Protect whole-server pushes from overwriting newer client edits - #44
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (12)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughPulls now record site and library revisions as local baselines. Pushes preflight selected targets, send expected revisions with imports, and support confirmed forced overwrites with backups. ChangesRevision-guarded push workflow
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant PushCLI
participant prepare_push
participant PrimoServer
participant finish_push
PushCLI->>prepare_push: Prepare target plans
prepare_push->>PrimoServer: Fetch push state
PrimoServer-->>prepare_push: Return target revisions
prepare_push-->>PushCLI: Return validated plans
PushCLI->>PrimoServer: Submit guarded import
PrimoServer-->>PushCLI: Return revision and backup
PushCLI->>finish_push: Save revision and process backup
Merge Risk: ⚪ Minimal · up to Pushes now check each site and the shared library against the last pulled or pushed server revision. They stop before overwriting newer server edits unless you confirm a forced overwrite, which creates backups. No blocking defects were found. The CMS must be updated alongside the CLI, and each workspace should be pulled once to establish baselines before pushing. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Revision checks and stop-on-conflict behavior reduce accidental overwrites, but the workspace library path loses a previous authentication check, and forced-overwrite recovery can be reported as failed after the new revision has already been trusted. The server-side safeguards needed to complete this design are not available for verification. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 19.05% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Stop a whole-server push before any uploads when a client changed a site or shared library since the last successful pull/push. Allow an intentional overwrite with explicit confirmation and server-created backups.
Validation: TypeScript build and all 71 CLI tests passed with PRIMO_TEST_CMS_BINARY set to the companion CMS build. Tests include stale later sites/library, no baseline, unsupported servers, explicit confirmation, force followed by ordinary push, partial-success reporting, legacy pulls, deleted sites, and a real two-site/shared-library CMS round trip.
Requires the companion CMS protocol update. Update CMS and CLI together, then pull to establish baselines. A conflict never pulls or merges automatically. Backups are private ZIP exports with original records; recovery of fields unsupported by the portable importer may require operator assistance. Push still updates CMS content without automatically publishing the website.
Companion CMS change: primocms/primo#1263
Summary by CodeRabbit
--forceto overwrite server changes after confirmation; add--yesto confirm without an interactive prompt. Overwrites require a server backup.--onlyto limit a push to one site.