feat(apisix): validate upstreams and credentials - #602
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe APISIX validator now serializes validation resources as JSON, includes upstreams, and maps consumer credentials to parent-derived IDs. Tests cover valid and invalid upstream and credential configurations. ChangesAPISIX validation
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The new validation payload paths include upstreams and consumer credentials with matching resource identifiers, with no actionable merge risk identified. Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (5 passed)
Full details: Security CheckExplanation Category 1 — CRITICAL: Sensitive Data Exposure in Logs & Responses. Resolution Keep the complete credential payload on the HTTPS request to APISIX so validation can inspect it, but prevent it from entering logs. Add a sensitive-request path or redaction hook to
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Description
Perform server-side validation of
upstreamsandcredentials. In previous implementations, these were skipped; now they are no longer skipped.Checklist
Summary by CodeRabbit
New Features
Bug Fixes