mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-07 08:06:37 +08:00
53ae3007d0
* autoresearch iter 23: fail-closed auth guarding for user/message_gateway Both plugins resolve contracts.AuthService in Apply to build their route middleware, but declared only DBService in Inject(). The kernel gates a plugin's Apply solely on declared deps, and cmd/app.go registers user before auth, so user mounted first, core.Inject failed, and loginMW silently degraded to a pass-through closure — leaving /api/v1/user change-password, profile and access-tokens unguarded. message_gateway was saved only by its later list position. Declare AuthService in Inject() for both, and pin the property with a reconcile-level test that mirrors production registration order and asserts the real auth middleware reaches the route table. * autoresearch iter 24: make auth middleware fallbacks fail closed user, message_gateway and admin each fell back to a c.Next() closure when contracts.AuthService could not be resolved, so a route would be served as if authenticated. For admin this is reachable at runtime: OnDispose calls service.ResetServices(), which nils the global the per-request guard reads, so requests still in flight during dispose bypass authorization entirely. Add ginutil.AuthUnavailable() and bind every fallback to it, with a test that drives each plugin's registered guard without an auth service present and asserts the request is aborted rather than passed through. * chore(autoresearch): log iter 23 (fail-open auth ordering, proven) * autoresearch iter 24 follow-up: let staticcheck infer the auth guard type * docs(autoresearch): log iters 24-25 and lessons 9-11 (declared-dep bug class, gate discipline)
4.0 KiB
4.0 KiB
| 1 | iteration | commit | metric | delta | status | guard | description |
|---|---|---|---|---|---|---|---|
| 2 | 0 | - | 102 | 0.0 | baseline | pass | initial measurement (pinned yardstick: repo gate + real-risk analyzers) |
| 3 | 1 | 1c5731b | 100 | -2.0 | keep | pass | core: Using2/Using3 now wrap dependency causes via errors.Join (proven: test fails on revert) |
| 4 | 2 | 37ad586 | 95 | -5.0 | keep | pass | sentinel == comparisons -> errors.Is across admin/upload/cap-pow (5 sites) |
| 5 | 3 | 686e3ef | 93 | -2.0 | keep | pass | filesrv.AbortUploadRecordError dedups error mapping + errors.As (2 sites, drops dead ErrInvalidUploadID) |
| 6 | 4 | 7e6b9e7 | 93 | 0.0 | keep | pass | PROVEN FIX: singleflight image generation no longer dies with the first caller canceled ctx (test fails on revert) |
| 7 | 6 | ce33997 | 92 | -1.0 | keep | pass | BUGFIX admin logs: negative cursor was accepted (bool ignored by callers) -> error-only contract; proven via revert (compile-level) + contract test |
| 8 | 7 | c66399e | 89 | -3.0 | keep | pass | push channels share title/content/level extraction (3 dead inits gone, ~20 fewer lines) |
| 9 | 8 | 18820b1 | 89 | 0.0 | keep | pass | BUGFIX push: synthesized notification content had random field order (map iteration); sorted keys, test observed failing pre-fix |
| 10 | 9 | 22ecafd | 87 | -2.0 | keep | pass | unparam: always-nil error returns dropped, 4 unreachable branches removed |
| 11 | 10 | c4068ef | 84 | -3.0 | keep | pass | errorlint cleared to 0: %%w at push test + telegram fallback, errors.As in config loader |
| 12 | 11 | 3d2038a | 80 | -4.0 | keep | pass | nilnil: unimplemented auth mocks now return a sentinel instead of (nil,nil) |
| 13 | 12 | 101cb2f | 79 | -1.0 | keep | pass | nilnil: inproc driver GetExecution returns error, matching asynq driver semantics |
| 14 | 14 | 6932b54 | 79 | 0.0 | keep | pass | DATA-LOSS BUGFIX: cache read error no longer clobbers buffered task log (proven: assertion fails on revert) |
| 15 | 15 | 2c41563 | 79 | 0.0 | keep | pass | PERF: CORS origin check no longer hits DB per request (5s cached read); proven - loader count 0 vs 1 on revert |
| 16 | 16 | 976f9b1 | 79 | 0.0 | keep | pass | PERF: contract-level batch user lookup replaces N+1 in access-log enrichment (test proves 1 query vs 3) |
| 17 | 17 | 1b1c452 | 79 | 0.0 | keep | pass | BUGFIX: orphan cron message_gateway:cleanup_pairing_codes now has a handler; invariant test added (proven by stash-revert) |
| 18 | 18 | 8c4955c | 79 | 0.0 | keep | pass | BUGFIX: removed phantom user:daily_audit cron (dispatched to unregistered task); cross-plugin invariant test added |
| 19 | 19 | 84eaf3f | 79 | 0.0 | keep | pass | CORDIS+BUGFIX: task handlers were asynq-typed so 4 upload tasks could not run under the in-process worker; made driver-agnostic + gate check 7 (proven: gate names all 3 files pre-fix) |
| 20 | 20 | efa7555 | 79 | 0.0 | keep | pass | BUGFIX telegram: LongPoller.Timeout was 10 nanoseconds -> getUpdates timeout=0 -> busy polling; now 10s (proven by reverting the constant) |
| 21 | 21 | 1023fa3 | 79 | 0.0 | keep | pass | DISK LEAK: telegram inbound media scratch dirs were never removed (no consumer reads them); cleanup on handler exit. No test possible (needs live download) |
| 22 | 22 | ad83841 | 54 | -25.0 | keep | pass | dead lint suppressions removed (24); 2 were load-bearing -> restored+narrowed with reasons after guard veto exposed verified contextcheck FPs |
| 23 | 23 | de938de | 54 | 0.0 | keep | pass | SECURITY/BUGFIX fail-open auth: user+message_gateway consumed contracts.AuthService in Apply but declared only DBService, so reconcile mounted user before auth and loginMW degraded to a pass-through (user change-password/profile/access-tokens unguarded in production, deterministically); declared the dep + added reconcile-level ordering test (PROVED: assertion fails on revert) |
| 24 | 24 | 62b48e9 | 54 | 0.0 | keep | pass | SECURITY: all three auth-middleware fallbacks were c.Next() (fail-open). Reachable at runtime in admin: OnDispose->ResetServices() nils the global the per-request guard reads, so in-flight requests pass as authenticated. Added ginutil.AuthUnavailable() + table test driving each registered guard (PROVED: abort assertion fails on revert to 577d795) |
| 25 | 25 | f58f5a4 | 54 | 0.0 | keep | pass | staticcheck ST1023 x4 from iter 24 (redundant gin.HandlerFunc on typed-RHS decls) - caught by GUARD only, go build/go test both stayed green; lesson: run checks.sh after EVERY commit, not just before ship |