Conversation
Shadscan scoreScore: 29/100 (grade: F) — floor: 29 Scanned |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 44 minutes. View limit detailsLimit details: You’ve used all 2 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (9)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (9)
🧰 Additional context used📓 Path-based instructions (4)Focus on correctness, type safety, server/client boundaries, async behavior, error handling, security, performance, and maintainability.⚙️ CodeRabbit configuration file Files:
Treat package changes as shared contracts.⚙️ CodeRabbit configuration file Files:
Source excerpt: `packages/api/src/*` is the single canonical layer for business database logic.📄 CodeRabbit inference engine (packages/api/AGENTS.md) Files:
Source excerpt: Editing files under `packages/api/**`📄 CodeRabbit inference engine (packages/api/AGENTS.md) Files:
🪛 Betterleaks (1.8.1)packages/api/tests/unit/donate-post-charge.test.ts[high] 505-505: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data. (stripe-access-token) 🪛 LanguageToolopenspec/changes/guest-giving-gift-processing-fee-policy/design.md[grammar] ~99-~99: Ensure spelling is correct (QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1) openspec/changes/guest-giving-gift-processing-fee-policy/tasks.md[grammar] ~42-~42: Use a hyphen to join words. (QB_NEW_EN_HYPHEN) 🔇 Additional comments (11)
📝 Summary
WalkthroughFor HTTP donate replays with matching charged cents, intake now passes stored fee metadata to the saga. Legacy empty fee extras remain absent, while conflicting stored full quotes still return ChangesLegacy donation replay
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to Legacy donation retries preserve their original fee-related payment parameters. No actionable merge-blocking defect was identified; complete the planned integration checks before merging. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change narrows a legacy payment-retry failure without changing the established authentication, tenant, amount, or stored-quote checks. Recovery by a different actor remains a separate limitation, and production rollout has not been verified here. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 6 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (6 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 3 files. (6 skipped: 6 unsupported.) Full details: Repo Gate EvidenceExplanation The PR description names the broad Resolution Add a Validation section with the exact commands and results. Include a focused command such as ✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Closes #1917.
A legacy donation can retain empty fee extras after its PaymentIntent was created but Core's completion write failed. HTTP replay previously supplied a new fee quote, changing provider metadata and payment-method parameters under the existing idempotency key. Intake now forwards the stored fee state, including legacy absence, after all existing amount and quote validations.
This preserves the remaining verified repair from closed, unmerged PR #1329. The broader fee policy is already on develop. The nine-path change retains tenant/auth checks, cents arithmetic, first-shot quotes, malformed/full-quote rejection and the existing provider identity.
Validation on published
e69602146f1ff4881078912d053ecc4dabfb369e, treebf473ec342827de9cdec1a99f862063a4dc9aa0d, basebd9acc44313761d3371996c85376373782da02fb:ci:preflightpasses all three application builds and 4341 tests with 4 existing skips. Fresh GitHub CI/reviews and hosted QA remain outstanding.The qualified recovery scope is same-actor, same-customer HTTP fee replay. Cross-actor
metadata.user_idrecovery remains unresolved: the outbox/claim does not record the first actual provider caller. This change does not infer historical attribution, remove it, invent a new payment key or claim actor-independent recovery.Deploy Checklist (for PRs to
productionordevelop)developDraft while shared #1915/#1916 preview/build prerequisites remain unresolved. Refresh against their actual merged base and qualify the resulting candidate before Ready/merge. The full-gates OpenSpec task stays unchecked.