Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe change adds optional ChangesPrompt Inbox Identity
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Change: Feature · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant Client
participant handleAddPrompt
participant Store
participant WriteNotification
Client->>handleAddPrompt: Submit prompt with source_inbox_id
handleAddPrompt->>Store: AddPromptWithResult
Store-->>handleAddPrompt: Prompt ID and insertion status
alt New prompt inserted
handleAddPrompt->>WriteNotification: Notify write
else Existing prompt replayed
handleAddPrompt-->>Client: Return existing prompt response
end
handleAddPrompt-->>Client: Return HTTP response
Suggested reviewers: Merge Risk: 🟡 Moderate · up to A delete or backup from another project can reserve an inbox identity and prevent a legitimate prompt from being restored or written. Resolve the identity-authority policy before merging. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Deleted prompt identities can now block later writes across several data paths. The review found paths that can record a deletion identity without establishing its ownership, while the new cloud authority registry is not yet connected to those paths. External exploitability is not fully established. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Out of Scope Changes checkExplanation The PR adds ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
…issue-1458-f2-lint-rescue
feat(store): record origin of locally created keyed prompts
fix(store): preserve verified prompt origin after local deletion
…-adapter feat(cloud): expose prompt authority calls to autosync
feat(store): expose eligible pending mutation high-water
…reflight feat(autosync): preflight keyed prompt authority before push
fix(autosync): pull despite local prompt provenance blocks
feat(store): preview one exact prompt source without authority
…store feat(cloudstore): record explicit prompt source attestations
Capture OpenCode 2.x prompts from user items of session.inbox.enqueued and send the inboxID as source_inbox_id, so a server with prompt inbox identity support (#1464) treats replays as no-ops, keeps equal-text items distinct, and refuses deleted identities. V1 chat.message and V2 share one capture helper; the identity-less V2 prompt hook is no longer used for capture. Adds a real-server regression for replay, restart, and delete.
feat(cloudserver): authorize explicit prompt source attestations
🔗 Linked Issue
Closes #1458. This tracker is the sole PR to
mainfor the completed foundation chain; children #1465, #1466, and #1469 were merged into this branch in order, not intomain.🏷️ PR Type
type:feature— New feature📝 Summary
(session_id, source_inbox_id)from local admission through sync and backup import/export.📂 Changes
internal/store/store.go,internal/store/store_test.go,internal/store/export_project_query_test.gointernal/server/server.go,internal/server/server_test.godocs/ARCHITECTURE.md🧪 Test Plan
CODEX_HOME='' go test ./internal/store ./internal/sync ./internal/server -count=1and completeCODEX_HOME='' go test ./... -count=1locally; F1/F2 recorded their independent tests.37b7f07eafter fix(store): guard prompt owner during deletes and identity adoption #1505: pending; do not enter main merge queue until verified. Prior tracker head79a5d0fapassed CI but full review found two bugs corrected in fix(store): preserve prompt deletion ownership across sparse sync #1492.🤖 Automated Checks
Prior integrated head
79a5d0fapassed CI and substantive CodeRabbit review identified sparse project backup and malformed pulled delete. #1492 corrected these and full backup roundtrips; its final head passed CI and full review with no new inline finding. Fresh tracker CI and substantive review on880f6b47remain pending.✅ Contributor Checklist
type:*label💬 Notes for Reviewers
The combined tracker diff is 2,264 lines because it accumulates three separately reviewed and size-authorized slices plus separately reviewed 234-, 50-, 147-, 48-, and 279-line integration corrections. Please review child PRs for the bounded units and this tracker for integration only. Merge order was #1465 → #1466 → #1469 → #1492 → #1495 → #1496 → #1504 → #1505. Do not merge #1240 as part of this PR.
Chain Context
mainmainbaselinemainvia merge queueChain Overview
main← 📍 #1464 integrated tracker ← #1505 owner/adoption guard ← #1504 project guard ← #1496 tombstone guard ← #1495 quarantine correction ← #1492 correction ← #1469 F3 ← #1466 F2 ← #1465 F1Scope
Summary by CodeRabbit
Final integration follow-up
Full tracker review on
37b7f07efound malformed pulled deletes could stall the sync cursor. #1495 quarantines that identity with raw dead-letter evidence instead of silently discarding it, and passed its CI, native review, and substantive full CodeRabbit review (no new actionable comments). Tracker880f6b47needs fresh CI and substantive review before entering the main merge queue.Tombstone identity follow-up
The substantive tracker review of
880f6b47identified a retained medium risk: a conflicting pulled delete or import could rebind an established tombstone key. #1496 prevents rebinding, quarantines pulled conflicts and rejects conflicting imports before deleting matched prompts. Its 147-line head passed CI, native review, and a full CodeRabbit review with minimal merge risk and no architecture-level retained concern. Fresh integrated CI and full review on70e5a45bare required before queue entry.Project ownership follow-up
The full integrated review of
70e5a45bfound that a same-identity repeat import could rebind the tombstone to a different project, losing it in the original scoped backup. #1504 rejects this established-project conflict and verifies scoped export → restore → replay protection. Its head passed full CI and substantive full CodeRabbit review with minimal merge risk. Native review start remained unavailable because the consent binding expired repeatedly before lineage creation; no native approval is claimed. Fresh integrated CI and full review onc5926826required before merge queue entry.Owner and adoption follow-up
The full tracker review of
c5926826identified an import-adoption sync journal gap and two wrong-owner delete paths. #1505 prevents cross-project backup deletion, quarantines spoofed inbox pairs on pulled deletes, and queues a canonical follow-up mutation on identity adoption so acknowledged/in-flight older upserts cannot erase delivery. Its final 279-line head passed CI and substantive full CodeRabbit review with minimal merge risk and no retained architecture concern. Fresh integrated CI and review of890b96ceremain required.