Skip to content

fix(docs): correct two stale THREAT_MODEL.md line anchors for auth_middleware.py - #17082

Merged
mrveiss merged 1 commit into
mainfrom
fix-threat-model-anchor-drift
Sep 19, 2026
Merged

mrveiss merged 1 commit into
mainfrom
fix-threat-model-anchor-drift

Conversation

@mrveiss

@mrveiss mrveiss commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

Thinking Path

Found while diagnosing red python-suite shards on #17016 (an unrelated PR): repo_tests/threat_model_anchors_resolve_test.py::test_anchor_points_at_its_symbol failed for two symbols in autobot-backend/auth_middleware.py. Confirmed the drift exists on origin/main itself, not a stale-branch artifact -- check_admin_permission is really defined at line 964 but THREAT_MODEL.md cites :967, and verify_internal_api_key is really at 951 but cited as :954. Both off by exactly 3 lines, consistent with #17042 (which touched auth_middleware.py) adding lines above both functions without updating the doc's anchors.

What Changed

  • docs/developer/THREAT_MODEL.md: corrected both anchors (:967 -> :964, :954 -> :951) to match the real current line numbers.

Verification

$ python3 -m pytest repo_tests/threat_model_anchors_resolve_test.py -q
41 passed

Failed with the exact two assertions this fixes before the change; all 41 pass after.

Model Used

Claude Sonnet 5

Single-issue rationale

A base-branch doc/code drift blocking a repo-wide guard test for every PR; needs its own immediate, minimal fix rather than riding along with unrelated work.

Issue Link

No issue -- a two-line doc-anchor fix this PR both finds and fixes; filing one would only add ceremony ahead of a fix already verified and ready to land.

Checklist

  • Tests added/updated and passing locally
  • No hardcoded values introduced
  • Commit message follows <type>(scope): <description> (#issue)

Summary by CodeRabbit

  • Documentation
    • Updated line references in the threat model to reflect current implementation locations.
    • No behavioural or security-rule changes.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: mrveiss/AutoBot-AI/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3aa9fa47-deb7-49ae-a282-758a14dbc5ab

📥 Commits

Reviewing files that changed from the base of the PR and between 4f09d9c and 11d13ee.

📒 Files selected for processing (1)
  • docs/developer/THREAT_MODEL.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The threat model updates the declaration line references for check_admin_permission and verify_internal_api_key. No behaviour or security rule changed.

Changes

Threat model references

Layer / File(s) Summary
Update security check references
docs/developer/THREAT_MODEL.md
The references for check_admin_permission and verify_internal_api_key now use their current declaration lines. The required admin dependency and service-to-service authentication rule remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: correcting two stale line anchors in THREAT_MODEL.md for auth_middleware.py.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Notice: 29 open PRs — past the runaway threshold (25)

There is no PR queue limit, and this is not a request to defer this PR. Work proceeds one issue at a time without a cap on open PRs; review capacity is the constraint.

This notice only means the count is high enough to be worth a glance for a runaway — something opening PRs in a loop, or a merge pipeline that has stalled so nothing is draining.

Currently open:

If the queue is draining normally, ignore this. Otherwise:

  1. Check whether CI is dispatching at all — see the ci-dispatch-watchdog status on these PRs
  2. Merge the ones whose CI has finished and review has passed: gh pr merge <number> --squash --delete-branch
  3. Look for a loop opening near-identical PRs

Warn-only runaway detector — .github/workflows/pr-queue-gate.yml. It never blocks a merge.

…ddleware.py (#17042)

check_admin_permission and verify_internal_api_key both drifted 3 lines
from their cited anchors (:967/:954 vs actual :964/:951) after #17042
added lines to auth_middleware.py without updating THREAT_MODEL.md.
Confirmed the drift exists on main itself, not just a stale branch --
blocks repo_tests/threat_model_anchors_resolve_test.py (and therefore the
whole python-suite shard it lands in) for every PR until fixed.
@mrveiss
mrveiss force-pushed the fix-threat-model-anchor-drift branch from 11d13ee to 486cf3d Compare September 19, 2026 03:38
@mrveiss
mrveiss merged commit 9513b2d into main Sep 19, 2026
49 checks passed
@mrveiss
mrveiss deleted the fix-threat-model-anchor-drift branch September 19, 2026 04:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant