Skip to content

fix: tighten extension anonymize rules after QA - #1657

Merged
Soner (shyim) merged 1 commit into
cursor/extension-anonymize-dump-70b3from
qa/extension-anonymize-fixes
Oct 5, 2026
Merged

Soner (shyim) merged 1 commit into
cursor/extension-anonymize-dump-70b3from
qa/extension-anonymize-fixes

Conversation

@moshimorschi

@moshimorschi Lena Forlin (moshimorschi) commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

What changed?

These are the fixes from the QA of #1635. They're one PR into your branch, so you can take what you like.

  • A broken extension config now stops the dump. Before, --anonymize silently skipped that extension, and its secrets stayed in the dump.
  • Built-in rules win over extension rules. An extension could switch off customer anonymization with customer.email: email.
  • JSON_REMOVE rules on the same column are combined. With Mollie and PayPal installed, PayPal's data in order_transaction.custom_fields stayed in the dump.
  • Faker values inside JSON are escaped. faker.Address.Address() broke the import.
  • Text around a faker template in dump.rewrite works again (qa+{{- faker.Internet.User() -}}@example.com), and faker inside SQL still works.
  • Stricter config. A typo under anonymize is an error, and the schema requires key in system_config objects.
  • Skill and README. The skill now validates with --only builtin, handles configs the build copies into place, sets sandbox or test mode, and covers JSON, free-text and unique columns. The README section no longer splits the environments text.

One heads-up: --only builtin needs #1627 from main, so it works once main is merged into your branch.

How was this tested?

Unit tests for each fix. End to end on MariaDB 11.8, including a restore and a storefront check, and the JSON case also on MySQL 8.4. Agents re-ran the skill on three real extensions.

Related issue or discussion

#1635, #1315

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5435192d-4271-4537-8497-66b414f283d9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

A broken extension config now stops project dump --anonymize instead of
silently skipping that extension. Built-in rules win over extension rules,
JSON_REMOVE rules on the same column are combined, faker values inside JSON
are escaped, and text around a faker template in dump.rewrite works again.

Unknown keys under anonymize are an error, and the schema requires key in
system_config objects. The skill validates with --only builtin and covers
relocated configs, sandbox mode, JSON, free-text and unique columns.
@moshimorschi
Lena Forlin (moshimorschi) marked this pull request as ready for review October 2, 2026 12:21
@shyim
Soner (shyim) merged commit 44e4924 into cursor/extension-anonymize-dump-70b3 Oct 5, 2026
5 checks passed
@shyim
Soner (shyim) deleted the qa/extension-anonymize-fixes branch October 5, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants