Skip to content

fix(backend): validate capability inputs before ledger reads - #758

Open
Thunderkill016 wants to merge 2 commits into
mainfrom
fix/backend-read-validation-20261004
Open

Thunderkill016 wants to merge 2 commits into
mainfrom
fix/backend-read-validation-20261004

Conversation

@Thunderkill016

@Thunderkill016 Thunderkill016 commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Authenticated invalid capability calls loaded the finance workspace before returning invalid_input. ledger.summary also loaded ledger trust unnecessarily. Validate custom ranges, reversed search dates and malformed cursor structure before those loaders run.

Valid outputs, authorization, financial formulas and paging remain unchanged. Reversed custom report dates still normalize; well-formed search cursor membership still requires the ledger.

Validation: 1984 domain tests pass with no skips; loader-count regressions, unchanged financial goldens, range normalization and paging pass. Typecheck, lint, production build, 191 policy tests, knowledge, architecture and capability manifest pass locally. Selected exact-head CI follows.

Read-only Supabase inspection found historical HTTP 402 responses and a later successful Auth health response. This fix addresses demonstrated avoidable reads; it does not establish the cause of organization egress or prove absence of intrusion. Exact billing usage is unavailable with the current public CLI/API access. No provider configuration, schema, billing, financial data or deployment is changed. Operational logs and credentials remain private.

Daily 24-hour log slices for the preceding week also contain historical 402s before the latest successful probe; a larger single query returned incomplete day coverage and was not treated as a full-window result. These are retained gateway events, not billing bytes or proof of complete incident coverage. Supabase billing FAQ documents 402 as an organization service restriction, which can have several quota/billing causes; attributing it specifically to egress requires billed usage by service/project.

Scope and evidence: docs/plans/active/audit-remediation-20261002.md, backend investigation dated 2026-10-04. Rollback: revert the two runner changes and their regressions. Integration and production operations remain owner decisions.

Final handoff: selected CI 37183132844 passes on 57824a3256c79fb6b5f57a6328341a101103d33b, with 1984 domain tests, 191 policy tests, static quality, production build and browser smoke (184 demo + 31 authenticated-double cases, no reported retries; one existing FCP diagnostic is skipped). CodeQL and secret history scan also pass. Database reset and responsive UI audit are not selected for this runner-only diff; the passing database wrapper is a policy skip, not new database test evidence. Repository provenance records the earlier local/CI snapshot; this PR is the current execution handoff. Ready for owner review/integration decision. No merge or deployment performed; billed egress attribution remains unresolved.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant