Skip to content

fix(api): refuse live links before saving on workspaces without a public base URL - #1084

Merged
Zach Dunn (zachdunn) merged 1 commit into
mainfrom
claude/live-link-create-public-guard
Oct 5, 2026
Merged

Zach Dunn (zachdunn) merged 1 commit into
mainfrom
claude/live-link-create-public-guard

Conversation

@zachdunn

Copy link
Copy Markdown
Member

On a workspace whose storage has no public base URL, POST /feeds saved the live link and then failed with 503 feed_object_not_public while building the response. The saved link stayed on the Links tab, its public page failed the same way, and a repo-wide one counted toward the 50 repo live link cap.

Changes

  • New liveLinksServable(workspace) in feed-service.ts: true when the active storage lane has a public base URL. It reads the workspace record only (no storage or credential reads).
  • POST /feeds runs that check before createFeed and refuses with the same 503 feed_object_not_public. No row is saved, so the cap is not used up. This also covers scopes with no files yet, which got a link before.
  • The PR comment sync, which creates live links too, uses the same check and creates no live link on such a workspace. The comment keeps its existing file links and leaves out the "View all" line.
  • A transient storage failure while building the response still leaves a valid row, which the next request returns.

The web Copy live link flow already reads this 503 as "not publicly served" and shows its no-retry toast, so nothing changes there.

Testing

  • New route test on a workspace with no public base URL: both a PR scope with a file and an empty repo scope return 503 feed_object_not_public, and the workspace has no live links after.
  • New comment test: on such a workspace the comment sync saves no live link and the body has no /c/ links.
  • API tests (3115), API typecheck, and pnpm check pass.

Closes #1082

…lic base URL

POST /feeds now checks the workspace's public base URL before the insert,
so a refused create leaves no row and no longer counts toward the repo
live link cap. The PR comment sync skips its live link on the same check.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (2)
  • coderabbit:review
  • review
🚫 Excluded labels (none allowed) (1)
  • wip

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7217397d-2f89-4172-9072-a9b5833298ab

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@changeset-bot

changeset-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: a450860

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
uploads-api a450860 Commit Preview URL

Branch Preview URL
Oct 05 2026, 12:01 PM

@zachdunn
Zach Dunn (zachdunn) merged commit 11ff75d into main Oct 5, 2026
4 checks passed
@zachdunn
Zach Dunn (zachdunn) deleted the claude/live-link-create-public-guard branch October 5, 2026 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Live link create leaves a row behind when hydration fails

1 participant