Conversation
Require a persisted recovery-code burn before creating a session. Cover repeated write failures with fresh user reads and real PostgreSQL, then verify recovery after storage succeeds and rejection of code reuse. Closes #228
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughRecovery-code login now fails if the service cannot persist code consumption. Unit and integration tests cover failed persistence, successful consumption, and reuse of a consumed code. ChangesRecovery code login
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to Recovery-code login now fails closed when consumption cannot be saved. The regressions cover failure and recovery behavior; the change is mergeable subject to required CI passing. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
Change
Recovery-code login now returns
invalid_mfa_codewhen persisting the consumed code fails, before creating a session or recording a successful login. Previously, each fresh database read restored the unburned hash and the same code could repeatedly authorize a session during a write failure.Closes #228.
Verification
go build ./..., CI-pinned golangci-lint 2.10.1 for root and integration-tagged auth, and normal commit hooks passed.Independent adversarial review: approved, no actionable findings, reviewed commit
cd62a3b4507f18f5fc90b43bdf5b69e8e0a578cf. Two implementation passes plus final committed-SHA verification used the user-authorized Astra reviewer in place of unavailable Opus. Local evidence covers synthetic accounts on real PostgreSQL, not production services. CodeRabbit is replaced by the authorized independent local review for this SHA; required CI remains a merge gate.Scope
The guarantee is that failed recovery-code persistence cannot authorize a login. Pre-existing concurrent consumption and stale whole-row recovery writes are separate residual risks; this change does not claim atomic consumption. The recovery-persistence test item in #263 is covered, but its other test gaps remain open.
Summary by CodeRabbit