Repository navigation
Stop the VOD loader from logging user data and hiding Twitch errors - #83
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 2 included reviews per hour; 0 remain after this review. Walkthrough
ChangesVOD Marker Flow
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to VOD marker loading keeps using the creator's connected Twitch account, as the app documents, and now reports Twitch request failures instead of silently returning empty results. No concrete defect remains. Note that the PR description still describes a viewer-only access rule that the final code intentionally does not implement. Security Architecture ReviewSecurity architecture risk: 🟠 High · up to Signed-in viewers with a Twitch connection can still receive another connected creator’s private VOD markers. This PR does not introduce that exposure, but it also does not deliver its stated access restriction. It improves error handling and removes sensitive logging. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
|
The VOD page reads markers with the creator's stored token again, as on main, and the page keeps its 60 second revalidate. Removes the viewer token path and the "markers are private" page. Keeps the clear fixes: no more logs of the Clerk user or Twitch payloads, non-OK Twitch responses throw, and an empty videos list gives no markers. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Note 🤖 Claude Opus 5.5 responding on behalf of Theo @greptileai review 6b47ebd changes the scope of this PR. Marker access stays as on main, and the PR now only fixes loader logging, Twitch error handling, and the empty |
The VOD page loader had three problems:
videoslist, the page crashed.Now the loader does not log that data. A failed Twitch request throws with its status code, so you see the error page and not an empty list. An empty
videoslist gives no markers.Marker access does not change. The page still reads markers with the creator's stored Twitch token, so any signed-in user can see a connected creator's markers. This is intentional (see bf5e5c5 and the demo link from #58). The first version of this PR used the viewer's token and showed a "markers are private" page. This version removes that change and keeps the 60 second revalidate.
#81 rewrites the same loader and includes these fixes. When it rebases, it can keep its own loader.
Tests:
pnpm test(33 passed),pnpm typecheck,pnpm lint, andpnpm build. The two new tests fail on main.Created with GPT-6 Astra in Codex. Takeover fixes by Claude Opus 5.5 in Claude Code.
🤖 Generated with Claude Code
Summary by CodeRabbit