Repository navigation
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude Thermo-nuclear review of this PR:
|
|
Follow-up: all four findings fixed, nothing left. Commands run: cargo +1.98.0 fmt --all --check; clippy --workspace --all-targets -D warnings; cargo test -p codexbar --lib (secure_file, cookie_cache, settings, credentials filters; 157 passed). |
Adversarial validation (lane-B review)Head validated: Verdict: no blocking defects. Spec coverage verified in source at head:
Validation re-run at head (pinned 1.98.0, E-cores): |
…nd publish atomically
Summary
Credential-bearing file writes now stage next to the destination and publish atomically, so a failed or interrupted write leaves the previous file intact and a partly written secret is never the live file.
secure_file::write_string(settings, API keys, manual cookies, token accounts, Claude/Grok account stores, Codex account store, ...) builds the protected (DPAPI) bytes, writes them to acreate_newsibling (mode0600set at creation and re-applied before any byte is written on unix),sync_all, then publishes throughatomic_file::replace_staged(ReplaceFileWon Windows). Newatomic_file::write_atomic_privateprovides this;write_atomicis unchanged for non-secret files. The old post-writerestrict_file_permissionsis gone (the staged file is private from creation).CookieHeaderCache::storenow writes throughsecure_file(DPAPI plus staged publish) instead offs::writeof plaintext JSON.loadreads throughsecure_file::read_string, which still accepts legacy plaintext entries.clearis unchanged.fs::copycalls ofauth.json(switch into the ambient home,materialize_as_managedfor an existing and a fresh managed home, and the ambient backup) now go through a newcredentials::copy_private_file, which reads the source and publishes with the existing exclusive-staged private writer (write_private_file, factored out ofwrite_auth_contents).fs::copypreserved the source mode (for example0644); the copy now always ends up0600on unix.stores.rssnapshots) are left alone.cookie_source = "off"andopenai_web_extras = falsewritten by theSettings::savepath are read back by theSettings::loadpath.Upstream reference
0600).v0.67.0) files:Sources/CodexBarCore/CredentialFileWriter.swift(writePrivate), testsTests/CodexBarTests/CredentialFileWriterTests.swift(staging is private before writing, failed write or publish preserves destination, credential stores use private staging).Ported / Deferred
Ported: all of (a) to (d) of the triage spec.
Deferred / intentionally different:
0700directory andrename(2)s. Windows has no mode bits and the per-user config directory ACL already governs the staged sibling, so this port stages acreate_newsibling in the destination directory (0600on unix) and publishes withReplaceFileWasatomic_filealready does.write_auth_contentsstill publishes withstd::fs::rename(unchanged) rather thanreplace_staged, to avoid changing behavior against a live Codex CLI holdingauth.jsonopen. Not part of this item.repairPermissions(chmod of pre-existing0644files on read) has no Windows analogue; on unix, every rewrite now republishes at0600.AntigravityOAuthCredentialsStoreandGeminiStatusProbecallers: no matching production credential file writes exist in this port (Antigravity here only reads local sessions; the onlyfs::writehits there are tests), so nothing to convert.Validation
cargo +1.98.0 fmt --all: cleancargo +1.98.0 clippy --workspace --all-targets -- -D warnings: passcargo +1.98.0 test -p codexbar -- --test-threads=4(full, shared code touched): 2170 passed, 0 failed, 1 ignoredsecure_file(replace leaves only the destination, failed publish keeps destination and leaves no secret sibling, missing directory not created, unix0600),cookie_cache(round trip and replace, failed store leaves no cookie bytes, legacy plaintext still loads),codex_accounts::credentials(copy replaces and leaves no staged file, unreadable source keeps destination, failed publish cleans staged secret, unix0600from a0644source),settingscookie-denial round trip. Existingsecure_fileDPAPI tests (windows_write_uses_protected_wrapper, round trip) still pass on Windows.apps/desktop-tauri/src-taurinot touched; workspace clippy passes).Affected areas
secure_file,atomic_file,browser::cookie_cache,codex_accounts)UI proof
Not applicable