Repository navigation
chore: data-minimization hardening — closed sync-error codes, drop unused columns, delete-on-revoke sessions - #66
Merged
Conversation
… unused columns, delete-on-revoke sessions Persist only what the product reads: - Sync errors: repo_sync.error / user_sync.error now carry a closed taxonomy code (lib/sync-errors.mjs) instead of String(err.message). Raw provider exception text, URLs, response bodies and stack traces can no longer reach persistent storage; APIs translate codes back to fixed messages at the presentation boundary, so SyncMonitor UX is unchanged. Migration 011 rewrites legacy free-text values. - Drop write-only columns: commits.author_user_id, author_login, authored_at, files_changed, is_merge and pull_requests.number, author_user_id, author_login, closed_at had zero readers in runtime, dashboard SQL, views, share/export, or API responses. Attribution guards (GraphQL author filter, isAttributedCommit, author-id checks) remain transiently enforced at ingest. - Sessions: logout and kill-all now DELETE auth_sessions rows instead of retaining revoked tombstones for ~30 days; GC purges expired or legacy-revoked rows outright. Missing-sid fails isSessionLive identically, so security semantics are unchanged. revoked_at stays as a defensive filter column for legacy rows. - Docs (privacy policy, security page, architecture, disaster recovery) updated to match the final schema exactly. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Focused data-minimization tranche: persist only what the product reads.
lib/sync-errors.mjs):repo_sync.error/user_sync.errornow persist onlyGITHUB_RATE_LIMIT,GITHUB_ACCESS_REVOKED,SYNC_HISTORY_FAILED,SYNC_PULLS_FAILED, orSYNC_INTERNAL_ERROR. Rawerr.message/stack/provider text can no longer reach the DB; API boundaries translate codes to fixed human-readable strings so SyncMonitor UX is unchanged.migrations/011_persistence_minimization.sql):commits.{author_user_id,author_login,authored_at,files_changed,is_merge}andpull_requests.{number,author_user_id,author_login,closed_at}— zero readers in runtime code, dashboard SQL, views, share/export, or API responses. Migration also rewrites legacy free-text error values to codes and purges dead session rows.auth_sessionsrows immediately; GC purges expired or legacy-revoked rows outright (was a ~30-day tombstone tail).revoked_atretained as a defensive filter column for pre-change rows. Missing-sid failsisSessionLiveidentically — no auth semantics change.author:{id},isAttributedCommit,item.user?.id === github_user_id, webhook author check — all still enforced transiently at ingest.Migration safety
Forward-only, idempotent
DROP COLUMN IF EXISTS; deploy code first, then apply migration (same discipline as 008). Drops remove columns only — no rows are deleted except dead session records and rewritten error values.Security/privacy implications
Reduces retained surface: no author identifiers, no raw provider error text, no revoked-session tombstones. No new permissions, grants, or policies; RLS/grants unchanged.
Test plan
npm test— 494 pass / 0 fail / 3 skipped (real-DB), incl. 18 new data-minimization guardsnpm run typecheck— cleannpm run build— greennpm audit --audit-level=moderate— 0 vulnerabilitiesGenerated with Devin