fix(plugin): bind durable installation replay to opaque identity - #175
Conversation
|
Warning Review limit reached
Next review available in: 9 seconds You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
Security/data-integrity outcome
Fail closed whenever a
PluginInstallationStorereturns durable evidence for a different opaque installation identity. Workspace, installer, manifest digest and grant equality are not sufficient ifinstallationIditself changed, and a lookup for one opaque locator must never expose a different durable row.Test-first sequence
plugin-installation-evidence-identity.test.tsintroduces a persistence-double regression that returns an otherwise identical create/replay winner with a different UUIDv4 installation ID. Against protected main5fdb8ee899991cbfd27c41ce59079648829b2a30,PluginInstallationApplication.install()would accept it becausesameInstallation()did not compare the opaque ID.installationIdequality tosameInstallation().plugin-installation-lookup-evidence-identity.test.tsindependently returns a different opaque ID fromfindById()while preserving workspace/user authority. Protected main would expose that row because the application verified only workspace and installer.installationIdto equal the requested locator before returning it.The PostgreSQL store already validates these identities. The application-level checks keep alternate/future persistence adapters from silently widening the trust boundary.
Scope
Three-file integrity hardening only. No schema, public API, capability, secret-store or outbound-network behavior changes.
Verification
Require unchanged exact head
b200fcf44ad2987e5d13d25d2bfdcf8cf92b4108to pass integration-service tests/typecheck/build, configured coverage/docstring gates, CI, AppGuardrail, SAST Semgrep, Security Scan, Commercial Readiness and all current review findings before merge. No predecessor evidence transfers.Refs #130.