Skip to content

fix: reconciliar guard-rails e estado GitHub/Supabase - #80

Merged
adm01-debug merged 3 commits into
mainfrom
fix/hermes-h8171399-reconciliacao-online
Aug 31, 2026
Merged

fix: reconciliar guard-rails e estado GitHub/Supabase#80
adm01-debug merged 3 commits into
mainfrom
fix/hermes-h8171399-reconciliacao-online

Conversation

@adm01-debug

@adm01-debug adm01-debug commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Reconcilia o pacote funcional do PR #66 com o estado real do GitHub/Supabase e corrige falhas determinísticas encontradas na revalidação.\n\nCorreções: filtro de opt-out usa chunking canônico; testes de autorização/contrato deixam de depender de formato textual; migrate-helper aposentado passa a falhar fechado com 410, sem leitura ou exposição de credenciais; scanner bloqueia segredos operacionais literais; Lighthouse CI passa a servir o build dist como SPA.\n\nValidações: ESLint e typecheck verdes; Vitest 458 aprovados e 2 ignorados; build verde; recorte Deno do PR #66 51/51; regressões alvo 20/20; suíte Deno 543 aprovados e 26 falhas ambientais/de integração explicitadas; 170/170 funções no guard de request ID; três coletas Lighthouse completas. Assertions Lighthouse continuam vermelhas por configuração Supabase ausente e problemas reais documentados; budgets não foram relaxados.\n\nNenhuma escrita em banco foi realizada. O destino usyxfpqlsspldubptrdl permanece bloqueado por MCP 401, CLI 403 e ausência de credenciais no GitHub Actions; o relatório contém o gate seguro para a reconciliação remota.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

adm01-debug has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@ecc-tools

ecc-tools Bot commented Aug 31, 2026

Copy link
Copy Markdown

Analyzing 200 commits...

@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 26 minutes.

View limit details

Limit details: You’ve used the included review currently available. Your 107 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8b575a9b-888d-448a-bf8c-0e5260a8f45a

📥 Commits

Reviewing files that changed from the base of the PR and between ce5dd16 and e6df597.

📒 Files selected for processing (8)
  • .lighthouserc.json
  • docs/execucao/RECONCILIACAO_GITHUB_SUPABASE_2026-08-31.md
  • scripts/security/check-no-committed-service-role.ts
  • supabase/functions/_shared/unsubscribe.ts
  • supabase/functions/campaign-health-alert/authz_test.ts
  • supabase/functions/migrate-helper/index.ts
  • supabase/functions/migrate-helper/security_test.ts
  • supabase/functions/run-retry-tests/contract_test.ts

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 31, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-31T10:44:39.669391Z e6df597 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@ecc-tools

ecc-tools Bot commented Aug 31, 2026

Copy link
Copy Markdown

Analysis Complete

Generated ECC bundle from 1 commits | Confidence: 50%

View Pull Request #81

Repository Profile
Attribute Value
Language TypeScript
Framework Not detected
Commit Convention conventional
Test Directory separate
Changed Files (4)
Metric Value
Files changed 4
Additions 192
Deletions 11

Top hotspots

Path Status +/-
docs/execucao/RECONCILIACAO_GITHUB_SUPABASE_2026-08-31.md added +167 / -0
supabase/functions/_shared/unsubscribe.ts modified +18 / -7
supabase/functions/campaign-health-alert/authz_test.ts modified +5 / -2
supabase/functions/run-retry-tests/contract_test.ts modified +2 / -2

Top directories

Directory Files Total changes
docs/execucao 1 167
supabase/functions/_shared 1 25
supabase/functions/campaign-health-alert 1 7
supabase/functions/run-retry-tests 1 4
Analysis Depth Readiness (commit-history, 7%)

ECC Tools uses this to decide whether recommendations should stay at commit-history/setup guidance or expand into CI, security, harness, reference-set, AI-routing, and team backlog work.

Area Status Evidence / Next Step
Commit history Partial 1 commits sampled
CI/CD signals Missing Add workflow files or CI troubleshooting evidence so ECC Tools can reason about pipeline setup.
Security evidence Missing Add AgentShield, audit, SARIF, SBOM, or security review evidence so recommendations can cover security posture.
Harness configuration Missing Add Claude, Codex, OpenCode, Zed, dmux, MCP, plugin, or cross-harness config evidence for harness-agnostic recommendations.
Reference/eval evidence Missing Add fixtures, golden traces, reference sets, or evaluator benchmarks so deeper recommendations have regression evidence.
AI routing and cost controls Missing Add model-routing, budget, usage, or cost-control files before relying on AI-heavy automation recommendations.
Team handoff and project tracking Missing Add roadmap, runbook, project, Linear, or follow-up tracking docs so generated work can land in a team queue.
Reference Set Readiness (0/7, 0%)
Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.
Likely Future Issues (2)
Severity Signal Why it may show up
HIGH Regression coverage may lag behind the diff 3 generic code paths changed; 0 test files changed
HIGH Schema or model changes may ship without migration follow-up 3 schema/model paths changed; 0 migration files changed
  • Regression coverage may lag behind the diff: The PR changes multiple code paths but does not touch any obvious test files.
  • Schema or model changes may ship without migration follow-up: The PR changes schema or model-facing files but does not include any obvious migration artifact.
Suggested Follow-up Work (2)
Type Suggested title Targets
PR test: add regression coverage for supabase/functions/_shared/unsubscribe.ts + supabase/functions/campaign-health-alert/authz_test.ts supabase/functions/_shared/unsubscribe.ts, supabase/functions/campaign-health-alert/authz_test.ts
PR db: add migration follow-up for supabase/functions/_shared/unsubscribe.ts + supabase/functions/campaign-health-alert/authz_test.ts supabase/functions/_shared/unsubscribe.ts, supabase/functions/campaign-health-alert/authz_test.ts
  • test: add regression coverage for supabase/functions/_shared/unsubscribe.ts + supabase/functions/campaign-health-alert/authz_test.ts: Backfill regression coverage before another change set lands on the touched code paths.
  • db: add migration follow-up for supabase/functions/_shared/unsubscribe.ts + supabase/functions/campaign-health-alert/authz_test.ts: Backfill the missing migration artifact before another schema or model change lands on top.

Copy-ready bodies

test: add regression coverage for supabase/functions/_shared/unsubscribe.ts + supabase/functions/campaign-health-alert/authz_test.ts

## Summary
- Add regression coverage for the recently touched code paths before more changes stack on top.

## Why
- Backfill regression coverage before another change set lands on the touched code paths.

## Touched paths
- `supabase/functions/_shared/unsubscribe.ts`
- `supabase/functions/campaign-health-alert/authz_test.ts`

## Validation
- Add or extend focused tests that exercise the touched paths.
- Run the affected test suite and verify the new coverage closes the gap.

db: add migration follow-up for supabase/functions/_shared/unsubscribe.ts + supabase/functions/campaign-health-alert/authz_test.ts

## Summary
- Add the missing migration or schema rollout step for the recently changed schema surface.

## Why
- Backfill the missing migration artifact before another schema or model change lands on top.

## Touched paths
- `supabase/functions/_shared/unsubscribe.ts`
- `supabase/functions/campaign-health-alert/authz_test.ts`

## Validation
- Create the migration or schema rollout artifact used by this repo.
- Run the repo migration / schema validation flow and verify the changed models still match production expectations.
Review Activity (1 reviews, 0 inline comments, 0 unresolved threads)
Signal Count
Approvals 0
Change requests 0
Comment-only reviews 1
Dismissed reviews 0
Pending reviews 0
Review threads 0
Unresolved threads 0
Outdated threads 0
Latest review Commented
Latest submitted at 2026-08-31T10:23:33Z

Latest reviewer states

Reviewer State Submitted
@greptile-apps[bot] Commented 2026-08-31T10:23:33Z
Review Follow-up Signals (1)
Severity Signal Evidence
MEDIUM Get an explicit approval No approving review is recorded for this PR

Recommended next actions

  • Ask for an approval after requested changes and unresolved discussions are addressed.
Generated Instincts (6)
Domain Count
git 2
code-style 3
testing 1

After merging, import with:

/instinct-import .claude/homunculus/instincts/inherited/Promo_Champions_V2.1-instincts.yaml

