Skip to content

(janitor/dedupe): consolidate bot link-token signing into signed-token helper - #6718

Merged
kilo-code-bot[bot] merged 1 commit into
mainfrom
janitor/dedupe/bot-identity-signed-token
Sep 25, 2026
Merged

kilo-code-bot[bot] merged 1 commit into
mainfrom
janitor/dedupe/bot-identity-signed-token

Conversation

@kilo-code-bot

@kilo-code-bot kilo-code-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Summary

bot-identity.ts hand-rolled the HMAC-signed, time-limited token scheme that signed-token.ts already owns, despite a comment noting it "follows the same pattern as src/lib/integrations/oauth-state.ts" (which itself delegates to signed-token.ts).

Finding

Classification: Shared behavior

signed-token.ts is the authoritative owner of the base64url(JSON({...payload, iat, nonce})).HMAC-SHA256 signed-token concept, with seven call sites already delegating to it (oauth-state, linear-link-state, linear-link-token, github-link-state, github-link-token, device-auth-viewer-token, plus gitlab/google oauth-state via createOAuthState). bot-identity.ts was the lone straggler re-implementing the identical scheme:

  • hmacSign — byte-for-byte identical to signed-token.ts's private hmacSign
  • createLinkToken — duplicated the iat/nonce injection and wire format
  • verifyLinkToken — duplicated dot-split, timingSafeEqual comparison, base64url decode, and age/TTL checks

Change

Replace the duplicated internals with calls to createSignedToken / verifySignedToken, keeping the link-account-specific Redis context load. The iat/nonce validation is now owned by signed-token.ts (which already validates them more strictly via Number.isFinite), so they are dropped from the local Zod schema.

Net: -33 lines, no behavioral change to the wire format or TTL.

Verification

  • oxlint (70 rules): 0 warnings, 0 errors
  • oxfmt --list-different: no formatting changes
  • Scoped tsgo typecheck: no errors attributable to this change (only pre-existing @types/node resolution artifacts from running outside the full web typecheck pipeline)
  • Jest suite could not be run in this environment: src/tests/setup/workerSetup.ts requires a live Postgres instance to bootstrap a per-worker test DB. The existing bot-identity.test.ts exercises createLinkAccountToken/verifyLinkToken round-trips and is unaffected in behavior.

bot-identity.ts hand-rolled the HMAC-signed, time-limited token scheme that signed-token.ts already owns. Delegate create/verify to createSignedToken/verifySignedToken, removing the duplicated hmacSign, wire-format, and timing-safe verification logic.
@kilo-code-bot kilo-code-bot Bot added the janitor Automated dead-code/duplication cleanup label Sep 25, 2026
@kilo-code-bot
kilo-code-bot Bot enabled auto-merge (squash) September 25, 2026 07:11
@kilo-code-bot

kilo-code-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor Author

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

Refactor of apps/web/src/lib/bot-identity.ts to reuse createSignedToken/verifySignedToken is behavior-preserving: wire format, HMAC key/algorithm, TTL, and future-timestamp rejection all match the removed implementation, and no callers referenced the deleted private helpers.

Files Reviewed (1 file)
  • apps/web/src/lib/bot-identity.ts

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

janitor Automated dead-code/duplication cleanup

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant