Background
openedx-core is adding the Competency-Based Education (CBE) data models under its openedx_learning
app. openedx/openedx-core#641 adds the criteria definition models, openedx/openedx-core#642 adds the
mastery status lookup and the learner progress models, and openedx/openedx-core#613 is the parent
issue covering both.
This repo runs a PII annotation check that requires every active Django model to be labelled as
containing personal data or not. That check only scans this repo's own tree: .pii_annotations.yml
sets source_path: ./, so it never reads models inside installed site-packages. A model is still
covered, without a safelist entry here, when the annotation lives as a .. no_pii: (or other) token
anywhere in that model's MRO docstrings, including a docstring written in the installed package's own
source. Seven of the ten models #641 and #642 add are annotated that way in openedx-core itself, so
they need no entry here, and adding one would be a lint error: a model with both an inline annotation
and a safelist entry is flagged as double-covered.
The remaining three are django-simple-history's generated Historical* shadow models for
CompetencyCriteriaGroup, CompetencyCriterion and CompetencyRuleProfile. Django's history package
generates these with an auto-generated "Name(field, field)" docstring and no annotation token
anywhere in their MRO, so a safelist entry is the only way to cover them. This repo already does the
same for other installed-package history models, organizations.HistoricalOrganization among them.
openedx/openedx-platform#38958 added this app's first safelist entry, openedx_learning.CompetencyTaxonomy,
for the same reason, before taxonomy_overrides_org turned that model's annotation inline too.
What to do
Add three entries to .annotation_safe_list.yml, each annotated as containing no PII, in the same
shape as the existing organizations.HistoricalOrganization entry:
openedx_learning.HistoricalCompetencyCriteriaGroup:
".. no_pii:": "No PII"
The three models, all generated by django-simple-history for models openedx/openedx-core#641 adds:
openedx_learning.HistoricalCompetencyCriteriaGroup
openedx_learning.HistoricalCompetencyCriterion
openedx_learning.HistoricalCompetencyRuleProfile
None of the ten models #641 and #642 add stores personal data of its own. The Historical* models
shadow their source models field-for-field and carry no PII beyond what those source models already
don't carry.
Not in scope
The other seven models from #641 and #642 (CompetencyCriteriaGroup, CompetencyCriterion,
CompetencyRuleProfile, CompetencyMasteryStatuses, StudentCompetencyCriteriaStatus,
StudentCompetencyCriteriaGroupStatus, StudentCompetencyStatus). Each carries its own inline
.. no_pii: docstring annotation in openedx-core's source, so code_annotations' MRO docstring
lookup covers them once the package is installed. Adding a safelist entry for any of them here would
be a lint error.
Ordering constraint
This does not need to land in the same pull request as the openedx-core pin bump, and does not need
to wait for it. Entries for models that aren't installed yet are inert: code_annotations only flags
a safelist entry as unused for a model it finds registered and uninstalled in this repo's own
configuration, and none of these three names resolves to anything at all here before the pin bump.
Landing this ahead of time means the pin-bump PR doesn't have to carry a safelist change of its own.
Acceptance criteria
Blocked by
None. This can merge ahead of openedx/openedx-core#641 and openedx/openedx-core#642.
Background
openedx-core is adding the Competency-Based Education (CBE) data models under its
openedx_learningapp. openedx/openedx-core#641 adds the criteria definition models, openedx/openedx-core#642 adds the
mastery status lookup and the learner progress models, and openedx/openedx-core#613 is the parent
issue covering both.
This repo runs a PII annotation check that requires every active Django model to be labelled as
containing personal data or not. That check only scans this repo's own tree:
.pii_annotations.ymlsets
source_path: ./, so it never reads models inside installed site-packages. A model is stillcovered, without a safelist entry here, when the annotation lives as a
.. no_pii:(or other) tokenanywhere in that model's MRO docstrings, including a docstring written in the installed package's own
source. Seven of the ten models #641 and #642 add are annotated that way in openedx-core itself, so
they need no entry here, and adding one would be a lint error: a model with both an inline annotation
and a safelist entry is flagged as double-covered.
The remaining three are
django-simple-history's generatedHistorical*shadow models forCompetencyCriteriaGroup,CompetencyCriterionandCompetencyRuleProfile. Django's history packagegenerates these with an auto-generated
"Name(field, field)"docstring and no annotation tokenanywhere in their MRO, so a safelist entry is the only way to cover them. This repo already does the
same for other installed-package history models,
organizations.HistoricalOrganizationamong them.openedx/openedx-platform#38958added this app's first safelist entry,openedx_learning.CompetencyTaxonomy,for the same reason, before
taxonomy_overrides_orgturned that model's annotation inline too.What to do
Add three entries to
.annotation_safe_list.yml, each annotated as containing no PII, in the sameshape as the existing
organizations.HistoricalOrganizationentry:The three models, all generated by
django-simple-historyfor models openedx/openedx-core#641 adds:openedx_learning.HistoricalCompetencyCriteriaGroupopenedx_learning.HistoricalCompetencyCriterionopenedx_learning.HistoricalCompetencyRuleProfileNone of the ten models #641 and #642 add stores personal data of its own. The
Historical*modelsshadow their source models field-for-field and carry no PII beyond what those source models already
don't carry.
Not in scope
The other seven models from #641 and #642 (
CompetencyCriteriaGroup,CompetencyCriterion,CompetencyRuleProfile,CompetencyMasteryStatuses,StudentCompetencyCriteriaStatus,StudentCompetencyCriteriaGroupStatus,StudentCompetencyStatus). Each carries its own inline.. no_pii:docstring annotation in openedx-core's source, socode_annotations' MRO docstringlookup covers them once the package is installed. Adding a safelist entry for any of them here would
be a lint error.
Ordering constraint
This does not need to land in the same pull request as the
openedx-corepin bump, and does not needto wait for it. Entries for models that aren't installed yet are inert:
code_annotationsonly flagsa safelist entry as unused for a model it finds registered and uninstalled in this repo's own
configuration, and none of these three names resolves to anything at all here before the pin bump.
Landing this ahead of time means the pin-bump PR doesn't have to carry a safelist change of its own.
Acceptance criteria
.annotation_safe_list.ymlmake pii_checkpasses, both before and after theopenedx-corepin inrequirements/edx/base.txtis bumped to a version containingCompetency criteria models (authoring/definition layer) openedx-core#641 and Mastery status lookup + learner progress models openedx-core#642
Blocked by
None. This can merge ahead of openedx/openedx-core#641 and openedx/openedx-core#642.