Files

  • .claude/ecc-tools.json
  • .claude/skills/Promo_Champions_V2.1/SKILL.md
  • .agents/skills/Promo_Champions_V2.1/SKILL.md
  • .agents/skills/Promo_Champions_V2.1/agents/openai.yaml
  • .claude/identity.json
  • .codex/config.toml
  • .codex/AGENTS.md
  • .codex/agents/explorer.toml
  • .codex/agents/reviewer.toml
  • .codex/agents/docs-researcher.toml
  • .claude/homunculus/instincts/inherited/Promo_Champions_V2.1-instincts.yaml

ECC Tools | Everything Claude Code

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

adm01-debug has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

adm01-debug has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@adm01-debug

Copy link
Copy Markdown
Owner Author

Decisão de merge P0: lint/typecheck, unitários, build, bundle size, empacotamento Edge, request-id e quality-gate estão verdes. Lighthouse completou três coletas e falhou por ausência de configuração Supabase no CI e débitos reais documentados; thresholds não foram relaxados. E2E geral permanece pendente sem credenciais/fixtures confiáveis, e o job enterprise não define timeout. A exceção não declara esses checks como aprovados. Nenhuma escrita em banco foi executada.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6df597bff

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +19 to +20
const operationalSecretAssignmentPattern =
/\b(?:const|let|var)\s+[A-Za-z0-9_]*(?:ACCESS_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY)[A-Za-z0-9_]*\s*=\s*(['"`])(?:[0-9a-f]{32,}|[A-Za-z0-9_+/=-]{40,})\1/gi;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Execute o scanner nos checks de pull request

Em um PR que reintroduza uma credencial operacional literal, este novo detector não bloqueia o merge: verifiquei pr-checks.yml, edge-functions-bundle.yml, edge-functions-request-id.yml e os demais workflows, e nenhum deles executa npm run security:secrets; a única referência está no script manual de package.json. Portanto, apesar de o relatório classificar a mudança como guard-rail de CI, o padrão só terá efeito quando alguém o executar localmente; inclua o scanner em um workflow obrigatório, com gatilho também para alterações neste script.

AGENTS.md reference: AGENTS.md:L19-L20

Useful? React with 👍 / 👎.

Comment on lines +19 to +20
const operationalSecretAssignmentPattern =
/\b(?:const|let|var)\s+[A-Za-z0-9_]*(?:ACCESS_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY)[A-Za-z0-9_]*\s*=\s*(['"`])(?:[0-9a-f]{32,}|[A-Za-z0-9_+/=-]{40,})\1/gi;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Detecte declarações TypeScript tipadas de segredos

Mesmo após o scanner ser ligado ao CI, uma declaração TypeScript comum como const ACCESS_TOKEN: string = "0123456789abcdef0123456789abcdef" não casa com este padrão, pois ele exige que = venha imediatamente após o identificador. Assim, credenciais literais com anotação de tipo passam silenciosamente pelo guard-rail; aceite anotações opcionais entre o nome e a atribuição ou analise a sintaxe TypeScript em vez de depender apenas desta expressão regular.

Useful? React with 👍 / 👎.

Deno.serve(withRequestId("migrate-helper", async (req, _ctx) => {
if (req.method === "OPTIONS") {
return new Response(null, { headers: corsHeaders });
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Respeite a allowlist de CORS no tombstone

Quando ALLOWED_ORIGINS está configurada, o preflight e a resposta 410 deste endpoint ainda retornam Access-Control-Allow-Origin: *, porque usam o valor estático corsHeaders; isso ignora a política configurada e permite que qualquer origem leia a resposta. O próprio contrato em _shared/cors.ts determina que novas Edge Functions usem getCorsHeaders(req) para aplicar a allowlist por requisição, portanto o tombstone deve calcular esses cabeçalhos tanto no OPTIONS quanto na resposta final.

Useful? React with 👍 / 👎.

@adm01-debug
adm01-debug merged commit 400e2ba into main Aug 31, 2026
12 of 15 checks passed
@adm01-debug
adm01-debug deleted the fix/hermes-h8171399-reconciliacao-online branch August 31, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants