Skip to content

Harden preview budgets, cache variants, and moderator guards - #267

Merged
admdly merged 8 commits into
mainfrom
fix/several
Oct 6, 2026
Merged

admdly merged 8 commits into
mainfrom
fix/several

Conversation

@admdly

@admdly admdly commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary by cubic

Harden preview rate limits and abbreviated-SHA resolution, enforce moderator authority at write time, and bound versions/v1 cache variants.

Previews API

  • Client burst drops to 12 (global stays 60); each request gets an 8-call subrequest ceiling shared across PR head, artifact fallback, main enrichment, and live download redirects.
  • Client identity is normalized to IPv4, IPv6 /64, or unknown before hashing; invalid or missing addresses share one allowance.
  • Abbreviated SHA lookups scan all artifact pages to establish uniqueness: collisions return 409 AMBIGUOUS_COMMIT, incomplete scans return 503, and prefix results bypass KV reads/writes (including legacy entries).
  • The 409 error is only exposed on /commit/{sha}; PR routes resolve full SHAs, so their contract omits it.
  • Full-SHA lookups and caching are unchanged.

Extensions v2 and versions

  • Approvals, rejections, and delists require the actor to still be an active moderator when the write commits, returning FORBIDDEN or ACCOUNT_INACTIVE correctly.
  • versions/v1 collapses mirror-trust User-Agent values into two classes before cache keying, so trusted and untrusted clients share entries while preserving Vary: User-Agent.

Written for commit 9ce57ee. Summary will update on new commits.

Turn on auto-fix

admdly added 5 commits October 4, 2026 23:17
Reduce preview GitHub rate-limit burst capacity to 12 per client (while keeping global burst 60), with bucket capacities enforced per key and legacy balances clamped. Add request-level subrequest budgeting (max 8 calls) and normalized client identity hashing (IPv4, IPv6 /64, IPv4-mapped IPv6, invalid/missing fallback) to prevent one cold lookup or caller from exhausting shared budget. Update previews v1 docs and expand tests for new limits, identity sharing, concurrent reserve behavior, and durable-object bucket isolation/reset in route tests.
Normalize mirror-trust User-Agent classes before public cache lookup so trusted and untrusted clients share a single cached entry per semantic variant. This keeps /versions responses consistent while preserving the User-Agent Vary contract and conditional request behavior. The change also adds regression tests covering root, latest, and version endpoints across both cache classes.
Tighten extensions v2 moderation and ownership writes so approvals, rejections, and delisting now require the actor to still be an active moderator at commit time, not just when the request starts. This adds a shared `moderatorActorError` path, updates SQL guards and route status mapping to return `FORBIDDEN` vs `ACCOUNT_INACTIVE` correctly, and adds regression coverage for moderators being demoted or deactivated mid-request.
@admdly admdly self-assigned this Oct 6, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
api 9ce57ee Oct 06 2026, 07:18 PM

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-06T18:52:41.827601Z 28d3114 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 23 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread src/services/previews/v1/README.md Outdated
Comment thread src/services/previews/v1/routes/pr.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 4 files (changes from recent commits).

Requires human review: Hardens preview rate-limiting and SHA resolution, enforces moderator authority at write time, and changes versions caching and the public commit-SHA contract; these operational, authorization, and API tradeoffs require human sign-off.

Turn on auto-fix | Re-trigger cubic

@admdly
admdly merged commit 7fcad0b into main Oct 6, 2026
9 checks passed
@admdly
admdly deleted the fix/several branch October 6, 2026 19:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant