Repository navigation
Harden preview budgets, cache variants, and moderator guards - #267
Conversation
Reduce preview GitHub rate-limit burst capacity to 12 per client (while keeping global burst 60), with bucket capacities enforced per key and legacy balances clamped. Add request-level subrequest budgeting (max 8 calls) and normalized client identity hashing (IPv4, IPv6 /64, IPv4-mapped IPv6, invalid/missing fallback) to prevent one cold lookup or caller from exhausting shared budget. Update previews v1 docs and expand tests for new limits, identity sharing, concurrent reserve behavior, and durable-object bucket isolation/reset in route tests.
Normalize mirror-trust User-Agent classes before public cache lookup so trusted and untrusted clients share a single cached entry per semantic variant. This keeps /versions responses consistent while preserving the User-Agent Vary contract and conditional request behavior. The change also adds regression tests covering root, latest, and version endpoints across both cache classes.
Tighten extensions v2 moderation and ownership writes so approvals, rejections, and delisting now require the actor to still be an active moderator at commit time, not just when the request starts. This adds a shared `moderatorActorError` path, updates SQL guards and route status mapping to return `FORBIDDEN` vs `ACCOUNT_INACTIVE` correctly, and adds regression coverage for moderators being demoted or deactivated mid-request.
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
api | 9ce57ee | Oct 06 2026, 07:18 PM |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
All reported issues were addressed across 23 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
There was a problem hiding this comment.
0 issues found across 4 files (changes from recent commits).
Requires human review: Hardens preview rate-limiting and SHA resolution, enforces moderator authority at write time, and changes versions caching and the public commit-SHA contract; these operational, authorization, and API tradeoffs require human sign-off.
Turn on auto-fix | Re-trigger cubic
Summary by cubic
Harden preview rate limits and abbreviated-SHA resolution, enforce moderator authority at write time, and bound
versions/v1cache variants.Previews API
/64, or unknown before hashing; invalid or missing addresses share one allowance.AMBIGUOUS_COMMIT, incomplete scans return 503, and prefix results bypass KV reads/writes (including legacy entries)./commit/{sha}; PR routes resolve full SHAs, so their contract omits it.Extensions v2 and versions
FORBIDDENorACCOUNT_INACTIVEcorrectly.versions/v1collapses mirror-trustUser-Agentvalues into two classes before cache keying, so trusted and untrusted clients share entries while preservingVary: User-Agent.Written for commit 9ce57ee. Summary will update on new commits.