Skip to content

Verify private-sharing metadata boundaries and record release evidence gaps - #274

Merged
brianorwhatever merged 2 commits into
mainfrom
test/262-private-sharing-evidence
Oct 5, 2026
Merged

brianorwhatever merged 2 commits into
mainfrom
test/262-private-sharing-evidence

Conversation

@brianorwhatever

@brianorwhatever brianorwhatever commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Private-sharing release review lacked one consolidated evidence matrix and direct regressions for several metadata-disclosure paths. Add seven behavioral tests using production handlers for indistinguishable denied HTTP responses, scoped discovery after revocation, invitation projections, cross-resource grant IDs, and scheduled push recipient filtering.

The accompanying matrix links existing authorization, invitation, revocation and offline coverage and records exact web/native, live Convex, provider and storage-cutover prerequisites. No production behavior or rollout policy changes.

Refs #262. This is bounded local verification, not full issue closure or release approval. Installed native links, live subscriptions/concurrency, real provider delivery and legacy storage-signature expiry remain unverified.

Validation:

  • Independent delegated review: no blocking findings; independently reproduced 7/7 new tests under Node and Bun and 175/175 focused tests.
  • Frontend/backend/config TypeScript and direct Vite build pass (existing chunk warnings).
  • Isolated revision: full Bun suite 664 passed, 0 failed; complete E2E suite 116 passed; E2E typecheck passed. An initial parallel local run timed out in the existing offline-compaction stress test; the serialized rerun passed without code changes.
  • Latest commit 7a1e741: unit/E2E, web, Android, unsigned iOS, automated review, and preview checks pass; GitHub reports MERGEABLE. Lighthouse is not triggered for this tests/docs-only diff. Independent follow-up review of the documentation adjustment found no issues.

@railway-app

railway-app Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the boop-pr-274 environment in Friends

Service Status Web Updated
boop ✅ Success (View Logs) Web Oct 5, 2026 at 12:33 am UTC

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No functional issues found. One minor documentation note is inline.

Reviewed changes

I reviewed the new private-sharing verification suite and its evidence document. I ran the suite locally: 7/7 tests pass under both node --test and bun test. To check that the grant-substitution test can actually fail, I removed the grant.listId !== args.listId guard in convex/listGrants.ts. That test then fails as it should.

  • Denied-response indistinguishability: the tests compare full status, body and headers for private and missing list IDs, and for attachment probes. For the attachment probes they also check that the bucket stub records zero storage reads.
  • Discovery and invitation projections: these cover lists:read scope gating on getSharedWithMe, removal of revoked titles even when stale bookmarks exist, and the exact preview, inbox and mail-payload keys for both list and note invitations.
  • Cross-resource grant IDs and push filtering: when a grant ID from a different resource is used, the request is rejected with FORBIDDEN, with no row or scheduler changes. Scheduled list and per-user push actions skip pending, outsider and revoked recipients.
  • Evidence matrix doc: I checked the stated constants against the code and they match. These are the 30/3/10/120 invitation budgets, the seven-day expiry, the 600-second legacy GET signatures, the placeholder assetlinks fingerprint and the null release/authentication-cutover.json fields. All 15 referenced suites exist.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using claude-opus-5-5 | 𝕏

Comment thread docs/private-sharing-verification.md Outdated
@railway-app
railway-app Bot temporarily deployed to Friends / boop-pr-274 October 5, 2026 00:32 Destroyed
@brianorwhatever
brianorwhatever merged commit 7a6786c into main Oct 5, 2026
9 checks passed

This branch was successfully deployed

No deployments
Friends / boop-pr-274 — 7a1e741e Deployed Oct 5, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant