Repository navigation
Bound extension writes and revision history resources - #268
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
api | 61da131 | Oct 06 2026, 11:53 PM |
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 31 files
Requires human review: Auto-approval blocked because this review re-detected 7 unresolved issues already reported by Cubic.
Turn on auto-fix | Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 16 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Requires human review: Adds resource quotas, rate limiting, retention compaction, and a D1 migration with a breaking revision-list/detail contract. Needs human sign-off on quota/retention policy, schema migration, and API contract changes.
Turn on auto-fix | Re-trigger cubic
Extension writes can accumulate retained history and amplify moderation reads. This change bounds raw request bodies and accepted writes per account/developer, tracks retained bytes and record counts transactionally, and returns metadata-only revision lists with authorized content fetched on demand. Aggregate usage is measured without imposing whole-system admission caps.
Reviewed history can be compacted in bounded batches while preserving pending and published bodies, audit metadata and content hashes. Retention defaults to dry-run. Cleanup and inventory logging share one hourly cron; oversized legacy content remains stored and is guarded before reads.
Configuration and compatibility
0026_resource_bounds.sqlfor accounting, accepted-write events and retention metadata.EXTENSION_WRITE_RATE_LIMITERbinding, one hourly maintenance/inventory cron trigger, andEXTENSIONS_RETENTION_MODE=dry-runinwrangler.jsonc.503withRetry-After; rate exhaustion returns429, and retained quotas return409.