Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
WalkthroughThis PR introduces OpenAI data retention control via an environment variable and improves Outlook token expiry handling with a refresh buffer. Version is bumped to v2.21.36. Changes are configuration-driven and do not alter core control flow. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes
Possibly related PRs
Poem
Pre-merge checks and finishing touches❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✨ Finishing touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
See: vercel/ai#10060 |
| @@ -97,7 +100,11 @@ export const getOutlookClientWithRefresh = async ({ | |||
|
|
|||
| // Check if token needs refresh | |||
| const expiryDate = expiresAt ? expiresAt : null; | |||
There was a problem hiding this comment.
The expiry check mixes seconds (expires_at) with milliseconds (Date.now() + TOKEN_REFRESH_BUFFER_MS). Consider converting expires_at to ms before comparing to avoid unnecessary refreshes.
- const expiryDate = expiresAt ? expiresAt : null;
+ const expiryDateMs = expiresAt ? expiresAt * 1000 : null;
if (
- accessToken &&
- expiryDate &&
- expiryDate > Date.now() + TOKEN_REFRESH_BUFFER_MS
+ accessToken &&
+ expiryDateMs &&
+ expiryDateMs > Date.now() + TOKEN_REFRESH_BUFFER_MS
) {
return createOutlookClient(accessToken);
}🚀 Reply to ask Macroscope to explain or update this suggestion.
👍 Helpful? React to give us feedback.
There was a problem hiding this comment.
Issue on line in apps/web/utils/llms/model.ts:153:
Suggestion: Add defensive checks/defaults in apps/web/utils/llms/model.ts before provider construction—validate env.BEDROCK_ACCESS_KEY/env.BEDROCK_SECRET_KEY and default providerOptions/providerOptions.openai to empty objects—to prevent runtime errors.
+ if (!env.BEDROCK_ACCESS_KEY || !env.BEDROCK_SECRET_KEY) {
+ throw new Error("Bedrock selected but BEDROCK_ACCESS_KEY and/or BEDROCK_SECRET_KEY are not set");
+ }
🚀 Reply to ask Macroscope to explain or update this suggestion.
👍 Helpful? React to give us feedback.
There was a problem hiding this comment.
Actionable comments posted: 1
📜 Review details
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (4)
apps/web/env.ts(1 hunks)apps/web/utils/llms/model.ts(1 hunks)apps/web/utils/outlook/client.ts(2 hunks)version.txt(1 hunks)
🧰 Additional context used
📓 Path-based instructions (15)
apps/web/**/*.{ts,tsx}
📄 CodeRabbit inference engine (apps/web/CLAUDE.md)
apps/web/**/*.{ts,tsx}: Use TypeScript with strict null checks
Use@/path aliases for imports from project root
Use proper error handling with try/catch blocks
Format code with Prettier
Follow consistent naming conventions using PascalCase for components
Centralize shared types in dedicated type filesImport specific lodash functions rather than entire lodash library to minimize bundle size (e.g.,
import groupBy from 'lodash/groupBy')
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
**/*.{ts,tsx}
📄 CodeRabbit inference engine (.cursor/rules/data-fetching.mdc)
**/*.{ts,tsx}: For API GET requests to server, use theswrpackage
Useresult?.serverErrorwithtoastErrorfrom@/components/Toastfor error handling in async operations
**/*.{ts,tsx}: Use wrapper functions for Gmail message operations (get, list, batch, etc.) from @/utils/gmail/message.ts instead of direct API calls
Use wrapper functions for Gmail thread operations from @/utils/gmail/thread.ts instead of direct API calls
Use wrapper functions for Gmail label operations from @/utils/gmail/label.ts instead of direct API calls
**/*.{ts,tsx}: For early access feature flags, create hooks using the naming conventionuse[FeatureName]Enabledthat return a boolean fromuseFeatureFlagEnabled("flag-key")
For A/B test variant flags, create hooks using the naming conventionuse[FeatureName]Variantthat define variant types, useuseFeatureFlagVariantKey()with type casting, and provide a default "control" fallback
Use kebab-case for PostHog feature flag keys (e.g.,inbox-cleaner,pricing-options-2)
Always define types for A/B test variant flags (e.g.,type PricingVariant = "control" | "variant-a" | "variant-b") and provide type safety through type casting
**/*.{ts,tsx}: Don't use primitive type aliases or misleading types
Don't use empty type parameters in type aliases and interfaces
Don't use this and super in static contexts
Don't use any or unknown as type constraints
Don't use the TypeScript directive @ts-ignore
Don't use TypeScript enums
Don't export imported variables
Don't add type annotations to variables, parameters, and class properties that are initialized with literal expressions
Don't use TypeScript namespaces
Don't use non-null assertions with the!postfix operator
Don't use parameter properties in class constructors
Don't use user-defined types
Useas constinstead of literal types and type annotations
Use eitherT[]orArray<T>consistently
Initialize each enum member value explicitly
Useexport typefor types
Use `impo...
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
**/{server,api,actions,utils}/**/*.ts
📄 CodeRabbit inference engine (.cursor/rules/logging.mdc)
**/{server,api,actions,utils}/**/*.ts: UsecreateScopedLoggerfrom "@/utils/logger" for logging in backend code
Add thecreateScopedLoggerinstantiation at the top of the file with an appropriate scope name
Use.with()method to attach context variables only within specific functions, not on global loggers
For large functions with reused variables, usecreateScopedLogger().with()to attach context once and reuse the logger without passing variables repeatedly
Files:
apps/web/utils/outlook/client.tsapps/web/utils/llms/model.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (.cursor/rules/prisma-enum-imports.mdc)
Always import Prisma enums from
@/generated/prisma/enumsinstead of@/generated/prisma/clientto avoid Next.js bundling errors in client componentsImport Prisma using the project's centralized utility:
import prisma from '@/utils/prisma'
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
**/*.ts
📄 CodeRabbit inference engine (.cursor/rules/security.mdc)
**/*.ts: ALL database queries MUST be scoped to the authenticated user/account by including user/account filtering in WHERE clauses to prevent unauthorized data access
Always validate that resources belong to the authenticated user before performing operations, using ownership checks in WHERE clauses or relationships
Always validate all input parameters for type, format, and length before using them in database queries
Use SafeError for error responses to prevent information disclosure. Generic error messages should not reveal internal IDs, logic, or resource ownership details
Only return necessary fields in API responses using Prisma'sselectoption. Never expose sensitive data such as password hashes, private keys, or system flags
Prevent Insecure Direct Object References (IDOR) by validating resource ownership before operations. AllfindUnique/findFirstcalls MUST include ownership filters
Prevent mass assignment vulnerabilities by explicitly whitelisting allowed fields in update operations instead of accepting all user-provided data
Prevent privilege escalation by never allowing users to modify system fields, ownership fields, or admin-only attributes through user input
AllfindManyqueries MUST be scoped to the user's data by including appropriate WHERE filters to prevent returning data from other users
Use Prisma relationships for access control by leveraging nested where clauses (e.g.,emailAccount: { id: emailAccountId }) to validate ownership
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (.cursor/rules/ui-components.mdc)
**/*.{tsx,ts}: Use Shadcn UI and Tailwind for components and styling
Usenext/imagepackage for images
For API GET requests to server, use theswrpackage with hooks likeuseSWRto fetch data
For text inputs, use theInputcomponent withregisterPropsfor form integration and error handling
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
**/*.{tsx,ts,css}
📄 CodeRabbit inference engine (.cursor/rules/ui-components.mdc)
Implement responsive design with Tailwind CSS using a mobile-first approach
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
**/*.{js,jsx,ts,tsx}
📄 CodeRabbit inference engine (.cursor/rules/ultracite.mdc)
**/*.{js,jsx,ts,tsx}: Don't useaccessKeyattribute on any HTML element
Don't setaria-hidden="true"on focusable elements
Don't add ARIA roles, states, and properties to elements that don't support them
Don't use distracting elements like<marquee>or<blink>
Only use thescopeprop on<th>elements
Don't assign non-interactive ARIA roles to interactive HTML elements
Make sure label elements have text content and are associated with an input
Don't assign interactive ARIA roles to non-interactive HTML elements
Don't assigntabIndexto non-interactive HTML elements
Don't use positive integers fortabIndexproperty
Don't include "image", "picture", or "photo" in img alt prop
Don't use explicit role property that's the same as the implicit/default role
Make static elements with click handlers use a valid role attribute
Always include atitleelement for SVG elements
Give all elements requiring alt text meaningful information for screen readers
Make sure anchors have content that's accessible to screen readers
AssigntabIndexto non-interactive HTML elements witharia-activedescendant
Include all required ARIA attributes for elements with ARIA roles
Make sure ARIA properties are valid for the element's supported roles
Always include atypeattribute for button elements
Make elements with interactive roles and handlers focusable
Give heading elements content that's accessible to screen readers (not hidden witharia-hidden)
Always include alangattribute on the html element
Always include atitleattribute for iframe elements
AccompanyonClickwith at least one of:onKeyUp,onKeyDown, oronKeyPress
AccompanyonMouseOver/onMouseOutwithonFocus/onBlur
Include caption tracks for audio and video elements
Use semantic elements instead of role attributes in JSX
Make sure all anchors are valid and navigable
Ensure all ARIA properties (aria-*) are valid
Use valid, non-abstract ARIA roles for elements with ARIA roles
Use valid AR...
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
!(pages/_document).{jsx,tsx}
📄 CodeRabbit inference engine (.cursor/rules/ultracite.mdc)
Don't use the next/head module in pages/_document.js on Next.js projects
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsversion.txtapps/web/utils/llms/model.ts
**/*.{js,ts,jsx,tsx}
📄 CodeRabbit inference engine (.cursor/rules/utilities.mdc)
**/*.{js,ts,jsx,tsx}: Use lodash utilities for common operations (arrays, objects, strings)
Import specific lodash functions to minimize bundle size (e.g.,import groupBy from 'lodash/groupBy')
Files:
apps/web/utils/outlook/client.tsapps/web/env.tsapps/web/utils/llms/model.ts
apps/web/**/{.env.example,env.ts,turbo.json}
📄 CodeRabbit inference engine (apps/web/CLAUDE.md)
Add environment variables to
.env.example,env.ts, andturbo.json
Files:
apps/web/env.ts
apps/web/env.ts
📄 CodeRabbit inference engine (.cursor/rules/environment-variables.mdc)
apps/web/env.ts: Add server-only environment variables toapps/web/env.tsunder theserverobject with Zod schema validation
Add client-side environment variables toapps/web/env.tsunder theclientobject withNEXT_PUBLIC_prefix and Zod schema validation
Add client-side environment variables toapps/web/env.tsunder theexperimental__runtimeEnvobject to enable runtime access
Files:
apps/web/env.ts
{.env.example,apps/web/env.ts}
📄 CodeRabbit inference engine (.cursor/rules/environment-variables.mdc)
Client-side environment variables must be prefixed with
NEXT_PUBLIC_
Files:
apps/web/env.ts
apps/web/{utils/ai,utils/llms,__tests__}/**/*.ts
📄 CodeRabbit inference engine (.cursor/rules/llm.mdc)
LLM-related code must be organized in specific directories:
apps/web/utils/ai/for main implementations,apps/web/utils/llms/for core utilities and configurations, andapps/web/__tests__/for LLM-specific tests
Files:
apps/web/utils/llms/model.ts
apps/web/utils/llms/{index,model}.ts
📄 CodeRabbit inference engine (.cursor/rules/llm.mdc)
Core LLM functionality must be defined in
utils/llms/index.ts, model definitions and configurations inutils/llms/model.ts, and usage tracking inutils/usage.ts
Files:
apps/web/utils/llms/model.ts
🧠 Learnings (10)
📚 Learning: 2025-11-25T14:36:45.807Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/environment-variables.mdc:0-0
Timestamp: 2025-11-25T14:36:45.807Z
Learning: Applies to apps/web/env.ts : Add server-only environment variables to `apps/web/env.ts` under the `server` object with Zod schema validation
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:36:43.454Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/environment-variables.mdc:0-0
Timestamp: 2025-11-25T14:36:43.454Z
Learning: Applies to apps/web/env.ts : Define environment variables in `apps/web/env.ts` using Zod schema validation, organizing them into `server` and `client` sections
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:36:45.807Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/environment-variables.mdc:0-0
Timestamp: 2025-11-25T14:36:45.807Z
Learning: Applies to apps/web/env.ts : Add client-side environment variables to `apps/web/env.ts` under the `client` object with `NEXT_PUBLIC_` prefix and Zod schema validation
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:36:45.807Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/environment-variables.mdc:0-0
Timestamp: 2025-11-25T14:36:45.807Z
Learning: Applies to apps/web/env.ts : Add client-side environment variables to `apps/web/env.ts` under the `experimental__runtimeEnv` object to enable runtime access
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:36:43.454Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/environment-variables.mdc:0-0
Timestamp: 2025-11-25T14:36:43.454Z
Learning: Applies to apps/web/env.ts : For client-side environment variables in `apps/web/env.ts`, prefix them with `NEXT_PUBLIC_` and add them to both the `client` and `experimental__runtimeEnv` sections
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:36:18.416Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: apps/web/CLAUDE.md:0-0
Timestamp: 2025-11-25T14:36:18.416Z
Learning: Applies to apps/web/**/{.env.example,env.ts,turbo.json} : Add environment variables to `.env.example`, `env.ts`, and `turbo.json`
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:37:56.430Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/llm-test.mdc:0-0
Timestamp: 2025-11-25T14:37:56.430Z
Learning: Applies to apps/web/__tests__/**/*.test.ts : Use `describe.runIf(isAiTest)` with environment variable `RUN_AI_TESTS === "true"` to conditionally run LLM tests
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:36:45.807Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/environment-variables.mdc:0-0
Timestamp: 2025-11-25T14:36:45.807Z
Learning: Applies to {.env.example,apps/web/env.ts} : Client-side environment variables must be prefixed with `NEXT_PUBLIC_`
Applied to files:
apps/web/env.ts
📚 Learning: 2025-07-19T15:06:43.730Z
Learnt from: garnertb
Repo: elie222/inbox-zero PR: 580
File: apps/web/.env.example:4-7
Timestamp: 2025-07-19T15:06:43.730Z
Learning: In apps/web/.env.example, boolean environment variables follow an unquoted convention (e.g., LOG_ZOD_ERRORS=true, AUTH_TRUST_HOST=true). Logical grouping of related variables (like auth variables together) is preferred over strict alphabetical ordering for better developer experience.
Applied to files:
apps/web/env.ts
📚 Learning: 2025-11-25T14:38:07.606Z
Learnt from: CR
Repo: elie222/inbox-zero PR: 0
File: .cursor/rules/llm.mdc:0-0
Timestamp: 2025-11-25T14:38:07.606Z
Learning: Applies to apps/web/utils/ai/**/*.ts : LLM feature functions must import from `zod` for schema validation, use `createScopedLogger` from `@/utils/logger`, `chatCompletionObject` and `createGenerateObject` from `@/utils/llms`, and import `EmailAccountWithAI` type from `@/utils/llms/types`
Applied to files:
apps/web/utils/llms/model.ts
🧬 Code graph analysis (1)
apps/web/utils/llms/model.ts (2)
apps/web/env.ts (1)
env(17-246)apps/web/utils/llms/config.ts (2)
providerOptions(18-29)Provider(7-16)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
- GitHub Check: cubic · AI code reviewer
- GitHub Check: Review for correctness
- GitHub Check: test
🔇 Additional comments (4)
version.txt (1)
1-1: LGTM!Version bump is appropriate for the feature additions in this PR.
apps/web/utils/outlook/client.ts (2)
11-12: LGTM!The 10-minute buffer is a sensible safeguard to prevent token expiry during long-running Outlook operations.
103-107: LGTM!The enhanced token refresh logic correctly prevents using tokens that will expire within 10 minutes, ensuring stability during long-running operations.
apps/web/utils/llms/model.ts (1)
71-86: LGTM! The OpenAIstoreparameter implementation is correct.OpenAI's API supports the
storeparameter to control data persistence, and the Vercel AI SDK properly mapsproviderOptions.openai.storeto this parameter. When Zero Data Retention is enabled at the organization level, OpenAI treats the store parameter as false regardless of the request value. Settingstore: falsewhen theOPENAI_ZERO_DATA_RETENTIONenvironment variable is enabled is the correct defensive approach and aligns with the referenced issue.
| AI_GATEWAY_API_KEY: z.string().optional(), | ||
| OLLAMA_BASE_URL: z.string().optional(), | ||
|
|
||
| OPENAI_ZERO_DATA_RETENTION: z.coerce.boolean().optional().default(false), |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Check if OPENAI_ZERO_DATA_RETENTION is in .env.example and turbo.json
echo "=== Checking .env.example ==="
find . -name ".env.example" -type f | head -1 | xargs grep -n "OPENAI_ZERO_DATA_RETENTION" || echo "NOT FOUND"
echo ""
echo "=== Checking turbo.json ==="
find . -name "turbo.json" -type f | head -1 | xargs grep -n "OPENAI_ZERO_DATA_RETENTION" || echo "NOT FOUND"
echo ""
echo "=== Current .env.example (last 20 lines) ==="
find . -name ".env.example" -type f | head -1 | xargs tail -20
echo ""
echo "=== Current turbo.json build.env section ==="
find . -name "turbo.json" -type f | head -1 | xargs jq '.tasks.build.env // empty' 2>/dev/null || echo "Could not parse turbo.json"Repository: elie222/inbox-zero
Length of output: 3299
Add OPENAI_ZERO_DATA_RETENTION to .env.example and turbo.json.
The environment variable is defined in env.ts but missing from .env.example and turbo.json. Add it to .env.example with an example value and to turbo.json under tasks.build.env array.
🤖 Prompt for AI Agents
In apps/web/env.ts around line 63, OPENAI_ZERO_DATA_RETENTION is defined but
missing from configuration examples; add a line to .env.example like
OPENAI_ZERO_DATA_RETENTION=false (or true as appropriate) so users see an
example, and update turbo.json by adding "OPENAI_ZERO_DATA_RETENTION" to the
tasks.build.env array (ensure JSON formatting/commas remain valid).
Add
OPENAI_ZERO_DATA_RETENTIONenv flag and setselectModelOpenAIproviderOptions.openai.store=falsewhen enabled; refresh Outlook tokens when expiry is within 10 minutesIntroduce a boolean
OPENAI_ZERO_DATA_RETENTIONenv var and apply it inutils/llms/model.tsto setproviderOptions.openai.store=falsefor OpenAI models; adjust Outlook client token refresh to trigger when expiry is within 10 minutes; bump version.📍Where to Start
Start with the OpenAI options logic in
selectModelin apps/web/utils/llms/model.ts.📊 Macroscope summarized 648e8c3. 3 files reviewed, 9 issues evaluated, 6 issues filtered, 2 comments posted
🗂️ Filtered Issues
apps/web/env.ts — 0 comments posted, 1 evaluated, 1 filtered
NEXT_PUBLIC_FREE_UNSUBSCRIBE_CREDITSis defined asz.number().default(5)on the client (line 149) but the corresponding value inexperimental__runtimeEnvis sourced fromprocess.env.NEXT_PUBLIC_FREE_UNSUBSCRIBE_CREDITS, which is always a string when set. Withoutz.coerce.number(), providing an env var like"5"will fail validation at runtime instead of being parsed to a number. All other client numeric envs usez.coerce.number(); this one is inconsistent and will cause a runtime parse error when set. [ Out of scope ]apps/web/utils/llms/model.ts — 1 comment posted, 4 evaluated, 2 filtered
providerOptionsis accepted byselectModelbut is only forwarded in theProvider.OPEN_AIandProvider.OPENROUTERbranches. ForGOOGLE,GROQ,AI_GATEWAY,BEDROCK, andANTHROPIC, any providedproviderOptionsare silently ignored, which breaks interface parity and may lead callers to believe options are applied when they are not. Either document the asymmetry or forward/validate options consistently. [ Low confidence ]getBackupModelconstructs an OpenRouter client usingenv.OPENROUTER_API_KEYwithout checking if it exists. IfOPENROUTER_BACKUP_MODELis set butOPENROUTER_API_KEYis missing, the backup model is created with an undefined API key, likely causing runtime failures when used. Add a check to require the API key or returnnull. [ Low confidence ]apps/web/utils/outlook/client.ts — 1 comment posted, 4 evaluated, 3 filtered
scopeparameter for thegrant_type=refresh_tokenrequest to the v2.0 token endpoint. This can lead toinvalid_request/invalid_grantresponses depending on tenant/app configuration. [ Low confidence ]saveTokensis called before validating the token response. Iftokens.access_tokenis missing or empty,createOutlookClient(tokens.access_token)will throw aSafeError, but the function will have already persisted an invalidaccess_token/expires_at, leaving state in a bad/partially updated condition. [ Low confidence ]expires_at:Math.floor(Date.now() / 1000 + tokens.expires_in)assumestokens.expires_inis a finite number. If it is missing or not numeric, the result will beNaNand be stored, breaking future expiry checks. [ Low confidence ]Summary by CodeRabbit
New Features
Bug Fixes
✏️ Tip: You can customize this high-level summary in your review settings.