for customer-managed automation bots, including delegation, scope boundaries, approval, expiry, revocation, and audit queries.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.87,"slice":"core","lang":"en"}
{"prompt":"Add detached JWS verification to the webhook CLI","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.6,"slice":"core","lang":"en"}
{"prompt":"PR excerpt:\n\n```diff\n async function requireAdmin(req, res, next) {\n- const user = await loadUser(req.session.userId)\n- if (!user.roles.includes('admin')) return res.sendStatus(403)\n+ const claims = decodeJwt(req.headers.authorization.slice(7))\n+ if (claims.role !== 'admin') return res.sendStatus(403)\n next()\n }\n```\n\nThe author says this removes a database lookup. Review the change for signature verification, claim freshness, tenant scoping, token source assumptions, error handling, and differences between the session role list and JWT role field. Do not patch it.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.7,"slice":"pasted-context","lang":"en"}
{"prompt":"Schreibe eine kurze Administrator-Dokumentation zur bestehenden Notfallzugriffs-Funktion, einschließlich Aktivierung, Ablauf, Audit-Events und Einschränkungen. Keine Codeänderungen.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.39,"slice":"boundary","lang":"de"}
{"prompt":"Build the responsive security-events explorer with saved filters, expandable payloads, virtualized rows, and accessible severity indicators.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.69,"slice":"core","lang":"en"}
{"prompt":"Review how the current GitHub Actions release workflow signs artifacts, then turn the findings into a maintainer runbook with verification and recovery steps.","purpose":"writing","secondary":"review","mixed":true,"difficulty":0.65,"slice":"mixed","lang":"en"}
{"prompt":"Set the session cookie's `SameSite` value to `Lax`","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.09,"slice":"core","lang":"en"}
{"prompt":"Benenne `TokenMgr` repositoryweit in `TokenManager` um; öffentliche JSON-Felder, Datenbankspalten und Verhalten bleiben unverändert.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.55,"slice":"boundary","lang":"de"}
{"prompt":"Consolidate the browser and mobile redirect-URI validators while preserving every accepted URI and rejection message.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.63,"slice":"core","lang":"en"}
{"prompt":"Diagnose the missing logout audit event","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.45,"slice":"core","lang":"en"}
{"prompt":"Explain how the session cache prevents a revoked account from remaining active until cookie expiry.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.57,"slice":"core","lang":"en"}
{"prompt":"Create API documentation for the existing token introspection endpoint, including authentication, response fields, inactive tokens, caching, and rate limits.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.4,"slice":"boundary","lang":"en"}
{"prompt":"Plan the migration from long-lived deploy keys to GitHub OIDC federation across CI, cloud providers, package registries, and emergency workflows.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.9,"slice":"core","lang":"en"}
{"prompt":"Frontend ticket:\n\n```text\nPage: `/settings/security/sessions`\nDesktop: sortable table with device, approximate location, last active, created, actions\nMobile: stacked cards; revoke action remains visible\nCurrent session gets a `This device` badge and cannot be revoked individually\nStates: initial skeleton, no other sessions, revoke pending, revoke failed, bulk revoke confirmation\nLive behavior: websocket removes revoked sessions; events may arrive twice\nAccessibility: confirmation names the device; focus returns to heading after removal\nPrivacy: tooltip must explain approximate location\nExisting hooks: `useSessions`, `useRevokeSession`\n```\n\nImplement the page and interaction tests without changing session APIs.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.72,"slice":"pasted-context","lang":"en"}
{"prompt":"Implement `/v1/auth/recovery-codes/regenerate` with recent-authentication enforcement, atomic invalidation, and audit logging.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.6,"slice":"boundary","lang":"en"}
{"prompt":"Remove the extra slash from the callback URL","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.04,"slice":"core","lang":"en"}
{"prompt":"Fix the two-pixel jump when the password-strength bar appears and extract its duplicated height token into the shared form styles.","purpose":"quickFix","secondary":"refactor","mixed":true,"difficulty":0.37,"slice":"mixed","lang":"en"}
{"prompt":"Replace scattered login-state booleans with one explicit state machine while preserving transitions, analytics, and rendered behavior.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.67,"slice":"core","lang":"en"}
{"prompt":"Cambia `usrScope` por `userScope` solo en `AccessCheck.ts`; no modifiques la lógica.","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.06,"slice":"boundary","lang":"es"}
{"prompt":"Investigate why Firefox sometimes submits the WebAuthn registration form twice after a platform-authenticator prompt.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.64,"slice":"core","lang":"en"}
{"prompt":"Summarize the current account-recovery flow for a threat-model review, using the implementation and tests as sources.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.41,"slice":"core","lang":"en"}
{"prompt":"Develop a roadmap for centralizing authorization policy across twelve services. Include semantic inventory, compatibility tests, shadow decisions, latency budgets, ownership, and rollback gates.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.92,"slice":"core","lang":"en"}
{"prompt":"Implement signed build provenance generation and verification in the release orchestrator.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.76,"slice":"core","lang":"en"}
{"prompt":"Create the React access-policy editor with nested conditions, validation, test simulation, undo, and keyboard navigation.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.77,"slice":"core","lang":"en"}
{"prompt":"Correct `authorizaton` in the CLI help","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.03,"slice":"core","lang":"en"}
{"prompt":"Merge the duplicated token-claim normalization paths while retaining claim values, errors, and compatibility with older issuers.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.66,"slice":"core","lang":"en"}
{"prompt":"Gateway logs from the incident:\n\n```text\nrequest_id=19f route=/admin/export user=usr_88\nsession cache hit account_state=active cached_at=13:41:02\naccount disabled in primary at=13:41:05\nrevocation event published partition=7 offset=9912\nconsumer-a applied offset=9912 at=13:41:06\nconsumer-b rebalance generation=44\nrequest_id=1a0 route=/admin/export user=usr_88 node=consumer-b\nsession cache hit account_state=active cached_at=13:40:59\nresponse=200 at=13:41:18\nconsumer-b resumed partition=7 offset=9908 at=13:41:21\n```\n\nA disabled administrator retained access on one node for 16 seconds. Determine why rebalance and cache invalidation ordering allowed this and whether the fallback TTL meets the intended revocation guarantee.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.79,"slice":"pasted-context","lang":"en"}
{"prompt":"Rename the local constant `secert` to `secret`.","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.02,"slice":"boundary","lang":"en"}
{"prompt":"Assess whether the current password reset flow leaks account existence through timing, response bodies, email behavior, or rate-limit headers. No edits requested.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.71,"slice":"core","lang":"en"}
{"prompt":"Restructure the authentication SDK into transport, token storage, refresh, and session modules, then write a maintainer note describing their boundaries. Preserve public exports and behavior.","purpose":"refactor","secondary":"writing","mixed":true,"difficulty":0.78,"slice":"mixed","lang":"en"}
{"prompt":"Plan the deprecation of SMS as an account-recovery factor, covering enrollment gaps, regional constraints, support escalation, customer communication, and removal gates.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.82,"slice":"core","lang":"en"}
{"prompt":"Add tenant-scoped signing-key rotation with overlapping verification windows and generation fencing.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.75,"slice":"core","lang":"en"}
{"prompt":"Build the mobile approval queue with scope summaries, expiry warnings, batch actions, and swipe alternatives.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.61,"slice":"core","lang":"en"}
{"prompt":"do the auth screen","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.4,"slice":"vague-eval","lang":"en"}
{"prompt":"Replace `AuthCtx` with `AuthContext` throughout the web app without changing provider behavior or exported compatibility aliases.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.54,"slice":"boundary","lang":"en"}
{"prompt":"Diagnose why emailed magic links sometimes expire immediately, implement the correction after proving the clock or encoding issue, and add a support note for identifying affected links.","purpose":"debugging","secondary":"writing","mixed":true,"difficulty":0.77,"slice":"mixed","lang":"en"}
{"prompt":"Why does the CI signer upload the public certificate before the artifact? Explain the existing recovery and verification ordering; no failure is reported.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.47,"slice":"boundary","lang":"en"}
{"prompt":"Track down the memory leak in the SAML metadata refresher after repeated certificate rotations.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.72,"slice":"core","lang":"en"}
{"prompt":"Write release notes for organization-level MFA enforcement, including exemptions, rollout timing, admin actions, and user-visible errors.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.37,"slice":"core","lang":"en"}
{"prompt":"Architecture notes from the identity working group:\n\n```text\nGoal: support customer-owned identity domains\nVerification candidates: DNS TXT, HTTPS well-known file\nOne domain can belong to only one organization\nSubdomains may be claimed separately only with explicit parent policy\nVerified domains enable automatic user discovery and optional forced SSO\nDomains must be rechecked after nameserver changes\nDeletion should not instantly free a domain for another tenant\nSupport needs a reversible dispute process\nAudit must record verification attempts without storing resolver secrets\n```\n\nProduce an architecture and rollout plan covering ownership semantics, verification, caching, revalidation, takeover prevention, disputes, forced SSO safety, and migration gates. No implementation yet.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.91,"slice":"pasted-context","lang":"en"}
{"prompt":"Give the security dashboard a useful empty state","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.32,"slice":"core","lang":"en"}
{"prompt":"Turn the current administrator impersonation implementation into documentation, and separately review whether its audit, expiry, and notification behavior supports the claims in that document.","purpose":"writing","secondary":"review","mixed":true,"difficulty":0.72,"slice":"mixed","lang":"en"}
{"prompt":"Outline a phased design for moving browser sessions from Redis to a globally replicated store, without changing code yet.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.84,"slice":"boundary","lang":"en"}
{"prompt":"Implement policy-decision caching with dependency-aware invalidation and bounded stale-deny behavior.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.81,"slice":"core","lang":"en"}
{"prompt":"Create an operator guide for rotating SAML certificates without breaking active logins.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.38,"slice":"core","lang":"en"}
{"prompt":"Move nonce validation out of the callback handler into a dedicated verifier while preserving all accepted flows and errors.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.57,"slice":"core","lang":"en"}
{"prompt":"Investigate why the GitHub Actions deploy job occasionally uses credentials from the previous environment.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.73,"slice":"boundary","lang":"en"}
{"prompt":"Add replay-resistant device authorization grants with polling throttles and expiry.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.69,"slice":"core","lang":"en"}
{"prompt":"Set the idle session timeout to 30 minutes","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.08,"slice":"core","lang":"en"}
{"prompt":"Create the responsive SSO configuration wizard with metadata upload, field validation, connection testing, and recovery guidance.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.69,"slice":"core","lang":"en"}
{"prompt":"Corrige apenas `authentification` para `authentication` no novo título da documentação.","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.03,"slice":"boundary","lang":"pt"}
{"prompt":"Review the JWT verification path for algorithm confusion, duplicate claims, key selection, critical headers, and token-size limits. Report findings only.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.79,"slice":"core","lang":"en"}
{"prompt":"Implement the access-review export endpoint and write its API guide. Include filters, asynchronous generation, retention, signed downloads, permissions, examples, and audit behavior.","purpose":"backendImpl","secondary":"writing","mixed":true,"difficulty":0.72,"slice":"mixed","lang":"en"}
{"prompt":"Design a migration from shared CI runners to isolated ephemeral runners, including trust tiers, image provenance, cache policy, secret delivery, capacity, and rollout.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.89,"slice":"core","lang":"en"}
{"prompt":"Implement certificate-bound API tokens with backward-compatible bearer verification during migration.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.74,"slice":"core","lang":"en"}
{"prompt":"Build the account-recovery status page with step progress, alternate paths, support escalation, and privacy-safe messaging.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.61,"slice":"core","lang":"en"}
{"prompt":"continue yesterday's security work","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.58,"slice":"vague-eval","lang":"en"}
{"prompt":"Extract role-name canonicalization into one shared utility while preserving stored values and every authorization decision.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.55,"slice":"boundary","lang":"en"}
{"prompt":"Investigate why revoked personal access tokens continue working through the GraphQL gateway, implement the verified cache fix, and document the propagation window accurately.","purpose":"debugging","secondary":"writing","mixed":true,"difficulty":0.82,"slice":"mixed","lang":"en"}
{"prompt":"Assess the proposed OAuth device flow for phishing resistance, code entropy, polling abuse, consent clarity, and shared-device cleanup. Review only.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.71,"slice":"boundary","lang":"en"}
{"prompt":"Find why a successful SAML login occasionally creates a second user instead of linking the existing account.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.7,"slice":"core","lang":"en"}
{"prompt":"Draft the incident-response playbook for suspected signing-key compromise, including containment, rotation, invalidation, verification, and communication.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.55,"slice":"core","lang":"en"}
{"prompt":"Workflow migration brief:\n\n```text\nRepositories: 137\nCurrent: each repo owns release YAML and long-lived cloud credentials\nTarget: reusable workflow pinned by commit digest\nLanguages: Go, Node, Python, Rust\nOutputs: containers, packages, SBOMs, provenance attestations\nConstraints:\n- regulated repos require two-person approval\n- self-hosted runners exist for hardware builds\n- hotfix releases must remain possible during control-plane outage\n- teams may adopt over two quarters\n- central workflow changes cannot silently alter release semantics\n```\n\nProduce a migration roadmap with workflow contracts, compatibility testing, exception handling, credential replacement, canaries, governance, rollback, and adoption metrics.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.92,"slice":"pasted-context","lang":"en"}
{"prompt":"Add a compact layout to the permissions table","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.41,"slice":"core","lang":"en"}
{"prompt":"Restructure the session-management package and document its extension points. Preserve cookie semantics, refresh timing, revocation behavior, and public APIs while separating storage, validation, and lifecycle concerns.","purpose":"refactor","secondary":"writing","mixed":true,"difficulty":0.78,"slice":"mixed","lang":"en"}
{"prompt":"Architect a multi-region key-management service for application signing keys, including quorum operations, audit, disaster recovery, rotation, and migration milestones.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.97,"slice":"boundary","lang":"en"}
{"prompt":"Implement a streaming parser for large SAML metadata aggregates with signature and entity limits.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.73,"slice":"core","lang":"en"}
{"prompt":"Write an onboarding guide for adding a new authorization action, including naming, policy tests, audit events, and UI exposure.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.41,"slice":"core","lang":"en"}
{"prompt":"Consolidate the three CSRF token stores behind one interface without changing token scope, expiry, or rotation.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.62,"slice":"core","lang":"en"}
{"prompt":"Investigate why deployment approvals occasionally disappear when a pull request is rebased.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.66,"slice":"boundary","lang":"en"}
{"prompt":"Add transactional account locking with reason codes, expiry, and audit events.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.64,"slice":"core","lang":"en"}
{"prompt":"Pin `cosign` to `v3.0.2`","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.06,"slice":"core","lang":"en"}
{"prompt":"Build the consent-history view with policy versions, acceptance timestamps, downloadable copies, and accessible expansion.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.59,"slice":"core","lang":"en"}
{"prompt":"Remplace `Authorisation` par `Authorization` uniquement dans le nouveau libellé anglais; ne touche pas aux clés i18n.","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.05,"slice":"boundary","lang":"fr"}
{"prompt":"Inspect the emergency-access implementation and explain whether an approver can authorize their own request through nested group membership.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.69,"slice":"core","lang":"en"}
{"prompt":"Implement organization session-policy endpoints and produce integration documentation. Cover idle and absolute timeouts, exemptions, validation, propagation, examples, and old-client behavior.","purpose":"backendImpl","secondary":"writing","mixed":true,"difficulty":0.7,"slice":"mixed","lang":"en"}
{"prompt":"Develop a roadmap for enforcing signed commits and protected release tags across all repositories, including bots, mirrors, emergency bypass, and audit gates.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.87,"slice":"core","lang":"en"}
{"prompt":"Add subject-token validation and audience narrowing to the RFC 8693 exchange implementation.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.68,"slice":"core","lang":"en"}
{"prompt":"Create the responsive audit-event detail panel with structured fields, raw JSON, copy actions, and redaction indicators.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.57,"slice":"core","lang":"en"}
{"prompt":"fix the permission thing","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.49,"slice":"vague-eval","lang":"en"}
{"prompt":"Replace duplicated issuer URL cleanup with one canonicalizer, preserving accepted configurations and metadata cache keys.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.54,"slice":"boundary","lang":"en"}
{"prompt":"Diagnose why recovery-code regeneration sometimes leaves one old code valid, implement the proven transaction correction, and add a security advisory note for affected versions.","purpose":"debugging","secondary":"writing","mixed":true,"difficulty":0.83,"slice":"mixed","lang":"en"}
{"prompt":"Why does the deployment controller require a fresh approval after only a documentation commit? Explain existing path filtering and trust assumptions.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.51,"slice":"boundary","lang":"en"}
{"prompt":"Track down the occasional `invalid_state` response when two login tabs complete in reverse order.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.68,"slice":"core","lang":"en"}
{"prompt":"Write a customer migration guide from API keys to OAuth client credentials, with examples, rollout advice, and troubleshooting.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.4,"slice":"core","lang":"en"}
{"prompt":"Threat-model excerpt:\n\n```text\nFeature: support-assisted account recovery\nSupport agent verifies ticket ownership, then requests a recovery session\nSecond agent approves for enterprise accounts\nRecovery session lasts 20 minutes and permits password reset plus MFA replacement\nCustomer receives email after completion, not before\nAgent cannot see existing MFA secrets\nAll actions enter the audit log\nOpen concerns:\n- compromised support account\n- social engineering during active incident\n- approving agent collusion\n- customer mailbox compromise\n- replaying an expired recovery-session URL\n```\n\nReview the proposed flow. Identify trust assumptions, abuse cases, missing customer controls, audit requirements, and recovery-session safeguards. No implementation requested.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.82,"slice":"pasted-context","lang":"en"}
{"prompt":"Add a loading skeleton to the device list","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.24,"slice":"core","lang":"en"}
{"prompt":"Plan and implement secure webhook signing for outbound events. First define canonicalization, key distribution, rotation, replay protection, timestamp tolerance, compatibility, and rollout; then add signing, tenant key storage, verification fixtures, and tests.","purpose":"planning","secondary":"backendImpl","mixed":true,"difficulty":0.91,"slice":"mixed","lang":"en"}
{"prompt":"Outline an architecture for privacy-preserving sign-in telemetry, covering pseudonymous identifiers, retention, sampling, regional storage, incident use, and rollout.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.86,"slice":"boundary","lang":"en"}
{"prompt":"Implement rate-limited password verification with constant-time dummy work for unknown accounts.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.7,"slice":"core","lang":"en"}
{"prompt":"Write a reference page for the authorization decision log format, field meanings, retention, and privacy constraints.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.4,"slice":"core","lang":"en"}
{"prompt":"Move SAML attribute mapping out of the login handler without changing precedence, defaults, or user provisioning.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.6,"slice":"core","lang":"en"}
{"prompt":"Investigate why the production CSP report endpoint receives duplicate violations from Chromium only.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.58,"slice":"boundary","lang":"en"}
{"prompt":"Add one-time administrator elevation tokens with approval binding and five-minute expiry.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.69,"slice":"core","lang":"en"}
{"prompt":"Change the MFA grace period to 7 days","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.07,"slice":"core","lang":"en"}
{"prompt":"Build the team-members page with role filters, pending invitations, bulk removal, responsive rows, and accessible confirmations.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.61,"slice":"core","lang":"en"}
{"prompt":"Corrige `securty` para `security` apenas no novo nome da etapa do workflow.","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.03,"slice":"boundary","lang":"pt"}
{"prompt":"Review whether the OAuth callback logs can expose authorization codes, state tokens, or provider error descriptions. Report evidence only.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.63,"slice":"core","lang":"en"}
{"prompt":"Implement the API-token inventory endpoint and write its reference documentation. Include scope filtering, last-use caveats, pagination, revocation state, examples, and permissions.","purpose":"backendImpl","secondary":"writing","mixed":true,"difficulty":0.66,"slice":"mixed","lang":"en"}
{"prompt":"Design a phased migration from self-signed internal certificates to a private ACME service, including bootstrap, renewal, trust rollover, outages, and retirement.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.9,"slice":"core","lang":"en"}
{"prompt":"Add bounded replay storage for signed browser challenges with atomic consume semantics.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.63,"slice":"core","lang":"en"}
{"prompt":"Create the security-key management screen with device names, last-use metadata, rename, removal, and lost-key guidance.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.6,"slice":"core","lang":"en"}
{"prompt":"keep going on the UI","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.41,"slice":"vague-eval","lang":"en"}
{"prompt":"Rename `PermSet` to `PermissionSet` across packages while preserving serialized type names and public aliases.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.57,"slice":"boundary","lang":"en"}
{"prompt":"Investigate the flaky CI signature verification on macOS runners, implement the verified timestamp or keychain correction, and document diagnostic steps for release engineers.","purpose":"debugging","secondary":"writing","mixed":true,"difficulty":0.79,"slice":"mixed","lang":"en"}
{"prompt":"Assess the proposal to put authorization scopes directly into CDN cache keys. Cover leakage, cardinality, stale grants, revocation, and correctness.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.67,"slice":"boundary","lang":"en"}
{"prompt":"Find why group membership updates occasionally take ten minutes to affect GraphQL field authorization.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.7,"slice":"core","lang":"en"}
{"prompt":"Draft a troubleshooting guide for SSO redirect loops, covering cookies, issuer mismatch, clock skew, proxies, and useful logs.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.4,"slice":"core","lang":"en"}
{"prompt":"Release pipeline logs:\n\n```text\nartifact=desktop-client-8.1.0.dmg sha256=8c9e...21a\ncodesign verification=success\nnotarization status=Accepted request=7f92\nattestation subject digest=8c9e...21a\nupload multipart started artifact digest=8c9e...21a\npart 12 retry after 503\nupload completed remote digest=0d74...bc1\npromotion policy: attestation subject found=true\nchannel stable updated to remote object\nclient download checksum mismatch expected=8c9e...21a actual=0d74...bc1\n```\n\nDetermine how the promoted remote object acquired a different digest while the policy still accepted the original attestation. Trace multipart retry, finalization, and subject-to-object binding.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.86,"slice":"pasted-context","lang":"en"}
{"prompt":"Add a copied state to the client-secret button","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.22,"slice":"core","lang":"en"}
{"prompt":"Restructure the policy compiler and document its intermediate representation. Preserve all decisions and diagnostics while separating parsing, normalization, optimization, and evaluation.","purpose":"refactor","secondary":"writing","mixed":true,"difficulty":0.81,"slice":"mixed","lang":"en"}
{"prompt":"Architect a secure delegated-administration model for resellers, including tenant boundaries, constrained roles, approval, audit, incident containment, and milestones.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.94,"slice":"boundary","lang":"en"}
{"prompt":"Implement Merkle-tree transparency proofs for signing-key publication.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.83,"slice":"core","lang":"en"}
{"prompt":"Create a maintainer guide for testing authentication changes across browsers, reverse proxies, and identity providers.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.43,"slice":"core","lang":"en"}
{"prompt":"Extract token-expiry calculations into a shared clock-aware module without changing rounding or grace periods.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.56,"slice":"core","lang":"en"}
{"prompt":"Investigate why the access-request badge remains stale after an approver rejects the request.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.56,"slice":"boundary","lang":"en"}
{"prompt":"Add per-organization login rate limits with trusted-proxy-aware client keys.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.67,"slice":"core","lang":"en"}
{"prompt":"Set the JWKS cache TTL to 10 minutes","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.08,"slice":"core","lang":"en"}
{"prompt":"Build the responsive login-history page with device grouping, anomaly flags, filters, and privacy explanations.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.62,"slice":"core","lang":"en"}
{"prompt":"把新页面里的 `Permisions` 改成 `Permissions`,不要改 i18n key。","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.04,"slice":"boundary","lang":"zh"}
{"prompt":"Inspect the account-linking code for session fixation, confused-deputy flows, email reassignment, and provider-subject collisions. No patch requested.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.78,"slice":"core","lang":"en"}
{"prompt":"Implement security-event subscriptions and write the integration guide. Include event types, filtering, webhook signatures, retries, ordering, retention, and examples.","purpose":"backendImpl","secondary":"writing","mixed":true,"difficulty":0.72,"slice":"mixed","lang":"en"}
{"prompt":"Plan a disaster-recovery strategy for identity services, including key material, session stores, provider metadata, regional failover, drills, and RTO tiers.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.92,"slice":"core","lang":"en"}
{"prompt":"Add deterministic policy traces with redacted inputs and stable decision-step IDs.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.7,"slice":"core","lang":"en"}
{"prompt":"Create the admin invitation flow with role preview, expiry, domain warnings, resend states, and accessible validation.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.59,"slice":"core","lang":"en"}
{"prompt":"do the cleanup from yesterday","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.42,"slice":"vague-eval","lang":"en"}
{"prompt":"Replace `IDPConfig` with `IdentityProviderConfig` across the codebase while preserving API field names and stored configuration.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.59,"slice":"boundary","lang":"en"}
{"prompt":"Diagnose why session revocation misses websocket connections, implement the verified lifecycle fix, and update the operator documentation with actual propagation guarantees.","purpose":"debugging","secondary":"writing","mixed":true,"difficulty":0.82,"slice":"mixed","lang":"en"}
{"prompt":"Explain whether a user can retain inherited access after their group is deleted. Review transaction and cache behavior only.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.62,"slice":"boundary","lang":"en"}
{"prompt":"Track down the occasional invalid signature from the key service immediately after rotation.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.74,"slice":"core","lang":"en"}
{"prompt":"Write a concise architecture overview of the existing identity platform for new backend engineers.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.4,"slice":"core","lang":"en"}
{"prompt":"Security review packet:\n\n```text\nFeature: shareable support-session link\nCreator: authenticated customer administrator\nRecipient: support agent\nLink grants read-only access to selected diagnostic pages for 60 minutes\nToken appears in URL fragment and is exchanged for a session cookie\nAdministrator can revoke early\nSupport identity is recorded during exchange\nLink may be opened only once\nDiagnostics can include usernames, IP addresses, and configuration values\nCurrent mockup has a Copy link button but no recipient confirmation\n```\n\nReview the design for link leakage, forwarding, one-time semantics, recipient binding, sensitive-data scope, revocation, audit, browser history, and administrator expectations. Do not implement.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.77,"slice":"pasted-context","lang":"en"}
{"prompt":"Add spacing between the recovery options","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.13,"slice":"core","lang":"en"}
{"prompt":"Plan and implement organization-managed encryption keys for audit exports. Define trust, envelope encryption, rotation, access loss, validation, migration, and support boundaries first; then add the key configuration and export encryption paths.","purpose":"planning","secondary":"backendImpl","mixed":true,"difficulty":0.94,"slice":"mixed","lang":"en"}
{"prompt":"Design a phased roadmap for moving authorization checks from application code into a policy sidecar, including latency, availability, version skew, shadowing, and rollback.","purpose":"planning","secondary":null,"mixed":false,"difficulty":0.91,"slice":"boundary","lang":"en"}
{"prompt":"Implement refresh-token binding to device-held keys with migration support for existing sessions.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.79,"slice":"core","lang":"en"}
{"prompt":"Écris une page de référence pour les erreurs OAuth renvoyées par notre API, avec causes, sécurité et actions recommandées.","purpose":"writing","secondary":null,"mixed":false,"difficulty":0.36,"slice":"core","lang":"fr"}
{"prompt":"Consolidate the two policy-test harnesses without changing fixtures, traces, or assertion output.","purpose":"refactor","secondary":null,"mixed":false,"difficulty":0.61,"slice":"core","lang":"en"}
{"prompt":"Investigate why Safari ignores the `Clear-Site-Data` header during logout in our embedded app flow.","purpose":"debugging","secondary":null,"mixed":false,"difficulty":0.67,"slice":"boundary","lang":"en"}
{"prompt":"Add idempotent invitation acceptance with email-change protection and audit events.","purpose":"backendImpl","secondary":null,"mixed":false,"difficulty":0.64,"slice":"core","lang":"en"}
{"prompt":"Remove the obsolete `oauth_beta` label","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.04,"slice":"core","lang":"en"}
{"prompt":"Build the policy-simulator result view with decision steps, matched rules, redacted inputs, and copyable diagnostics.","purpose":"frontendImpl","secondary":null,"mixed":false,"difficulty":0.64,"slice":"core","lang":"en"}
{"prompt":"`Authenticaton` を `Authentication` に修正して。新しい設定カードの見出しだけです。","purpose":"quickFix","secondary":null,"mixed":false,"difficulty":0.03,"slice":"boundary","lang":"ja"}
{"prompt":"Review the CI cache configuration for opportunities to poison build outputs across forks, branches, or trust levels. Report findings only.","purpose":"review","secondary":null,"mixed":false,"difficulty":0.76,"slice":"core","lang":"en"}
{"prompt":"Implement administrator-consent records and write the API documentation. Include policy version, scope set, actor, expiry, revocation, pagination, examples, and permissions.","purpose":"backendImpl","secondary":"writing","mixed":true,"difficulty":0.7,"slice":"mixed","lang":"en"}