Skip to content

fix(maintenance): preserve durable history and harden shared inputs - #561

Merged
DevSkyLex merged 2 commits into
developfrom
fix/security-maintenance-review
Oct 8, 2026
Merged

DevSkyLex merged 2 commits into
developfrom
fix/security-maintenance-review

Conversation

@DevSkyLex

@DevSkyLex DevSkyLex commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Context

Change Summary

  • Refuse deletion when interventions/tasks retain expenses, inventory movements or maintenance occurrences; serialize these checks with concurrent physical declarations.
  • Align stock/receipt lock ordering, atomically retain supplier/order creation receipts and complete equipment setup replay comparisons. Widen supplier codes with an additive main-database migration.
  • Bound time journals and revision history, expose explicit continuation metadata, and allow beneficiary-only requests before both counting and pagination.
  • Validate image geometry before decoding, escape default email text, protect reversible business CSV exports, and require independently reviewed SSH host keys.

Review Guide

Modules / Areas

  • Intervention, Inventory, Procurement, Maintenance, MaintenanceCost, Equipment, Shared, Notification and deployment workflows.

Main Files / Entry Points

  • Intervention workflow writers and time query/provider/repository paths.
  • Inventory stock handler and owner-published history ports.
  • Procurement handler/repository and Version20261008121000.
  • Shared image/CSV adapters, default email adapter/template and deploy-vps.yml.

Reviewer Focus

  • Business logic correctness and organization/beneficiary scope
  • Persistence, transaction ordering and main/auth wiring
  • API contract, collection bounds and architecture boundaries
  • MODULE.md invariants and deployment impact

Functional Impact

  • User-visible behavior and public response shape changed
  • Additive schema migration and deployment secret required
  • Journal callers must follow explicit pagination/continuation metadata

Before

Retries could create duplicate resources; deletion could erase durable maintenance facts; shared parsers and renderers accepted unsafe input; a journal page could be broader than a captured beneficiary-only UI scope.

After

Durable facts prevent deletion, retry identities stay payload-bound, shared boundaries validate/escape input and beneficiary-only reads apply the same restriction to entries and totals.

Risk And Rollback

  • Security, organization scope, persistence and deployment process involved
  • Keep the additive supplier column widening when reverting application code; narrowing refuses codes longer than 64 characters.
  • Preserve the SSH trust gate during image rollback. A prior image is not a database rollback.

Validation

Local Validation

  • Complete primary remediation suite: 15,556 tests, 125,467 assertions, isolated PostgreSQL.
  • Final beneficiary-scope change: 26 tests, 2,631 assertions, including the complete Workload API suite, isolated PostgreSQL 17/UTC.
  • Full PHPStan, coding style, both Deptrac gates, container/YAML lint, OpenAPI export and auth/main schema checks passed.
  • Seven actual-shell SSH trust tests passed; independent security, architecture and contract re-reviews completed.

CI Validation

  • All 16 active PR checks passed on API head 7094f77; mutation and PR Sonar were skipped by the existing workflow.
  • Merged into develop at 308e1c45751ab09962a090d053f1bd798f59bb39. Integrated CI passed all tests and 90% coverage, but Sonar rejected its quality gate after a successful scan; no deployment ran.
  • Development host-key reference configured from the operator's existing known_hosts entry, matching the public key shown by the usual SSH session.

Deployment Notes

  • Migration order matters
  • New secret required
  • Apply main migration before the companion frontend. Set VPS_SSH_KNOWN_HOSTS from an authenticated operator/provider channel in each deployment environment.

Known Gaps

  • Production host-key configuration and deployment remain outside this delivery. Development environment protection settings were not changed.
  • Unchanged repository code is outside this correction-diff re-review.

@github-actions github-actions Bot added area:github GitHub workflows, templates, or repository automation area:organization Organization or onboarding domain changes area:facility Facility domain changes area:equipment Equipment domain changes area:user User domain changes area:shared Shared, notification, or audit changes area:tests Test-only changes area:config Configuration or runtime settings changes risk:database Database schema, migrations, or persistence risk risk:api-contract API contract or serialization risk size:xl Very large PR: 800 changed lines or more state:draft Draft pull request labels Oct 8, 2026
@DevSkyLex
DevSkyLex marked this pull request as ready for review October 8, 2026 17:20
@github-actions github-actions Bot added state:ready Ready for review and removed state:draft Draft pull request labels Oct 8, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T17:24:27.884736Z 7094f77 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@DevSkyLex
DevSkyLex merged commit 308e1c4 into develop Oct 8, 2026
19 checks passed
@DevSkyLex
DevSkyLex deleted the fix/security-maintenance-review branch October 9, 2026 00:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:config Configuration or runtime settings changes area:equipment Equipment domain changes area:facility Facility domain changes area:github GitHub workflows, templates, or repository automation area:organization Organization or onboarding domain changes area:shared Shared, notification, or audit changes area:tests Test-only changes area:user User domain changes risk:api-contract API contract or serialization risk risk:database Database schema, migrations, or persistence risk size:xl Very large PR: 800 changed lines or more state:ready Ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant