Add static reserved username denylist for signup - #632
Conversation
Introduce a code-level denylist for brand, support, infrastructure, and email-local usernames. Wire isReservedUsername into username validation so signup and profile updates reject reserved names.
Split format validation from reserved-name checks so existing /@username routes and public username resolution still work while signup and profile updates reject reserved names.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis PR adds reserved-username detection, splits username validation into format-only and full validation, updates lookup and matching call sites to use the format-only helper, and changes one test database seed username. ChangesReserved Username Validation
Estimated code review effort: 2 (Simple) | ~12 minutes Sequence Diagram(s)sequenceDiagram
participant Caller
participant getUsernameValidationError
participant getUsernameFormatValidationError
participant getReservedUsernameError
Caller->>getUsernameValidationError: validate(username)
getUsernameValidationError->>getUsernameFormatValidationError: check required/pattern
getUsernameFormatValidationError-->>getUsernameValidationError: format error or null
alt format valid
getUsernameValidationError->>getReservedUsernameError: check denylist
getReservedUsernameError-->>getUsernameValidationError: reserved error or null
end
getUsernameValidationError-->>Caller: final error or null
Related Issues: None specified Related PRs: None specified Suggested labels: enhancement, security Suggested reviewers: kentcdodds 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔎 Preview deployed: https://kody-pr-632.kentcdodds.workers.dev Worker: Mocks:
|
The MCP smoke tests sign up through /auth, so the default fixture username must not be on the reserved denylist.
Summary
Adds a static code-level denylist so reserved usernames cannot be claimed during signup or profile updates. Covers brand/product names, support/trust surfaces, infrastructure/route-like names, and common email mailbox locals (postmaster, abuse, noreply, etc.). No database changes and no email routing changes.
Changes
reserved-usernames.tswithisReservedUsername/getReservedUsernameErrorgetUsernameValidationErrornow rejects reserved names (signup, profile update, admin user creation)getUsernameFormatValidationErrorso existing/@usernamerouting and public username resolution are unaffectedTesting
npx vitest run --project node-unit packages/worker/src/app/reserved-usernames.node.test.tsnpm run testvia pre-push hook (unit + E2E)System recap — extends existing primitive (medium risk)
Mode: recap · Base:
main· Head:cursor/username-denylist-8ab0Classification: extends — tightens signup/profile username validation on the existing auth primitive; no new primitives or storage.
Primitives touched
session-authSystem map
What changed
Summary by CodeRabbit
New Features
Bug Fixes
Tests
Chores