Commit Graph

6 Commits

Author SHA1 Message Date
can1357 dc2eb47297 security: added slot_uid-aware git env and workspace ownership handling
- Added optional slot_uid handling to push requests and git operations, validating IDs 1..65535.
- Passed slot-specific subprocess kwargs into git helpers, including safe.directory, HOME, user/group and umask.
- Injected slot-safe repo env helpers to scrub secrets, force git identity, and disable terminal prompts.
- Adjusted workspace and cache permissioning so slot users own workspaces with targeted chmod/chown behavior.
- Added tests for slot UID propagation, safe-directory env, and cross-slot push/retry behavior in unit and e2e suites.
2026-05-16 19:03:56 +02:00
can1357 f0e3a70d14 feat: added question auto-close scheduling, API wiring, and host tooling
- Implemented question auto-close scheduling with configurable enablement, delay, and scan interval.
- Added reaction lookup and issue-close operations across backend, proxy, and client APIs.
- Extended host tools and app server wiring to append auto-close suffixes, run scheduler, and cancel closures.
- Updated documentation and env examples with question-autoclose settings and behavior notes.
- Added pending_closures persistence and lifecycle handling to claim, finalize, requeue, and cancel rows.
- Added tests covering scheduler, DB, proxy, server, and host-tool cancellation scenarios.
2026-05-15 09:38:38 +02:00
can1357 7cd80f01a7 fix: repaired git fetch-prune flow for missing alternates and bad refs
- Extended the pool fetch path to prune missing git object alternates, delete bad refs reported by git, and retry fetch operations after each repair.
- Added a Database helper to persist issue branch updates and verified fetch repair behavior with a new test that ensures stale alternates and bad refs are removed.
2026-05-15 03:59:21 +02:00
can1357 bcf4db2ca9 refactor: restructured proxy server GitHub event flow and response tests 2026-05-15 02:32:36 +02:00
can1357 36174740f8 feat(proxy): implemented query-aware HMAC signing for proxy targets
- Added proxy-mode settings loading via load_proxy_settings in src/robomp/config.py to validate required serve-time env.
- Implemented query-aware HMAC signing and verification for request targets in src/robomp/proxy_client.py and src/robomp/proxy/server.py.
- Added hard body size limits in src/robomp/proxy/server.py returning 413 before full read or auth.
- Added origin URL validation in src/robomp/proxy/server.py before git push to block non-github or mismatched repos.
- Added configurable git timeouts in src/robomp/git_ops.py and enforced wall-clock limits in src/robomp/proxy/server.py git handlers.
- Updated src/robomp/git_ops.py push to pin --force-with-lease to refs/remotes/origin/<branch> for safer concurrent push protection.
2026-05-15 02:11:46 +02:00
can1357 1a66fab0ea test(tests): added proxy HMAC auth and git flow contract tests
- Added proxy HMAC contract tests for valid signatures and 401 responses on missing, bad, and stale headers.
- Added end-to-end tests for proxy request/response mapping across repo, issue, comment, review, and pull-request endpoints.
- Added GitHubProxyClient and ProxyGitTransport git flow tests for clone/push success and head-drift/repo mismatch failures.
2026-05-15 01:53:50 +02:00