Skip to content

fix(video): isolate drill-down cache by principal - #11369

Merged
diegosouzapw merged 2 commits into
release/v3.8.50from
fix/v3850-video-fu08-principal-isolation
Aug 24, 2026
Merged

diegosouzapw merged 2 commits into
release/v3.8.50from
fix/v3850-video-fu08-principal-isolation

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

Hardens the optional Video Bridge drill-down cache substrate while keeping the broader FU-08 status explicitly PARTIAL.

This slice adds:

  • canonical isolation by principalId + sessionId + videoRef
  • exact-path loopback broker authorization for the drill-down route
  • strict Zod input contracts and canonical visible-ASCII identifiers
  • per-principal quotas (16 entries / 64 MiB) plus global LRU ceilings (64 / 256 MiB)
  • TTL/LRU accounting and principal-scoped GET/DELETE behavior
  • canonical Base64 validation before accounting
  • full warning-sensitive JPEG decode and server-side re-encoding
  • rejection of truncated scans and removal of trailing polyglot/MP4 bytes
  • server-derived dimensions and auditable derivation metadata
  • cancellation-safe, atomic replacement with typed 400/499/sanitized-500 errors

Only the canonical JPEG generated server-side is retained, hashed, returned, and charged. Raw video/media is not persisted.

Adversarial TDD evidence

RED cases reproduced before the fix:

  • a real JPEG with its entropy scan truncated and FF D9 reattached was accepted
  • a valid JPEG with an appended MP4 ftypisom box, raw bytes, and synthetic EOI was retained whole

GREEN:

  • truncated scan is rejected with zero quota committed
  • polyglot input is fully decoded/re-encoded
  • returned bytes contain no ftypisom
  • retained-byte accounting exactly matches the canonical output
  • previous valid derivations survive validation failure/abort

Validation

  • full focused matrix before rebase: 47/47 PASS
  • post-rebase cache/route/authz matrix: 30/30 PASS
  • independent adversarial review: PASS, no blocker remaining in this slice
  • Prettier and targeted ESLint: PASS
  • npm run typecheck:core: PASS
  • npm run check:docs-all: PASS
  • OpenAPI routes/security/coverage: PASS
  • changelog integrity and diff-check: PASS

The 11 OpenAPI changes are intentional hardenings to an internal drill-down route; they were reviewed rather than hidden in a breaking-change allowlist.

Deliberate FU-08 boundary

This PR does not claim complete transparent drill-down:

  • no production Video Bridge producer/callsite feeds the cache yet
  • tenant identity is not yet bound end-to-end by a production caller
  • each entry still represents one resolution; no multi-resolution selector exists
  • an abort prevents commit after Sharp returns but cannot interrupt an already-running native encode

Those follow-ups remain documented as HOLD/PARTIAL. This PR does not authorize merge, tagging, or release publication; keep it open for owner review.

@diegosouzapw

Copy link
Copy Markdown
Owner Author

CI attribution snapshot (2026-08-24)

  • Candidate: d9dd8968deae0cee9b53f0fe0008f0b6cf85eb97
  • Exact base: dafb4ae808305c9287c751cf1ce16fe2234ba073
  • CodeQL (all four languages), Semgrep, and Semgrep Cloud passed.
  • Fast Production Build reached Next.js Creating an optimized production build ... and then GitHub cancelled the operation, with no compiler/type diagnostic. The exact base has the same cancellation signature in run 32693521371.
  • dast-smoke received SIGTERM while building its CLI prerequisite; it never reached application startup or DAST assertions.
  • The FU-08 security substrate passed the 47-test pre-rebase matrix, the 30-test post-rebase adversarial matrix, and an independent review covering truncated JPEG plus reattached EOI, JPEG polyglot tails, canonical Base64, quotas, auth-path isolation, and abort-safe atomic commit.
  • Its deliberate PARTIAL boundary remains explicit: no production producer/callsite, no end-to-end tenant binding, and no multiresolution selector are claimed.

No PR-specific build or DAST regression is demonstrated by the cancelled jobs. The PR remains OPEN and DRAFT; this note does not claim the complete CI matrix is green.

@diegosouzapw
diegosouzapw marked this pull request as ready for review August 24, 2026 12:24
@diegosouzapw
diegosouzapw merged commit c83116e into release/v3.8.50 Aug 24, 2026
27 of 30 checks passed
@diegosouzapw
diegosouzapw deleted the fix/v3850-video-fu08-principal-isolation branch August 25, 2026 02:37
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`). Video Bridge FU-08 drill-down cache substrate hardening (explicitly PARTIAL per the PR body — no production producer/callsite feeds this cache yet): canonical isolation by principalId+sessionId+videoRef, loopback broker auth, strict Zod contracts, per-principal + global LRU quotas, full JPEG decode/re-encode with truncated-scan and polyglot-tail rejection, cancellation-safe atomic replacement. Static gates green; own regression suite (videoBridgeDrilldown.test.ts, video-bridge-drilldown-authz.test.ts, video-bridge-drilldown-route.test.ts) passed in the combined-batch run. Thanks!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant