Skip to content

fix(protect): close runtime template coverage gaps - #348

Merged
patchstackdave merged 1 commit into
codex/guard-injection-safetyfrom
codex/guard-runtime-coverage
Oct 2, 2026
Merged

patchstackdave merged 1 commit into
codex/guard-injection-safetyfrom
codex/guard-runtime-coverage

Conversation

@patchstackdave

Copy link
Copy Markdown
Contributor

Stacked on #347.

  • Screen parsed Fastify form bodies correctly and filter buffered onSend responses while preserving cookies, status and framing.
  • Enable existing bounded response filtering in generated Express and Node middleware.
  • Refresh live rules in long-lived production runtimes and tolerate absent process globals in Fetch templates.
  • Preserve Fetch handler receivers and host arguments.
  • Verify executable seam wiring, not marker comments. Upgrade only fingerprint-recognized unchanged generated helpers; retain customized helpers and site identity.

Validation: complete suite (4,162 passed, seven skipped before the upgrade regression); 56 targeted tests including upgrade safety; all nine template typechecks; build. Real Fastify tests cover JSON/forms, benign controls, sibling routes, output redaction, cookies, streaming and bodyless responses. Existing response-engine tests cover size limits, encoding and framing.

Source inspection is not proof of live rule delivery. Streams and unsupported custom hooks remain explicit limitations. Public-boundary review completed; fixtures are synthetic.

@coderbuds

coderbuds Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Centralizes template upgrades with installTemplate and expands coverage tests.

🎯 Quality: 83% Excellent · 📦 Size: Large — consider splitting if possible

🛡️ Standards: Not checked — 501 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the assess-change-fit tool first, while a change this size is still cheap to split.

🤖 Authorship: Probably agent-written — OpenAI Codex, going by its branch name. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 206th PR — above team average · Averaging Good

See how your team is trending →

@patchstackdave
patchstackdave force-pushed the codex/guard-runtime-coverage branch from 84db562 to a30febc Compare October 2, 2026 06:28
@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit e830f79 into main Oct 2, 2026
22 of 41 checks passed
@patchstackdave
patchstackdave deleted the codex/guard-runtime-coverage branch October 2, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants