Skip to content

fix(link): revalidate context requests against live keys - #651

Closed
luvs01 wants to merge 3 commits into
devfrom
codex/fix-hub-link-policy-revocation-bypass
Closed

luvs01 wants to merge 3 commits into
devfrom
codex/fix-hub-link-policy-revocation-bypass

Conversation

@luvs01

@luvs01 luvs01 commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Motivation

  • The hub-link listener built a per-request policy snapshot at entry and closed the context-route revalidation over that snapshot, allowing a revoked API key to still authorize an in-flight context relay dispatch.
  • The change ensures the context-route admission revalidation uses the live listener policy so a deleted or rotated key cannot complete an outstanding request.

Description

  • Rebuild the hub-link policy at the time of post-body, pre-dispatch revalidation by changing the revalidation closure to () => resolveApiAuth(req, ingress === "hub-link" ? linkPolicy() : policy) in src/server/index/serve-options.ts so hub-link requests consult current config/links instead of the original snapshot.
  • Add a focused regression test in tests/server/link-listener-admission.test.ts that asserts the code path contains the new revalidation form and that replacing config.apiKeys causes resolveApiAuth to reject the previously-valid linked key.
  • Add a handler-level regression test in tests/server/context-history-ownership.test.ts that drives the real post-body revalidation gate with the same requestPolicyView/resolveApiAuth pair the listener uses: a key revoked mid-request is refused before dispatch, while a closure over the request-entry snapshot would still admit it.
  • Update structure/runtime.md to document the in-flight revocation guarantee for the hub-link listener so the runtime contract reflects the fix.

Testing

  • Ran bun test tests/server/context-history-ownership.test.ts and all 6 tests passed, including the new live-policy revalidation case.
  • Ran bun test tests/server/link-listener-admission.test.ts and all 4 tests passed (Bun 1.4.2).
  • Ran bun run typecheck and it completed successfully.
  • Ran bun run structure:check and it completed successfully after the doc edit.
  • Ran bun run privacy:scan and it passed.
  • Ran git diff --check and it reported no problems.

Codex Task

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: luvs01/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: ac8ffd28-4654-4946-a61c-7058228d0b0c


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions github-actions Bot added the bug Something isn't working label Sep 26, 2026
@github-actions

Copy link
Copy Markdown

✅ Deterministic PR hygiene checks passed.

Repository owner deleted a comment from devin-ai-integration Bot Sep 26, 2026
Replace the assertion-only coverage for the hub-link post-body revalidation with a handler-level regression test in tests/server/context-history-ownership.test.ts. The test builds the same requestPolicyView/resolveApiAuth pair the listener uses, revokes the linked key mid-request, and proves the live-policy closure refuses dispatch while the request-entry snapshot would still admit it.
devin-ai-integration[bot]

This comment was marked as resolved.

The revalidation test resolves serve-options.ts via the shared
repoPath() helper instead of a test-relative URL, so relocating the
test file cannot silently point it at a different tree.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
@luvs01

luvs01 commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

이관됨: lidge-jun#5968

@luvs01

luvs01 commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

동일 수정이 상류 저장소에 제출되어 이 포크 PR의 목적은 달성됐습니다.

@luvs01 luvs01 closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aardvark bug Something isn't working codex

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant