Repository navigation
Conversation
Revalidate pairing or trusted identity before and after body reception. Keep automatic dashboard access and masked listing unchanged. Linux/Bun 1.4.0: 249 focused tests passed, 1 native-Windows skip. Typecheck, privacy, structure and whitespace checks passed. No native-platform, live-provider or full-suite acceptance is claimed. Fork-only draft candidate; no merge, deployment or finding closure.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
A loopback session that clicks a stored key now gets the server's standing 403, and the row used to reduce that to a bare transient-failure hint. The reveal result discriminates the refusal from a real failure, and the key table answers it with the pairing surface — the local pairing form on the same-origin standalone transport the grant mint accepts, the explanation alone elsewhere — then retries the refused reveal once pairing lands. Co-Authored-By: Epinephrine <luvs01@hanmail.net>
|
Review triage complete — pushed Fixed (1):
Dismissed (0): no other unresolved threads from Devin Review, CodeRabbit, or the Codex connector — CodeRabbit skipped this draft and the connector left no comments on the head. Checks: |
|
Done. The PR had exactly one unresolved finding across all three bots — Devin Review's "stored-key reveal has no pairing path in the local key screen" — and it was genuine: this PR's new 403 hits standalone loopback dashboards, where pairing is possible but was undiscoverable from the keys screen. Fixed in
Checks: Caveats: Thread |
✅ READY
Hygiene✅ Deterministic PR hygiene checks passed. |
|
Re-triage pass on head |
|
No new findings — the trigger was a self-fired event. Review id 5425922106 (08:45:19) is the previous run's own thread reply submitted as a Full inventory of PR #709 at head
Nothing to fix or dismiss; posted a one-line re-triage note on the PR so the record is clear. |
The reveal result's failure field is a discriminator, not copy, but the local-i18n gate treats every reason: literal as user-facing text. Rename it to kind, which the data-copy allowlist does not claim. The row-action tests still answered reveal with the old string-or-null contract, and the workspace mounts never passed the required apiBase, so the panel's new standaloneApiTargets lookup crashed every render of the suite. Co-Authored-By: Epinephrine <luvs01@hanmail.net> Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The head commit answers a refused stored-key reveal with the panel's pairing surface, but nothing exercised it. Mount the page on the same-origin standalone transport and drive the denied read end to end: notice plus local pairing form, and the refused reveal retried once pairing lands. The non-standalone answer (explanation alone) and the transient-failure path are covered beside it, and the row-action suite gains the denied-row case the new contract introduced. The web-dashboard guide now mentions the refused reveal's on-page recovery in both languages, matching the structure note. Co-Authored-By: Epinephrine <luvs01@hanmail.net> Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-Authored-By: Epinephrine <luvs01@hanmail.net>
Summary
Cache-Control: no-store.Fork-only draft requested by the fork owner. No upstream submission, merge, installation, credential rotation or Security Cloud finding closure is performed. Pairing retains its existing configuration-write authority boundary; this is not human-presence authentication or protection from an unrestricted same-user writer. Other management operations are not redesigned here.
Verification
Base:
5d69e5cdc58441ac5c1735ea2f81f1bc46eff0ac.Published head:
9c944c4af397257078a4651a8c6911d5043dcfa7.Exact tested and read-back tree:
d5bcc961d2f7395fd624e140d68e096cea847ef0.Nine files change, with 202 insertions and 16 deletions. Temporary publication workflows and transfer files are absent from this tree.
Actual Linux / repository-pinned Bun 1.4.0 execution
Executed focused files:
Tests used the repository's exported
createIsolatedTestEnvironment()andbun test --isolatewithin its returned environment, with inherited HTTP proxy variables cleared. This retains private-home and credential isolation while avoiding the standard wrapper's unrelated automatic GUI dependency installation, unavailable in this offline executor.Other executed commands:
Publication run
37423634727checked the readable patch's SHA-256, original preimages, exact nine-file scope and complete resulting tree before creating the new ref. Connector readback confirms the published parent and tree. No patched application code or dependency installation executed with its publication write token. Incomplete preliminary transfer data was discarded before this checksum-gated publication. This is transport verification, not an additional application test run.Limits and outstanding review
The skipped case is the existing native Windows owner/effective-DACL test. No native Windows/macOS execution, real Tailscale Serve deployment, live provider request, interactive browser acceptance, installed-package/service validation, documentation build or full repository/import-connected test suite was performed. Tailscale coverage exercises the real issuer and authorization code with a controlled trusted-ingress input, not a deployed identity proxy. All keys are synthetic fixtures; no user key store or installed service was read or changed by the tests.
Focused coverage is the explicit resource exception. Current-head hosted CI and independent security review of the session/disclosure boundary remain required. Pending, skipped or older-head checks are not passes. Keep the finding open until this correction is actually integrated and verified.
Checklist
Review readiness checklist
UI screenshot
Stored-key reveal refused on an automatic loopback session (
8b39d3008): the server returns the standing 403, the key table shows the operator-authorized-session notice, and the local pairing form offersocx gui pairon the same standalone origin.Link to Devin session: https://app.devin.ai/sessions/4618b44763d145869890b93014329ccd
Open in Devin Desktop: https://app.devin.ai/desktop/session/4618b44763d145869890b93014329ccd?variant=devin