Skip to content

feat: close the non-trailing parity rows (matrix gaps 24, 29, 30, 33, 41) - #113

Merged
rennf93 merged 1 commit into
masterfrom
feat/parity-closure-rows
Oct 7, 2026
Merged

rennf93 merged 1 commit into
masterfrom
feat/parity-closure-rows

Conversation

@rennf93

@rennf93 rennf93 commented Oct 7, 2026

Copy link
Copy Markdown
Member

Summary

The five PARTIAL/MISSING rows that do NOT map to the four trailing root causes, closed so the matrix reaches zero PARTIAL/MISSING:

  • Gap 24 (A4 ban-list migration): IPBanManager.initializeRedis ports _ipban_migration.py - scan_iter over {prefix}banned_ips:*, the canonicalizeIp twin (bracket stripping, IPv6 compression, IPv4-mapped collapse), expired legacy keys deleted, the canonical key keeping the longer TTL, legacy key always removed, every failure a warning.
  • Gap 29 (A3 route_config_revision): BaseSecurityDecorator.routeConfigRevision - the reference revision counter, bumped on every route-config mutation seam (counter held in a module WeakMap so the mixin-composed anonymous class types keep clean declaration emit).
  • Gap 30 (A8 check_ip_access): standalone checkIpAccess with the IpAccessResult detail verdict (reason + cloudProvider/network), the unknown-identity allowlist arms, whitelist-skips-countries propagation, the reference error semantics, and the cloud tier as an injected CloudHandler (the reference singleton read becomes DI).
  • Gap 33 (D15 handler exports): all eight manager classes plus canonicalizeIp exported from the package root.
  • Gap 41 (B12 nestjs CORS): configureCors + buildOriginAllowlist in the nestjs adapter - the host-express preflight seam with the CodeQL-safe explicit allowlist predicate; the cors package rides as an optional peer with devDeps for tests.

Matrix rows flipped

  • A4 ban-list migration: MISSING sub-item -> FULL
  • A3 route_config_revision: PARTIAL -> FULL
  • A8 check_ip_access: PARTIAL -> FULL
  • A-layer/D15 handler-manager exports: PARTIAL (gap 33) -> FULL
  • B12 nestjs CORS: IDIOM/PARTIAL (gap 41) -> FULL

Tests

  • packages/core/tests/test-core/parity-closure-rows.test.ts (26 tests): migration arms against a scripted Redis client, revision counter, every checkIpAccess tier, root-export parity.
  • packages/nestjs/tests/cors.test.ts (6 tests): registration, allow-origin reflection, preflight method/header mapping, allowlist denials, the install-hint failure arm.

Gates

  • turbo lint/build/test 10/10; core coverage 100/100/100 lines/functions/statements, 97.16% branches; nestjs coverage 100%; pnpm audit 0 unignored

Stacked on #112 (#109 -> #110 -> #111 -> #112 -> this); merge in order.

@rennf93 rennf93 added area: handlers Touches packages/core/src/handlers/ area: decorators Touches packages/core/src/decorators/ area: utils Touches packages/core/src/utils.ts package: core Changes inside @guardcore/core package: nestjs Changes inside @guardcore/nestjs tests Test suite changes (vitest) no-issue labels Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 03063255-ed23-4f6b-99ae-cc6a8e735b5d
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added documentation Docs, README, CHANGELOG, governance files dependencies package.json or pnpm-lock.yaml area: protocols Touches packages/core/src/protocols/ area: checks Touches packages/core/src/core/checks/ area: detection-engine Touches packages/core/src/detection-engine/ area: models Touches packages/core/src/models/ area: middleware-support Touches packages/core/src/middleware-support.ts or index.ts build Makefile / Docker / turbo / tsup / vitest / tsconfig area: core-subsystems and removed area: utils Touches packages/core/src/utils.ts labels Oct 7, 2026
@rennf93 rennf93 self-assigned this Oct 7, 2026
Comment thread packages/core/tests/test-detection-engine/validation-cache.test.ts Fixed
Comment thread packages/core/tests/test-detection-engine/validation-cache.test.ts Fixed
@rennf93
rennf93 force-pushed the feat/parity-closure-rows branch 2 times, most recently from 9ae5bd9 to d605a06 Compare October 7, 2026 18:46
@github-actions github-actions Bot added dependencies package.json or pnpm-lock.yaml area: checks Touches packages/core/src/core/checks/ area: decorators Touches packages/core/src/decorators/ package: nestjs Changes inside @guardcore/nestjs and removed dependencies package.json or pnpm-lock.yaml area: checks Touches packages/core/src/core/checks/ area: decorators Touches packages/core/src/decorators/ package: nestjs Changes inside @guardcore/nestjs labels Oct 7, 2026
… 41)

- IPBanManager.initializeRedis ports the reference ban-list migration
  (_ipban_migration.py): non-canonical legacy keys (bracketed /
  non-compressed IPv6, IPv4-mapped) move to the canonical key with the
  longer remaining TTL preserved, expired keys are deleted, failures warn
  and leave the store untouched. Ships the canonicalizeIp twin.
- BaseSecurityDecorator gains the routeConfigRevision surface (the
  RouteConfigRevision counter, bumped on every route-config mutation seam).
- The standalone checkIpAccess ships the detailed IP-access verdict (block
  reason, cloud provider/network, unknown-identity allowlist arms,
  whitelist-skips-countries, the reference error semantics; the cloud tier
  takes an injected CloudHandler where the reference reads its singleton).
- Every handler manager class exports from the package root like the
  reference guard_core.__init__.
- The NestJS adapter gains the adapter-level CORS helper (configureCors +
  buildOriginAllowlist) - the host-express preflight seam with the explicit
  origin allowlist predicate.
@rennf93
rennf93 force-pushed the feat/parity-closure-rows branch from 6cdee74 to 22a2a91 Compare October 7, 2026 19:12
@github-actions github-actions Bot removed area: protocols Touches packages/core/src/protocols/ area: detection-engine Touches packages/core/src/detection-engine/ area: models Touches packages/core/src/models/ build Makefile / Docker / turbo / tsup / vitest / tsconfig area: core-subsystems labels Oct 7, 2026
@rennf93
rennf93 merged commit 5d371e3 into master Oct 7, 2026
18 checks passed
@rennf93
rennf93 deleted the feat/parity-closure-rows branch October 7, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: checks Touches packages/core/src/core/checks/ area: decorators Touches packages/core/src/decorators/ area: handlers Touches packages/core/src/handlers/ area: middleware-support Touches packages/core/src/middleware-support.ts or index.ts dependencies package.json or pnpm-lock.yaml documentation Docs, README, CHANGELOG, governance files no-issue package: core Changes inside @guardcore/core package: nestjs Changes inside @guardcore/nestjs tests Test suite changes (vitest)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants