Skip to content

Fix several findings - #263

Merged
admdly merged 10 commits into
mainfrom
fix/several
Oct 4, 2026
Merged

admdly merged 10 commits into
mainfrom
fix/several

Conversation

@admdly

@admdly admdly commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary by cubic

Fixes several security, rate-limiting, and caching findings across the extensions, previews, central-alerts, versions, and stats services, and tightens the identity-sync auth model.

Rate limits and budgets

  • Claim verification reserves tokens from per-account, per-developer, and global D1-backed budgets before calling GitHub; exhausted claims return 429.
  • PUT /developers/me is capped at 20 writes per rolling 24 hours and coalesces identical replays without changing approval, history, or catalogue revalidation.
  • All previews GitHub requests draw from a Durable Object token bucket with a 60-call burst and per-client and global refills; main enrichment lookups are coalesced per commit SHA.
  • Adds D1 migrations 0024 (claim verification budgets) and 0025 (developer history index) plus the PreviewGitHubBudget Durable Object binding and migration.

Auth and caching

  • Identity sync now requires a dedicated identity-sync assertion carrying a signed body_sha256 claim; these proofs only authorize the sync route, GitHub org evidence expires within one hour, and unreadable bodies return 400.
  • Versions, stats, and central-alerts public GETs edge-cache even when clients send unused Authorization headers; handlers still see the original request.
  • Central alerts pagination normalizes equivalent inputs, rejects invalid offsets before lookup, and caches successful pages by effective page.

Written for commit 0449150. Summary will update on new commits.

admdly added 7 commits October 4, 2026 19:12
Introduce a dedicated `identity-sync` bearer assertion flow with a required signed `body_sha256` claim, and allow `requireAuth` to accept route-specific verifiers. The extensions identity sync middleware now validates exact request bytes against the signed digest, keeps these proofs scoped to the sync endpoint, and enforces a one-hour cap on stored GitHub org evidence freshness. Documentation and tests were expanded to cover the new auth model, tamper cases, raw-body integrity, secret rotation, and helper utilities.
Introduce a D1-backed claim verification budget system for ownership claims, with atomic reservation across three limits: per-account, per-normalized-developer, and a global hourly cap. Claim creation now checks this budget before GitHub verification and returns RATE_LIMITED/429 when exhausted, while preserving existing duplicate-claim behavior.

This adds migration 0024, schema/table wiring, and a new budget reservation helper, updates ownership route 429 docs and service README guidance (including deployment order), and expands tests to cover mismatches, cancellation, upstream failures, fail-closed writes, normalization sharing, aggregate limits, concurrency atomicity, expiry renewal, and fixture cleanup.
Introduce a Durable Object-backed token bucket for previews GitHub traffic, with shared global and per-client limits enforced before upstream requests. Thread the budgeted GitHub helper through preview lookup and download routes, document the behavior, add coverage for exhaustion and refill cases, and register the new binding/migration in Wrangler and worker types.
This change makes GET /central-alerts/v1/list behave as a public, cacheable endpoint. It normalizes equivalent pagination inputs to the same effective page, validates offset/limit rules before lookup, and caches successful 200 responses by page value instead of by arbitrary auth headers.

It also ensures validation errors and DB failures are uncached and non-public, while preserving the legacy full-list contract when no usable pagination is supplied. The README documents the newly supported pagination and cache semantics.
Add a 20-write rolling 24-hour budget for `PUT /developers/me`, enforced atomically from `developer_history` with a new `(changed_by, changed_at)` index and migration. No-op profile replays now return success without changing approval, writing audit history, or triggering catalogue revalidation, while real edits still invalidate approval as needed. Tests and service docs were updated to cover concurrency, field comparison, retained budget after deletion, and the new 429 `PROFILE_MUTATION_RATE_LIMITED` response.
Add a new `publicResponseCache` helper that strips `Authorization` only for cache keying, then restores the original request for handlers and error paths. Versions, stats, and central-alerts now use this middleware so public responses still hit edge cache even when clients send unused credentials, and cached routes apply `etag()` before caching to keep conditional requests working on cache hits.

Tests were updated to reflect the new behavior, including a shared `isolateEdgeCache` utility that namespaces Cache API entries per test to avoid cross-test contamination. Service READMEs were also updated to document that unused Authorization headers no longer bypass public edge caching.
@admdly admdly self-assigned this Oct 4, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
api 0449150 Oct 04 2026, 07:59 PM

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-04T19:41:36.767174Z d8d91ff PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread src/lib/auth/bearer-assertion.ts
Comment thread src/services/previews/v1/github/request.ts
Comment thread src/services/extensions/v2/db/migrations/0024_profile_history_budget.sql Outdated
Comment thread src/services/extensions/v2/db/developer-claims.ts
Comment thread test/lib/cache.test.ts Outdated
Comment thread src/services/extensions/v2/middleware.ts Outdated
Comment thread src/services/previews/v1/routes/main.ts Outdated
Comment thread test/services/extensions/v2/developer-profiles.test.ts Outdated
Comment thread test/utils/isolate-edge-cache.ts Outdated
Comment thread src/services/central-alerts/v1/README.md
Suppress the shared auth warning for sibling-purpose assertions, harden the identity-sync body read, coalesce main enrichment per commit SHA, fix drizzle bookkeeping via generate (0025), and tighten tests and docs.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 13 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread src/services/extensions/v2/middleware.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Requires human review: Adds claim-verification and profile-write budgets, signed identity-sync auth, preview GitHub token buckets, and edge-cache changes across services, plus D1 migrations 0024/0025; the quota, auth-contract, and migration choices need human sign-off.

Re-trigger cubic

@admdly
admdly merged commit b1762d8 into main Oct 4, 2026
9 checks passed
@admdly
admdly deleted the fix/several branch October 4, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant