Skip to content

fix(protect): make scaffold injection transactional and source-aware - #347

Merged
patchstackdave merged 2 commits into
mainfrom
codex/guard-injection-safety
Oct 2, 2026
Merged

patchstackdave merged 2 commits into
mainfrom
codex/guard-injection-safety

Conversation

@patchstackdave

Copy link
Copy Markdown
Contributor

First in a stacked guard/setup improvement series.

  • Resolve a CLI-owned TypeScript parser for JavaScript-only installations.
  • Insert registration after complete imports, bootstrap calls and the last body parser; report early router mounts as uncovered.
  • Prepare TanStack client/server changes together, preserve Request semantics, and reuse existing request imports.
  • Preserve customized helpers and report unresolved wiring instead of claiming success.

Validation: build; typecheck including nine templates; full suite (4,156 passed, seven skipped); synthetic multiline, compact bootstrap, dynamic configuration, rerun, and Request-body regressions.

Public-boundary review completed; all new fixtures are synthetic.

@coderbuds

coderbuds Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Transactional guard injection with comprehensive AST-based patches.

🎯 Quality: 95% Elite · 📦 Size: Large — consider splitting if possible

🛡️ Standards: Not checked — 403 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the assess-change-fit tool first, while a change this size is still cheap to split.

🤖 Authorship: Probably agent-written — OpenAI Codex, going by its branch name. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 206th PR — above team average · Averaging Excellent

See how your team is trending →

@patchstackdave

Copy link
Copy Markdown
Contributor Author

Review fixes pushed in 72cce8d.

  • Only compose application entries with a verified generated guard helper. Missing exports and no-op/custom helper implementations now remain untouched and report manual integration instead of successful protection.
  • Verification accepts comments, formatting, quote style, and the baked site ID; it does not accept executable changes.
  • Added ESM, CommonJS, TypeScript, helper-replacement, and TanStack regression cases. Dependent PRs have been rebased onto this fix.

The combined stack passes 4,258 tests (7 skipped), typechecking of 10 templates, build, and capability checks.

@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit 8556476 into main Oct 2, 2026
22 checks passed
@patchstackdave
patchstackdave deleted the codex/guard-injection-safety branch October 2, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants