fix(auth): reject ambiguous conversation widget tokens - #108161
pauldambra wants to merge 1 commit into
Conversation
🤖 CI report
|
| First copy | Second copy | Lines | Tokens |
|---|---|---|---|
posthog/temporal/ai_observability/run_aggregate_evaluation.py:692 |
posthog/temporal/ai_observability/run_trace_evaluation.py:928 |
38 | 203 |
products/warehouse_sources/backend/temporal/data_imports/sources/companycam/source.py:1 |
products/warehouse_sources/backend/temporal/data_imports/sources/wix/source.py:1 |
21 | 164 |
posthog/temporal/ai_observability/run_aggregate_evaluation.py:584 |
posthog/temporal/ai_observability/run_trace_evaluation.py:855 |
24 | 135 |
products/signals/backend/scout_harness/tools/report.py:1475 |
products/signals/backend/scout_harness/tools/report.py:1647 |
21 | 133 |
products/signals/backend/scout_harness/tools/report.py:1604 |
products/signals/backend/scout_harness/tools/report.py:1754 |
30 | 118 |
posthog/temporal/ai_observability/run_session_evaluation.py:466 |
posthog/temporal/ai_observability/run_trace_evaluation.py:664 |
24 | 115 |
posthog/management/commands/backfill_hogflow_billable_action_types.py:49 |
posthog/management/commands/refresh_hog_flows.py:69 |
23 | 112 |
products/batch_exports/backend/api/batch_export.py:2092 |
products/batch_exports/backend/api/batch_export.py:2131 |
24 | 112 |
products/warehouse_sources/backend/temporal/data_imports/sources/pardot/pardot.py:2 |
products/warehouse_sources/backend/temporal/data_imports/sources/wix/wix.py:1 |
12 | 97 |
products/signals/backend/scout_harness/tools/report.py:1516 |
products/signals/backend/scout_harness/tools/report.py:1675 |
12 | 71 |
products/signals/backend/scout_harness/tools/report.py:1531 |
products/signals/backend/scout_harness/tools/report.py:1690 |
16 | 70 |
⚠️ Duplication (TypeScript) — 2 new duplicated blocks (worst 158 tokens)
New TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.
| First copy | Second copy | Lines | Tokens |
|---|---|---|---|
products/business_knowledge/frontend/scenes/settings/businessKnowledgeSettingsLogic.test.ts:10 |
products/data_catalog/frontend/certificationsLogic.test.ts:17 |
23 | 158 |
products/business_knowledge/frontend/scenes/settings/businessKnowledgeSettingsLogic.test.ts:10 |
products/data_quality/frontend/dataQualityGateLogic.test.ts:14 |
23 | 158 |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: PostHog/posthog/.coderabbit.yaml Review profile: QUIET Plan: Enterprise Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughWidgetAuthentication now raises AuthenticationFailed when team lookup raises Team.DoesNotExist or Team.MultipleObjectsReturned. A parameterized test checks both cases. Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Ambiguous widget tokens now fail authentication instead of surfacing an unhandled lookup exception; missing-token behavior and successful authentication remain unchanged. No concrete merge-blocking risk remains in the supplied changes. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change rejects ambiguous tokens instead of granting access to either matching team. No new access path was identified, but the exact HTTP response and behavior across every widget endpoint were not verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 1✅ Passed checks (1 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Generated-By: PostHog Desktop Task-Id: 160dfc49-dceb-4887-b9f5-a93b2da017ed
258376d to
39278a5
Compare
|
✅ Security review complete — 1 finding posted as a review, in 11 min. Add the |
|
[Robot] Note 🤖 Automated comment by QA Swarm — not written by a human Verdict: APPROVE (round 1 @ 39278a5)No actionable findings. Ambiguous widget tokens fail authentication instead of causing a server error. Key findings
ConvergenceBoth reviewers found no correctness or security defects. Reviewer summaries
Automated by QA Swarm — not a human review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Not approved yet — waiting on the conditions below.
Re-add the stamphog label to request another review once you have addressed this.
stamphog can't approve this pull request because two gates refused it. The deny-list gate flagged it for matching the auth category, since it changes posthog/auth.py and adds tests for authentication. The tier gate classified it as T2-never (12 lines, 2 files, single-area fix), a tier that is never eligible for automated approval. The size gate passed, so splitting the PR won't change the outcome. Please ask a human reviewer, ideally someone who owns authentication, to review it.
- 👍 on the PR from chatgpt-codex-connector[bot].
Gate mechanics and policy version
| Gate | Result | |
|---|---|---|
| prerequisites | ✓ | all clear |
| deny-list | ✗ | matches: auth |
| size | ✓ | 2L, 1F substantive, 12L/2F incl. docs/generated/snapshots — within ceiling |
| tier | ✗ | classified as T2-never: T2-never (12L, 2F, single-area, fix) |
| stamphog 2.3.0 | .stamphog/policy.yml @ unknown · reviewed head 39278a5 |

[Robot] Prepared by PostHog Desktop.
Problem
A widget token that matches more than one project causes a server error.
Changes
Reject an ambiguous token with an authentication error.
This fixes existing behavior before the module split in #99248.
How did you test this code?
Parameterized authentication tests cover missing and duplicate tokens. The focused tests ran against both module layouts. The full type check covers the combined fixes.
Release status
Automatic notifications
Docs update
No existing document under
docs/covers this validation detail.🤖 Agent context
Autonomy: Human-driven (agent-assisted)
Agent: PostHog Desktop / Codex, GPT-6
Tools: Git, GitHub CLI, hogli, pytest, Ruff, mypy, and CodeRabbit.
Skills: stacking-prs, improving-drf-endpoints, writing-tests, writing-code-comments, writing-user-facing-copy, setting-up-devbox, running-ci-preflight, reviewing-with-coderabbit, writing-pr-descriptions.
Each existing bug has its own layer below the refactor. No matching open fix appeared in the PR search.
The combined CodeRabbit review found two deployment tradeoffs in the membership layer. That PR records the decisions.
Created with PostHog Desktop