Repository navigation
fix(sysmlapi): keep the bearer token on the configured server and the branch read honest - #1029
Merged
Merged
Conversation
… branch read honest A next-page link to another host, port or plaintext is refused like a redirect there instead of being followed with the token; the repository URL the environment supplies is held to the plaintext rule before any request; a branch read before its first commit is still checked for a head that appeared since; and %publish by name resolves the project the session loaded by id, so a namesake no longer makes the name ambiguous. Co-Authored-By: jason.han <hanhuijun@gmail.com>
Contributor
Author
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
Contributor
Author
…till names so A tracked project renamed or deleted on the server no longer answers to the requested name, so the publish falls back to resolving the name afresh under the ambiguity rules instead of committing into the renamed project or creating a new one over its namesake. Co-Authored-By: jason.han <hanhuijun@gmail.com>
5 of 6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Four defects in the SysML v2 API repository client behind
%repo,%projects,%loadand%publish, each fixed at its root ininternal/translate/interop/sysmlapiand the REPL's repository commands:Link: rel="next"header could carry the bearer token to another host.pagedandElementsfollowednextLinkwherever it resolved, andDoattachesAuthorization: Bearerto any URL. The rulecheckRedirectalready applied to redirects is now one method,tokenStays, shared by redirects and linked pages (nextPage): with a token, a successor URL that is plaintext, leaves https, or names another host or effective port is refused ("the token is for host only") and never requested. Without a token the link is followed as before.repoBasereturnedDefaultURL()untested, soFLEXO_SYSMLV2_URL=http://…off this machine plusFLEXO_INTEROP_TOKENsent the token in the clear on every command.repoBasenow holds the default to the sameCheckURLas%repo <url>, so%repo,%projects,%load,%publishand the project-name completions surface the samePlaintextErrorbefore any request, lifted the same way byFLEXO_ALLOW_PLAIN_HTTP=1.Repository.Commitskipped the head re-read after reading a headless branch.seen == ""meant both "never read" and "read, no head yet", so a change set computed against the empty graph was posted onto a branch another writer had since given its first commit.Repositorynow tracksreadapart fromseen; a head read byGraph, resumed or written is always re-read before a commit, and a branch read without a head must still have none, elseStaleBranchError.%publishby name could not reach the project a session loaded by id.Publishresolved the target by name only, so a namesake on the server made the loaded project unreachable. When the tracked state is for the selected server and the requested name is the tracked project's name, the stored id resolves the project — provided the server still has it under that name: a tracked project since renamed or deleted is no match, and the name is resolved afresh under the usual rules.--projectnaming another project and the ambiguous-name refusal when no tracked project matches are unchanged.Docs (
docs/reference/repl-commands.md,docs/guide/12-jupyter.md) now say the plaintext rule covers the environment's URL and that a redirect or next-page link off the server is refused with the token.How it was verified
New tests, each failing on
develop's code and passing here:sysmlapi:TestLinkedPagesKeepTheTokenOnTheServer— two httptest servers, the first linkingrel="next"to the second: the error names both hosts and not the token, the second server sees no request, and a tokenless client still follows the link (ProjectsandElements);TestCommitRefusesAHeadThatAppearedSinceTheRead— branch with no head atGraph, a head atCommit→StaleBranchError{Seen: "", Head: "c1"}, no POST; and the commit proceeds once the branch is headless again.repl:TestDefaultURLIsHeldToThePlaintextRule—t.Setenvof an off-hosthttp://URL and a token:%repo,%projects,%load --id,%publishand completion refuse before any request, the message namesFLEXO_ALLOW_PLAIN_HTTPand not the token, and the opt-in lifts it;TestPublishByNameUpdatesTheLoadedNamesake— two projects namedVehicles,%load --idthe first,%publish Vehiclesupdates it, while an untracked session is still refused as ambiguous and--projectstill selects explicitly; once the tracked project is renamed, and once it is deleted,%publish Vehiclesgoes to the namesake and creates nothing.Gates run locally:
Checklist
make testandmake lintpass locallychanges/unreleased/<slug>.<section>.md, not as an edit toCHANGELOG.mdmake docs-countsrun if a gate count moved (compliance rows need nothing: the census is counted at docs build) — no gate count movedF4,K5) in the body, docs, or changelogLink to Devin session: https://nasa-jpl-demo.devinenterprise.com/sessions/650e2bc343d24b67a3333c972e20b8b7
Open in Devin Desktop: https://nasa-jpl-demo.devinenterprise.com/desktop/session/650e2bc343d24b67a3333c972e20b8b7?variant=devin
Requested by: @HuiJun