Repository navigation
manual verification: review follow-ups and persona capture fix - #336
Merged
Merged
Conversation
… notes the privacy deletion tombstoned the identity and purged blobs but left submitted_fields, the persona signal snapshot, inquiry ids, access tokens, event ip/user agent, free-text event data, comment bodies, qa sample notes and checklist notes behind on verification cases. scrub them in place (rows and event keys stay so the audit shape survives), and include case paper trail versions and case document break-glass records in the version cleanup.
…ul save the document_break_glass event was written in the finder, before pundit and before the record saved, so a blank reason or an unauthorised user left an append-only event recording access that never happened. write it inside the save transaction with the persisted reason.
booking fields were written before the aasm check and the scheduled mail fired on every delivery, so retries double-mailed and a reschedule on a frozen case mutated it before raising. check allowed states first, do all writes under with_lock in one transaction, treat an identical uid+start as a duplicate, and ignore cancellations for a stale uid. ignored deliveries leave a call_booking_ignored audit event.
persona puts the generic status text in title and the actual cause in detail; we only surfaced title, so sentry showed 'Bad request' with no reason.
- denial no longer fires the shared rejected_* mailers, which relayed the internal reason and a resubmit link to the user on top of the reason-free case email. the staff-only slack deactivation ping on a fatal reason is kept. - the persona capture path required no attestation, biometric consent or submitted fields. both paths now start from one form that records them, and submit_docs! refuses to transition without them from any caller. a webhook arriving without consent on record drops the capture and clears the inquiry. - the link reminder scope rotated tokens for users already mid-flow, locking them out. consumed tokens are excluded and rechecked under lock. - rotate_access_link! persisted the new token before checking the transition. it now runs under with_lock with the check first, and a plain resend keeps access_token_used_at; only request-redo re-arms the gate. - events, comments and documents leave the destroy cascade, so a paranoid soft-delete of a case no longer trips the append-only event guard. hard delete of a case raises on purpose. - non-file or zero-byte upload params get a friendly flash instead of a 500. - persona downloads are sniffed with marcel instead of hardcoded image/jpeg; unsupported files are rejected with an audit event and a capture with zero usable files no longer advances. - the capture template's prefill keys are underscored, not hyphenated; the hyphenated keys were 400ing every capture start in production.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
follow-ups from the code review of #306, plus the production fix for the persona capture flow.
production fix
every "scan with your camera" start was 400ing. the capture template's prefill field keys are underscored (
name_first,name_last,email_address) where the kyc templates use hyphens, and persona rejects prefill for unknown keys. keys corrected, and persona api errors now include thedetailfield so the next one says why in sentry.review findings
rejected_*mailers, which carry the internal rejection reason + details and a resubmit link, on top of the reason-free case email. the user-facing mailers are suppressed for manual calls; the staff-only slack deactivation ping on a fatal reason stays.submit_docs!has a guard so no caller can advance without them. a webhook arriving without consent on record drops the capture. direct upload is now strict server-side about the four required fields too.submitted_fields, the persona signal snapshot, inquiry ids, access tokens, event ip/ua, free-text event data, comment bodies, qa sample notes and checklist notes all survived a privacy deletion. scrubbed in place; rows and event keys stay so the audit shape survives.with_lock, check first, and a plain resend keepsaccess_token_used_at. only request-redo re-arms the gate.call_booking_ignoredevent.behaviour changes worth a glance
requiredonly).call_booking_ignoredandcapture_files_rejected.testing
all touched spec files: 212 examples, 0 failures. rubocop clean on changed files.