Skip to content

Upgrade hypercerts feed service to v0.2.0 - #31

Merged
Kzoeps merged 14 commits into
productionfrom
dev
Sep 24, 2026
Merged

Kzoeps merged 14 commits into
productionfrom
dev

Conversation

@Kzoeps

@Kzoeps Kzoeps commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@changeset-bot

changeset-bot Bot commented Sep 24, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: b168b86

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 23925792-5cdf-4e36-a2ae-971f6156d00f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​atproto-labs/​did-resolver@​0.3.7 ⏵ 0.3.999 +131006697 +2100
Added@​atproto-labs/​fetch-node@​0.3.7861006796100
Updated@​atproto/​lex-server@​0.1.9 ⏵ 0.1.1977 +110010099 +1100
Updated@​atproto/​crypto@​0.5.4 ⏵ 0.5.599 +81008598 +2100
Updated@​atproto/​syntax@​0.7.5 ⏵ 0.7.6100 +110094 +199 +1100

View full report

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
3.2% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@greptile-apps

greptile-apps Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The PR should not merge without resolving or explicitly accepting the authenticated availability failure caused by global replay-store exhaustion.

Findings

  1. P1 Security Replay store blocks other issuers ▶
Summary

The PR adds optional AT Protocol service authentication to both feed procedures, binds authenticated feed viewers to verified issuers, publishes a hostname-level did:web discovery document, and introduces bounded process-local token replay protection.

  • Anonymous requests continue to require params.viewerDid; authenticated requests may omit it.
  • The replay store has a documented capacity risk that can deny fresh authenticated requests across issuers.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[POST feed request] --> B{Authorization present?}
  B -- No --> C[Require body viewerDid]
  B -- Yes --> D[Verify JWT and issuer DID]
  D --> E[Check endpoint and consume issuer/jti]
  E --> F{Replay store has capacity?}
  F -- No --> G[HTTP 503]
  F -- Yes --> H[Bind viewer to verified issuer]
  C --> I[Generate feed]
  H --> I
Loading

Reviews (1) · Last reviewed commit: "Merge pull request #29 from hypercerts-o..."

Comment thread src/auth/service-auth.ts
@Kzoeps
Kzoeps merged commit 5013b00 into production Sep 24, 2026
6 of 7 checks passed

This branch is being deployed

1 in progress deployment
hyperindex / staging — b168b866 Deployed Sep 24, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant