feat: E2E #2 (Stash) gap remediation + S6 hardening
Closes the gaps and the one security finding from the second end-to-end
CLI test (E2E_STASH_REPORT.md), plus the H1 boot-regression found while
re-reviewing those fixes.
Security
- S6: reserved-path validation (`check_reserved`) now case-folds before
comparing, so `/API/v2/x`, `/HEALTHZ`, `/Admin/x` are rejected like
their lowercase forms. Request-time matching stays case-sensitive.
- S10: "public route != public data" callout in sdk-shape.md (script_gate
skips authz when the principal is anonymous).
Observability / features
- G1: trigger executions now write `execution_logs`. Migration 0043 adds
a `source` column (CHECK mirrors ExecutionSource/OutboxSourceKind,
DEFAULT 'http' backfills history); a shared `build_execution_log` helper
in executor-core; dispatcher logging for outbox triggers + queue
consumers (skips sync-HTTP rows the orchestrator already logs). `pic
logs` gains a source column + `--source` filter.
- G5: dev-only in-memory email capture under PICLOUD_DEV_MODE with no SMTP
(email::send succeeds locally), readable at GET /api/v1/admin/dev/emails
(Owner/Admin only; route mounted only in capture mode).
- G6: generalized the Rhai in-place-mutation footgun note (trim/replace/
make_upper/make_lower/crop/truncate/pad return ()).
- G2/G3/G4 (CLI): `pic members`, `pic files`, `pic queues`, read-only
`pic kv` (+ new kv_api.rs); `pic deploy --timeout/--memory/--kind/
--sandbox`; first-class `pic triggers create-{docs,files,pubsub,queue,
email}` wrappers. All new client path segments percent-encoded via seg().
H1 regression fix (found in re-review)
- The S6 change also runs in `compile_routes`, which compiles every stored
route at boot and on each route CRUD. A single stored route the new
validation rejects (creatable while the S6 gap existed) made the whole
compile Err and aborted startup. `compile_routes` is now lenient: it
skips an un-compilable row with a warning instead of bricking boot
(route creation still validates separately). Migration 0044 sweeps
pre-existing reserved-path routes on upgrade (WHERE mirrors
check_reserved exactly). Added regression tests for both.
Verified: cargo fmt, clippy --all-targets --all-features -D warnings, the
schema_snapshot test, and the new S6/lenient-compile unit tests all pass;
boot-resilience and G1/G5 confirmed live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -15,11 +15,13 @@ use axum::{
|
||||
Extension, Json, Router,
|
||||
};
|
||||
use chrono::Utc;
|
||||
use picloud_executor_core::{ExecError, ExecRequest, ExecResponse, InvocationType};
|
||||
use picloud_executor_core::{
|
||||
build_execution_log, ExecError, ExecRequest, ExecResponse, InvocationType,
|
||||
};
|
||||
use picloud_shared::{
|
||||
AppId, DispatchMode, ExecutionId, ExecutionLog, ExecutionLogSink, ExecutionStatus,
|
||||
HttpDispatchPayload, InboxFailureKind, InboxResult, NewHttpOutbox, OutboxWriter, Principal,
|
||||
RequestId, ScriptId,
|
||||
AppId, DispatchMode, ExecutionId, ExecutionLog, ExecutionLogSink, ExecutionSource,
|
||||
ExecutionStatus, HttpDispatchPayload, InboxFailureKind, InboxResult, NewHttpOutbox,
|
||||
OutboxWriter, Principal, RequestId, ScriptId,
|
||||
};
|
||||
use serde_json::Value as Json_;
|
||||
use uuid::Uuid;
|
||||
@@ -150,6 +152,7 @@ where
|
||||
request_path,
|
||||
request_headers,
|
||||
request_body,
|
||||
ExecutionSource::Http,
|
||||
&outcome,
|
||||
started,
|
||||
finished,
|
||||
@@ -530,6 +533,7 @@ fn build_inbox_execution_log(
|
||||
script_logs: Json_::Array(vec![]),
|
||||
duration_ms,
|
||||
status,
|
||||
source: ExecutionSource::Http,
|
||||
created_at: started,
|
||||
}
|
||||
}
|
||||
@@ -630,67 +634,9 @@ fn exec_response_to_http(resp: ExecResponse) -> Response {
|
||||
(status, http_headers, Json(resp.body)).into_response()
|
||||
}
|
||||
|
||||
#[allow(clippy::too_many_arguments)]
|
||||
fn build_execution_log(
|
||||
app_id: AppId,
|
||||
script_id: ScriptId,
|
||||
request_id: RequestId,
|
||||
request_path: String,
|
||||
request_headers: BTreeMap<String, String>,
|
||||
request_body: Json_,
|
||||
outcome: &Result<ExecResponse, ExecError>,
|
||||
started: chrono::DateTime<Utc>,
|
||||
finished: chrono::DateTime<Utc>,
|
||||
) -> ExecutionLog {
|
||||
let duration_ms = u64::try_from(
|
||||
finished
|
||||
.signed_duration_since(started)
|
||||
.num_milliseconds()
|
||||
.max(0),
|
||||
)
|
||||
.unwrap_or(0);
|
||||
|
||||
let (status, response_code, response_body, script_logs) = match outcome {
|
||||
Ok(resp) => {
|
||||
let logs = serde_json::to_value(&resp.logs).unwrap_or(Json_::Array(vec![]));
|
||||
(
|
||||
ExecutionStatus::Success,
|
||||
Some(resp.status_code),
|
||||
Some(resp.body.clone()),
|
||||
logs,
|
||||
)
|
||||
}
|
||||
Err(e) => {
|
||||
let status = match e {
|
||||
ExecError::Timeout(_) => ExecutionStatus::Timeout,
|
||||
ExecError::OperationBudgetExceeded => ExecutionStatus::BudgetExceeded,
|
||||
_ => ExecutionStatus::Error,
|
||||
};
|
||||
(
|
||||
status,
|
||||
None,
|
||||
Some(serde_json::json!({ "error": e.to_string() })),
|
||||
Json_::Array(vec![]),
|
||||
)
|
||||
}
|
||||
};
|
||||
|
||||
ExecutionLog {
|
||||
id: Uuid::new_v4(),
|
||||
app_id,
|
||||
script_id,
|
||||
request_id,
|
||||
request_path,
|
||||
request_headers,
|
||||
request_body,
|
||||
response_code,
|
||||
response_body,
|
||||
script_logs,
|
||||
duration_ms,
|
||||
status,
|
||||
created_at: started,
|
||||
}
|
||||
}
|
||||
// `build_execution_log` moved to `picloud_executor_core` so the manager's
|
||||
// trigger dispatcher can build identically-shaped rows (G1 — trigger
|
||||
// executions are now logged with their `ExecutionSource`).
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
// Errors
|
||||
|
||||
Reference in New Issue
Block a user