Repository navigation
Verify private-sharing metadata boundaries and record release evidence gaps - #274
Merged
Merged
Conversation
6 tasks
|
🚅 Deployed to the boop-pr-274 environment in Friends
|
There was a problem hiding this comment.
ℹ️ No functional issues found. One minor documentation note is inline.
Reviewed changes
I reviewed the new private-sharing verification suite and its evidence document. I ran the suite locally: 7/7 tests pass under both node --test and bun test. To check that the grant-substitution test can actually fail, I removed the grant.listId !== args.listId guard in convex/listGrants.ts. That test then fails as it should.
- Denied-response indistinguishability: the tests compare full status, body and headers for private and missing list IDs, and for attachment probes. For the attachment probes they also check that the bucket stub records zero storage reads.
- Discovery and invitation projections: these cover
lists:readscope gating ongetSharedWithMe, removal of revoked titles even when stale bookmarks exist, and the exact preview, inbox and mail-payload keys for both list and note invitations. - Cross-resource grant IDs and push filtering: when a grant ID from a different resource is used, the request is rejected with
FORBIDDEN, with no row or scheduler changes. Scheduled list and per-user push actions skip pending, outsider and revoked recipients. - Evidence matrix doc: I checked the stated constants against the code and they match. These are the 30/3/10/120 invitation budgets, the seven-day expiry, the 600-second legacy GET signatures, the placeholder assetlinks fingerprint and the null
release/authentication-cutover.jsonfields. All 15 referenced suites exist.
claude-opus-5-5 | 𝕏
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Private-sharing release review lacked one consolidated evidence matrix and direct regressions for several metadata-disclosure paths. Add seven behavioral tests using production handlers for indistinguishable denied HTTP responses, scoped discovery after revocation, invitation projections, cross-resource grant IDs, and scheduled push recipient filtering.
The accompanying matrix links existing authorization, invitation, revocation and offline coverage and records exact web/native, live Convex, provider and storage-cutover prerequisites. No production behavior or rollout policy changes.
Refs #262. This is bounded local verification, not full issue closure or release approval. Installed native links, live subscriptions/concurrency, real provider delivery and legacy storage-signature expiry remain unverified.
Validation:
7a1e741: unit/E2E, web, Android, unsigned iOS, automated review, and preview checks pass; GitHub reports MERGEABLE. Lighthouse is not triggered for this tests/docs-only diff. Independent follow-up review of the documentation adjustment found no issues.