Skip to content

chore: data-minimization hardening — closed sync-error codes, drop unused columns, delete-on-revoke sessions - #66

Merged
Aliferous3 merged 1 commit into
mainfrom
chore/data-minimization-hardening
Sep 30, 2026
Merged

Aliferous3 merged 1 commit into
mainfrom
chore/data-minimization-hardening

Conversation

@Aliferous3

Copy link
Copy Markdown
Owner

Summary

Focused data-minimization tranche: persist only what the product reads.

  • Sync errors → closed taxonomy (lib/sync-errors.mjs): repo_sync.error / user_sync.error now persist only GITHUB_RATE_LIMIT, GITHUB_ACCESS_REVOKED, SYNC_HISTORY_FAILED, SYNC_PULLS_FAILED, or SYNC_INTERNAL_ERROR. Raw err.message/stack/provider text can no longer reach the DB; API boundaries translate codes to fixed human-readable strings so SyncMonitor UX is unchanged.
  • Drop write-only columns (migrations/011_persistence_minimization.sql): commits.{author_user_id,author_login,authored_at,files_changed,is_merge} and pull_requests.{number,author_user_id,author_login,closed_at} — zero readers in runtime code, dashboard SQL, views, share/export, or API responses. Migration also rewrites legacy free-text error values to codes and purges dead session rows.
  • Sessions delete-on-revoke: logout / kill-all / DELETE MY DATA delete auth_sessions rows immediately; GC purges expired or legacy-revoked rows outright (was a ~30-day tombstone tail). revoked_at retained as a defensive filter column for pre-change rows. Missing-sid fails isSessionLive identically — no auth semantics change.
  • Docs: privacy policy collaborator claim removed; security trust record, architecture, and disaster-recovery docs updated to the final schema.
  • Attribution guards untouched: GraphQL author:{id}, isAttributedCommit, item.user?.id === github_user_id, webhook author check — all still enforced transiently at ingest.

Migration safety

Forward-only, idempotent DROP COLUMN IF EXISTS; deploy code first, then apply migration (same discipline as 008). Drops remove columns only — no rows are deleted except dead session records and rewritten error values.

Security/privacy implications

Reduces retained surface: no author identifiers, no raw provider error text, no revoked-session tombstones. No new permissions, grants, or policies; RLS/grants unchanged.

Test plan

  • npm test — 494 pass / 0 fail / 3 skipped (real-DB), incl. 18 new data-minimization guards
  • npm run typecheck — clean
  • npm run build — green
  • npm audit --audit-level=moderate — 0 vulnerabilities
  • CI green (build/test/audit/gitleaks)
  • Pre-migration backup + baseline counts before applying 011
  • Post-migration schema/RLS/grants verification + browser QA

Generated with Devin

… unused columns, delete-on-revoke sessions

Persist only what the product reads:

- Sync errors: repo_sync.error / user_sync.error now carry a closed
  taxonomy code (lib/sync-errors.mjs) instead of String(err.message).
  Raw provider exception text, URLs, response bodies and stack traces
  can no longer reach persistent storage; APIs translate codes back to
  fixed messages at the presentation boundary, so SyncMonitor UX is
  unchanged. Migration 011 rewrites legacy free-text values.

- Drop write-only columns: commits.author_user_id, author_login,
  authored_at, files_changed, is_merge and pull_requests.number,
  author_user_id, author_login, closed_at had zero readers in runtime,
  dashboard SQL, views, share/export, or API responses. Attribution
  guards (GraphQL author filter, isAttributedCommit, author-id checks)
  remain transiently enforced at ingest.

- Sessions: logout and kill-all now DELETE auth_sessions rows instead
  of retaining revoked tombstones for ~30 days; GC purges expired or
  legacy-revoked rows outright. Missing-sid fails isSessionLive
  identically, so security semantics are unchanged. revoked_at stays
  as a defensive filter column for legacy rows.

- Docs (privacy policy, security page, architecture, disaster
  recovery) updated to match the final schema exactly.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
dev-ledger Building Building Preview Sep 30, 2026 8:42am UTC

@Aliferous3
Aliferous3 merged commit 533f0a3 into main Sep 30, 2026
5 checks passed

This branch was successfully deployed

1 active deployment
Preview — 9c54ed1b Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant