Repository navigation
fix(core): carry an audit source into sandbox deployment writes - #18
Merged
Merged
Conversation
The PUT and POST /core/v1/sandbox/deployment handlers never attached the administrator audit source. A changed selection makes ExecutionOperations.Update record a "change" audit in the committing transaction, which requires adminaudit.Source on the context; without it the transaction fails with adminaudit.ErrInvalidSource and the route answers 400 invalid_request. An identical no-op selection skips the audit and still returned 200, which hid the fault and broke Web's edit action. Attach the source in both handlers, matching the reset routes, and cover the change and initialize paths with a regression test. Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
修复
PUT /core/v1/sandbox/deployment在提交有变化的部署选择时返回400 invalid_request、导致 Web 控制台「编辑沙箱部署」无法保存的问题(OAC-22)。根因
updateSandboxDeployment/initializeSandboxDeployment两个 handler 未调用setAdminAuditSource,请求上下文里没有adminaudit.Source。变更路径ExecutionOperations.Update在!equal(或替换凭据)时会在提交事务中tx.RecordAudit("change", …);auditpg.RecordDeploymentMutation要求 ctx 携带该 source,缺失即返回adminaudit.ErrInvalidSource,被writeDeploymentError映射为400 invalid_request。完全相同(no-op)的选择跳过 audit,所以仍返回 200,掩盖了故障。/core/v1的DeploymentAuthenticator只校验 Core key,不注入 audit source。改动
services/core/internal/api/sandbox_deployment_setup.go:在updateSandboxDeployment与initializeSandboxDeployment调用操作前补setAdminAuditSource(r, ""),与startSandboxReset/cancelSandboxReset保持一致。部署级 mutation 的ProjectID为空,符合adminaudit.ValidateDeploymentMutation。services/core/internal/api/sandbox_deployment_audit_test.go:新增回归测试,断言 POST(initialize)与 PUT(change)传入操作的上下文都带有adminaudit.Source,且该 source 能通过ValidateDeploymentMutation(即真正可落 audit)。验证
go test ./services/core/internal/api/ -run TestSandboxDeploymentMutationsCarryAdministratorAuditSource -count=1→ PASS。仅回退 handler 改动后重跑同一测试 → FAIL,
initialize与change两条路径都报carried no deployment audit source,证明测试确实覆盖该回归。go test ./services/core/internal/api/ -count=1→ ok(40.5s)。services/core/...(排除internal/store)与packages/agents-client/...全量单测 → 除下述环境项外全部 ok。python3 -m unittest discover -s services/core/tests -p official_diagnostics_test.py→ OK;python3 services/core/deploy/e2b/managed_init_test.py→ OK。python3 scripts/check-names.test.py+python3 scripts/check-names.py→ 通过;gofmt -l无输出。已知限制 / 未运行
make check-core未完整执行:本环境未配置OAC_TEST_DATABASE_URL,check-core-store与依赖测试库的包会跳过/无法运行。因此「PUT 返回 200 且落库(generation 递增、specification 更新)」的 DB 端到端行为、以及 Web「编辑沙箱部署」的端到端保存,需在带专用 PostgreSQL 的 CI/验证环境确认。services/core/internal/nativeinstaller的两个测试(TestBootstrapCommandDiscardsTimedOutResponse、TestBootstrapDownloadsVerifiedPlatformAcrossHTTPSRedirect)在本环境失败,原因是安装包 HTTPS 下载受代理 TLS 拦截(curl 60证书校验失败),与本次改动无关;带直连/正确 CA 的环境应通过。