Repository navigation
Preserve trusted legacy Stack exchanges - #145
Conversation
📝 WalkthroughWalkthroughStack tenant exchanges now validate the trusted control token before capabilities. Empty capability input defaults to ChangesStack tenant capability handling
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
internal/proxy/multitenant_test.go (1)
528-528: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winAdd a negative regression test for the capability fallback.
The positive case verifies the default capabilities for an authenticated exchange. Add a second request with the same body and
Authorizationheader, but withoutX-Subrouter-Stack-Control-Token. Asserthttp.StatusUnauthorized.The PR objective requires omitted capability lists to remain gated by the trusted Stack control-plane credential.
Example
+ unauthenticated := httptest.NewRequest( + http.MethodPost, + "/_subrouter/auth/stack", + strings.NewReader(`{"teamId":"team-123","teamName":"Acme"}`), + ) + unauthenticated.Header.Set("Authorization", "Bearer stack-access") + unauthenticatedResponse := httptest.NewRecorder() + handler.ServeHTTP(unauthenticatedResponse, unauthenticated) + if unauthenticatedResponse.Code != http.StatusUnauthorized { + t.Fatalf("unauthenticated exchange status = %d", unauthenticatedResponse.Code) + }Also applies to: 558-563
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@internal/proxy/multitenant_test.go` at line 528, Add a negative regression case alongside the authenticated exchange test using the same request body and Authorization header but omitting X-Subrouter-Stack-Control-Token. Send it through the existing handler/test flow and assert that the response status is http.StatusUnauthorized, preserving the positive default-capabilities case.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@internal/proxy/multitenant_test.go`:
- Line 528: Add a negative regression case alongside the authenticated exchange
test using the same request body and Authorization header but omitting
X-Subrouter-Stack-Control-Token. Send it through the existing handler/test flow
and assert that the response status is http.StatusUnauthorized, preserving the
positive default-capabilities case.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 48cd669e-cef0-4c5a-bf65-ea8b2c2dce1d
📒 Files selected for processing (2)
internal/proxy/multitenant.gointernal/proxy/multitenant_test.go
Accepts an omitted capability list only after authenticating the trusted Stack control-plane credential, preserving the pre-capability broker during rollout. Explicit capability-scoped exchanges remain unchanged. Adds coverage proving the compatibility exchange receives use and account-management scope.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Preserves legacy trusted Stack exchanges by allowing omitted capability lists only after verifying the control-plane token. For trusted calls without capabilities, we default to manage_accounts and use; explicit capability-scoped exchanges are unchanged.
X-Subrouter-Stack-Control-Tokenbefore capability parsing to block untrusted fallbacks.Written for commit 4a48c8c. Summary will update on new commits.
Summary by CodeRabbit
manage_accountsandusecapabilities.