Conversation
An interop key {namespace}:{operation}:{args_hash} in namespace `ns` or
`nsapi` starts `ns:` / `nsapi:`, which the CachekitIO server parses as a
namespace-prefixed key: it is rejected or scoped to a namespace named after
the operation. interop/v1 1.1.0 reserves both names (exact-match,
namespace-only); re-vendor the vectors byte-for-byte from protocol.
BREAKING CHANGE: cache.wrap(fn, { interop, namespace: 'ns' | 'nsapi' }) and generateInteropKey now throw ConfigurationError. Such keys were already rejected or misrouted by CachekitIO, but worked on other backends.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-ts/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughInterop segment validation now rejects ChangesInterop namespace reservations
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Interop now rejects exact Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change narrows which interop namespaces the SDK accepts and rejects invalid configurations before cache access. No introduced security weakness was established, but server-side behavior and the impact on existing users of the newly reserved names remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 60.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 6 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
…ure (LAB-5876)
RegExp.test string-coerces its argument but Set.has does not, so an untyped
['ns'] or new String('nsapi') passed the segment grammar, skipped the
reserved-namespace check, and generateInteropKey minted an `ns:` key.
validateInteropSegment now rejects a non-string first, at both wrap time and
call time.
The interop protocol suite now pins the fixture sha256 and its key/value/error
vector counts: it.each over a truncated fixture silently runs fewer cases.
Provenance points at the protocol squash commit.
|
Merged |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
This PR reserves
nsandnsapias interop namespaces in the TypeScript SDK. Keys starting withns:ornsapi:are parsed by the CachekitIO server as namespace-prefixed, so they would be rejected or misrouted. This implements the reservation defined in cachekit-io/protocol#78.Public API changes (breaking)
cache.wrap(fn, { interop, namespace, ... }): throwsConfigurationErrorat wrap time whennamespaceis exactly'ns'or'nsapi'.generateInteropKey(...): throwsConfigurationErrorfor the same namespaces. The JSDoc@throwsnow lists this case.validateInteropSegment(kind, value): whenkind === 'namespace', it now also rejects reserved values. The check runs after the grammar check, and the error message contains "reserved" and names the conflicting'<value>:'prefix.WrapOptions.interopJSDoc (types/cache.ts, shipped in.d.ts): documents the reservation and states that operation names are unaffected.Scope of the reservation
RESERVED_INTEROP_NAMESPACESset. Values such asnsx,nsfw,nsapi2andnsapixremain valid namespaces.nsandnsapiare still accepted as operation names.INTEROP_SEGMENT_PATTERNis unchanged, because it also governs operation names.Supporting changes
interop-mode.json1.1.0 is re-vendored byte-for-byte from the protocol repo.nsapix, operationnsapi).cache.wraptest asserts both reserved namespaces throw/reserved/.cache.test.tsswitches fromnamespace: 'ns'to'blobs'..secrets.baseline: line numbers shift for the regenerated fixture, and one new vector hash entry is added.Migration impact
Deployments that used
nsornsapias an interop namespace on non-CachekitIO backends must rename the namespace. The rename makes every existing entry in that namespace a cache miss.Summary
This PR hardens interop namespace validation so that the reserved namespaces
nsandnsapicannot be bypassed with non-string input. It also adds tests for invalidation logging and for the integrity of the vendored interop test-vector fixture.Changes
validateInteropSegment(kind, value)(serialization/interop.ts)ConfigurationErrorwhenvalueis not a string, before the grammar and reservation checks run.RegExp.testconverts its argument to a string, butSet.hasdoes not. An untyped input such as['ns']ornew String('nsapi')could pass the grammar check, skip the reserved-namespace check, and produce anns:-prefixed key.@throwscontract now includes the non-string case.generateInteropKeygoes through this validation, so it now rejects the same inputs.Tests
interop.test.ts: confirms that['ns']andnew String('nsapi')are rejected by bothvalidateInteropSegmentandgenerateInteropKey.cache.test.ts(LAB-4336): confirms thatcache.invalidate('namespace')with no namespace logs[cachekit] invalidate("namespace") called with no namespace; nothing invalidatedat the caller. It also confirms that a call with a namespace logs nothing.interop-mode.protocol.test.ts:interop-mode.jsonfixture by its SHA-256 hash and by its vector counts: 34 key, 4 value and 11 error vectors.it.eachcases and still pass.965aeb01…and explains how to re-vendor the fixture.Maintenance
.secrets.baselineline numbers and timestamp are updated to match the shifted test file.Compatibility
Callers that pass non-string values as interop namespace or operation segments will now get a
ConfigurationError. This is the breaking change marked with!in the PR title.Summary by CodeRabbit
nsornsapiare now rejected, while these values remain valid as operation names. Non-string namespace segments are also rejected.