Fix several findings - #263
Conversation
Introduce a dedicated `identity-sync` bearer assertion flow with a required signed `body_sha256` claim, and allow `requireAuth` to accept route-specific verifiers. The extensions identity sync middleware now validates exact request bytes against the signed digest, keeps these proofs scoped to the sync endpoint, and enforces a one-hour cap on stored GitHub org evidence freshness. Documentation and tests were expanded to cover the new auth model, tamper cases, raw-body integrity, secret rotation, and helper utilities.
Introduce a D1-backed claim verification budget system for ownership claims, with atomic reservation across three limits: per-account, per-normalized-developer, and a global hourly cap. Claim creation now checks this budget before GitHub verification and returns RATE_LIMITED/429 when exhausted, while preserving existing duplicate-claim behavior. This adds migration 0024, schema/table wiring, and a new budget reservation helper, updates ownership route 429 docs and service README guidance (including deployment order), and expands tests to cover mismatches, cancellation, upstream failures, fail-closed writes, normalization sharing, aggregate limits, concurrency atomicity, expiry renewal, and fixture cleanup.
Introduce a Durable Object-backed token bucket for previews GitHub traffic, with shared global and per-client limits enforced before upstream requests. Thread the budgeted GitHub helper through preview lookup and download routes, document the behavior, add coverage for exhaustion and refill cases, and register the new binding/migration in Wrangler and worker types.
This change makes GET /central-alerts/v1/list behave as a public, cacheable endpoint. It normalizes equivalent pagination inputs to the same effective page, validates offset/limit rules before lookup, and caches successful 200 responses by page value instead of by arbitrary auth headers. It also ensures validation errors and DB failures are uncached and non-public, while preserving the legacy full-list contract when no usable pagination is supplied. The README documents the newly supported pagination and cache semantics.
Add a 20-write rolling 24-hour budget for `PUT /developers/me`, enforced atomically from `developer_history` with a new `(changed_by, changed_at)` index and migration. No-op profile replays now return success without changing approval, writing audit history, or triggering catalogue revalidation, while real edits still invalidate approval as needed. Tests and service docs were updated to cover concurrency, field comparison, retained budget after deletion, and the new 429 `PROFILE_MUTATION_RATE_LIMITED` response.
Add a new `publicResponseCache` helper that strips `Authorization` only for cache keying, then restores the original request for handlers and error paths. Versions, stats, and central-alerts now use this middleware so public responses still hit edge cache even when clients send unused credentials, and cached routes apply `etag()` before caching to keep conditional requests working on cache hits. Tests were updated to reflect the new behavior, including a shared `isolateEdgeCache` utility that namespaces Cache API entries per test to avoid cross-test contamination. Service READMEs were also updated to document that unused Authorization headers no longer bypass public edge caching.
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
api | 0449150 | Oct 04 2026, 07:59 PM |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Suppress the shared auth warning for sibling-purpose assertions, harden the identity-sync body read, coalesce main enrichment per commit SHA, fix drizzle bookkeeping via generate (0025), and tighten tests and docs.
There was a problem hiding this comment.
All reported issues were addressed across 13 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Requires human review: Adds claim-verification and profile-write budgets, signed identity-sync auth, preview GitHub token buckets, and edge-cache changes across services, plus D1 migrations 0024/0025; the quota, auth-contract, and migration choices need human sign-off.
Re-trigger cubic
Summary by cubic
Fixes several security, rate-limiting, and caching findings across the extensions, previews, central-alerts, versions, and stats services, and tightens the identity-sync auth model.
Rate limits and budgets
PUT /developers/meis capped at 20 writes per rolling 24 hours and coalesces identical replays without changing approval, history, or catalogue revalidation.PreviewGitHubBudgetDurable Object binding and migration.Auth and caching
identity-syncassertion carrying a signedbody_sha256claim; these proofs only authorize the sync route, GitHub org evidence expires within one hour, and unreadable bodies return 400.Written for commit 0449150. Summary will update on new commits.