fix(video): isolate drill-down cache by principal - #11369
Merged
diegosouzapw merged 2 commits intoAug 24, 2026
Merged
Conversation
Owner
Author
|
CI attribution snapshot (2026-08-24)
No PR-specific build or DAST regression is demonstrated by the cancelled jobs. The PR remains OPEN and DRAFT; this note does not claim the complete CI matrix is green. |
diegosouzapw
marked this pull request as ready for review
August 24, 2026 12:24
This was referenced Aug 24, 2026
This was referenced Aug 26, 2026
Merged
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`). Video Bridge FU-08 drill-down cache substrate hardening (explicitly PARTIAL per the PR body — no production producer/callsite feeds this cache yet): canonical isolation by principalId+sessionId+videoRef, loopback broker auth, strict Zod contracts, per-principal + global LRU quotas, full JPEG decode/re-encode with truncated-scan and polyglot-tail rejection, cancellation-safe atomic replacement. Static gates green; own regression suite (videoBridgeDrilldown.test.ts, video-bridge-drilldown-authz.test.ts, video-bridge-drilldown-route.test.ts) passed in the combined-batch run. Thanks!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Hardens the optional Video Bridge drill-down cache substrate while keeping the broader FU-08 status explicitly PARTIAL.
This slice adds:
principalId + sessionId + videoRefOnly the canonical JPEG generated server-side is retained, hashed, returned, and charged. Raw video/media is not persisted.
Adversarial TDD evidence
RED cases reproduced before the fix:
FF D9reattached was acceptedftypisombox, raw bytes, and synthetic EOI was retained wholeGREEN:
ftypisomValidation
npm run typecheck:core: PASSnpm run check:docs-all: PASSThe 11 OpenAPI changes are intentional hardenings to an internal drill-down route; they were reviewed rather than hidden in a breaking-change allowlist.
Deliberate FU-08 boundary
This PR does not claim complete transparent drill-down:
Those follow-ups remain documented as HOLD/PARTIAL. This PR does not authorize merge, tagging, or release publication; keep it open for owner review.