Repository navigation
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Removing the row in 4d75dd2 was wrong. #202 declares VITE_CDP_PROJECT_ID in .env.example and docs/coinbase-setup.md as the single CDP value permitted in a client build, and pairs it with the rule that no backend credential may carry a VITE_ prefix. The table row is what makes that distinction visible in the credential inventory, so it belongs here. Keep the clarification that no frontend exists in the repository yet, which is the one piece of context the row was missing.
|
P1 — blank values in
Old behaviour was Neither change is mentioned in the description and neither is needed for the CDP work. Is the intent that blank means unset ( P1 — the redaction wildcard depth is capped at 3 and nothing pins the boundary.
The two tests cover depths 0, 1 and 2, so the cliff at 4 is invisible — and this is the item the description asks reviewers to focus on ("Logger redaction coverage"). Depth 4 is reachable in practice: a CDP or Axios error logged as
P1 — Three uses in Minor — z.string().default('base-sepolia')
.refine((v) => v === 'base-sepolia', 'CDP_NETWORK must be base-sepolia')
.transform(() => 'base-sepolia' as const)
Nothing else. The disabled-mode discriminated union is the right shape — |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ccf1e07ba0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
ccf1e07 to
7e27f94
Compare
|
Pushed P1 — blank values crash startup. Fixed, and it was reachable today: the P1 — redaction depth (also @chatgpt-codex-connector). One honest limitation, documented in the code and pinned by a test asserting both halves: Pino bakes P1 — Minor — @chatgpt-codex-connector — @chatgpt-codex-connector — rotation runbooks. The conflict was real and the ADR was wrong; fixed on #201 and cross-referenced here. The setup doc now leads with the split: the API key supports an overlap window, the Wallet Secret does not. Unit suite is 475 green (was 442). |
|
To use Codex here, create a Codex account and connect to github. |
Three problems in the configuration boundary:
Blank values crashed startup where they previously fell back to a default.
dotenv turns a bare KEY= line into '', and z.string().default() only fires on
undefined, so PORT= became a hard startup failure while a blank
STRIPE_SECRET_KEY silently reached the Stripe client as '' instead of the
placeholder -- two different answers to the same input. Both previously used
process.env.X || fallback. normalizeSource now treats blank as absent for every
key, so the two agree again. The local .env in this repo already has three
blank-valued keys, so this was reachable today.
Credential redaction stopped at three levels. COINBASE_REDACTION_PATHS expanded
each field to field, *.field, *.*.field, *.*.*.field, and fast-redact's * matches
exactly one level, so a secret nested deeper leaked -- reachable through a CDP or
Axios error logged as { err }, whose config and headers nest several levels down.
fast-redact has no recursive wildcard, so raising the cap only moves the cliff.
Redaction is now a walk that censors by key name at any depth, bounded only by a
named MAX_REDACTION_DEPTH, and covers errors (preserving message and stack),
arrays, cycles, and child logger bindings.
TELEGRAM_MOCK now fails closed on non-canonical values. Blank keeps meaning
unset, so existing deployments are unaffected, but a typo such as
TELEGRAM_MOCK=1 no longer reads as 'not mocked' and sends real Telegram traffic.
Also replaces the CDP_NETWORK refine/transform pair with z.literal, records that
required_error is Zod 3 syntax that #183 will have to migrate, and reconciles the
wallet-secret rotation runbook with ADR 001: the API key supports an overlap
window, the wallet secret does not.
The Coinbase work lands as a stack: #202, #203, and #204 are all based on feat/coinbase-foundation rather than on main. The pull_request trigger filtered on branches: [main], so none of those three ran lint, type check, unit tests, integration tests, or CodeQL -- the only green checks on them were Dependabot and CodeRabbit, and the gap is invisible because a PR with no matching workflow looks the same as one with nothing to run. Dropping the filter costs nothing: a pull_request event still only fires for an open PR, and same-repo branches keep access to the Stripe secret the integration job needs.
7e27f94 to
e4a1124
Compare
Summary
Closes #189.
This PR adds the fail-closed configuration boundary required before AgentWallet can initialize Coinbase CDP or submit x402 payments:
Stack
This PR is stacked on #201 and intentionally targets
feat/coinbase-foundationso the review contains only issue #189. After #201 merges, this PR should be retargeted tomain.Security properties
VITE_prefixVITE_CDP_PROJECT_IDis declared as browser-publicCDP_NETWORK=baseand every non-base-sepoliavalue fail startupVerification
npm cinpm run buildnpm run lint -- --quietnpm run format:checknpm run test:unit -- --runInBand(40 suites, 441 tests)npm run test:integration(4 suites passed; 36 passed, 96 intentionally skipped)GET /healthsmoke test (HTTP 200)This repository currently has no frontend build target. The server schema deliberately omits
VITE_CDP_PROJECT_ID, and no backend CDP credential has a public prefix.Reviewer focus