Repository navigation
fix(backend): validate capability inputs before ledger reads - #758
Open
Thunderkill016 wants to merge 2 commits into
Open
Thunderkill016 wants to merge 2 commits into
Thunderkill016 wants to merge 2 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Authenticated invalid capability calls loaded the finance workspace before returning
invalid_input.ledger.summaryalso loaded ledger trust unnecessarily. Validate custom ranges, reversed search dates and malformed cursor structure before those loaders run.Valid outputs, authorization, financial formulas and paging remain unchanged. Reversed custom report dates still normalize; well-formed search cursor membership still requires the ledger.
Validation: 1984 domain tests pass with no skips; loader-count regressions, unchanged financial goldens, range normalization and paging pass. Typecheck, lint, production build, 191 policy tests, knowledge, architecture and capability manifest pass locally. Selected exact-head CI follows.
Read-only Supabase inspection found historical HTTP 402 responses and a later successful Auth health response. This fix addresses demonstrated avoidable reads; it does not establish the cause of organization egress or prove absence of intrusion. Exact billing usage is unavailable with the current public CLI/API access. No provider configuration, schema, billing, financial data or deployment is changed. Operational logs and credentials remain private.
Daily 24-hour log slices for the preceding week also contain historical 402s before the latest successful probe; a larger single query returned incomplete day coverage and was not treated as a full-window result. These are retained gateway events, not billing bytes or proof of complete incident coverage. Supabase billing FAQ documents 402 as an organization service restriction, which can have several quota/billing causes; attributing it specifically to egress requires billed usage by service/project.
Scope and evidence:
docs/plans/active/audit-remediation-20261002.md, backend investigation dated 2026-10-04. Rollback: revert the two runner changes and their regressions. Integration and production operations remain owner decisions.Final handoff: selected CI 37183132844 passes on
57824a3256c79fb6b5f57a6328341a101103d33b, with 1984 domain tests, 191 policy tests, static quality, production build and browser smoke (184 demo + 31 authenticated-double cases, no reported retries; one existing FCP diagnostic is skipped). CodeQL and secret history scan also pass. Database reset and responsive UI audit are not selected for this runner-only diff; the passing database wrapper is a policy skip, not new database test evidence. Repository provenance records the earlier local/CI snapshot; this PR is the current execution handoff. Ready for owner review/integration decision. No merge or deployment performed; billed egress attribution remains unresolved.