Repository navigation
feat(oci): add native foundation - #7444
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryThe PR introduces native server-side OCI API-key credential support, including validation, request signing, endpoint resolution, encrypted storage, API contracts, and setup UI.
Confidence Score: 5/5The PR appears safe to merge because no blocking failure remains in the eligible follow-up review scope. No blocking failure remains.
|
| Filename | Overview |
|---|---|
| apps/sim/lib/internal/oci/client.server.ts | Implements server-only OCI credential parsing, Signature v1 request signing, bounded transport, and setup verification. |
| apps/sim/lib/internal/oci/endpoints.ts | Adds a fixed OCI region/realm registry and strict service-endpoint validation. |
| apps/sim/lib/credentials/oci-api-key-service-account.server.ts | Validates OCI API-key material, verifies it against OCI, sanitizes failures, and encrypts the resulting secret. |
| apps/sim/lib/credentials/orchestration/index.ts | Integrates OCI fields into credential updates and enforces complete credential tuples during rotation. |
| apps/sim/lib/credentials/orchestration/credential-create.ts | Integrates OCI verification and sanitized provider errors into credential creation. |
| apps/sim/lib/api/contracts/v2/credentials.ts | Extends V2 credential contracts with OCI identifiers, region, private key, and optional passphrase fields. |
| apps/sim/app/workspace/[workspaceId]/integrations/components/connect-service-account-modal/connect-service-account-modal.tsx | Adds the OCI API-key setup and reconnect form with required-field checks and secret inputs. |
| apps/sim/lib/credentials/service-account-secret.ts | Registers OCI as a supported service-account secret provider and routes its fields through verification. |
| packages/sim-cli/src/generated/v2-api.ts | Updates generated CLI API types to expose the new write-only OCI credential fields. |
Sequence Diagram
sequenceDiagram
participant User
participant API as Credential API
participant Validator as OCI Credential Validator
participant OCI as OCI GetNamespace
participant Store as Encrypted Credential Store
User->>API: Submit OCI API-key fields
API->>Validator: Validate OCIDs, region, fingerprint, and RSA key
Validator->>OCI: Send signed, bounded GetNamespace request
OCI-->>Validator: Return namespace
Validator->>Store: Encrypt and persist validated credential
Store-->>API: Return sanitized credential metadata
API-->>User: Credential created or rotated
Reviews (17): Last reviewed commit: "fix(oci): preserve transport size errors" | Re-trigger Greptile
There was a problem hiding this comment.
All reported issues were addressed across 12 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
d7a3b4f to
d2d066d
Compare
|
@greptile review this PR |
|
@cubic-dev-ai review this PR |
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
d2d066d to
77e26a0
Compare
|
@greptile review this PR |
|
@cubic-dev-ai review this PR |
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
|
@greptile review this PR |
|
@cubic-dev-ai review this PR |
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
b1c7879 to
a48813a
Compare
|
@greptile review this PR |
|
@cubic-dev-ai review this PR |
@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
5 issues found across 12 files
Confidence score: 2/5
apps/sim/lib/internal/oci/errors.tscan leave provider-supplied signatures in sanitized OCI diagnostics, including authorization fragments with spaces around=; broaden the signature guard or fail closed for the full fragment and classifysignatureas sensitive.apps/sim/lib/internal/oci/client.server.tsmay expose credential-bearingserviceHeadersvalues when providers echo them in errors, creating a credential-leak risk; include caller-supplied signed-header values in the shared redaction set.apps/sim/lib/internal/oci/client.server.tsfully buffers and parses large non-2xx response bodies before applying the diagnostic cap, increasing memory and resource-exhaustion risk; use the bounded response reader with a 64 KiB limit and cancel oversized reads.apps/sim/lib/internal/oci/client.server.test.tsdoes not actually exercise redaction because the echoed percent-encoded URL causessanitizeOciErrorFieldto fail closed; revise the fixture and assertions to verify the intended secret removal.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="apps/sim/lib/internal/oci/client.server.ts">
<violation number="1" location="apps/sim/lib/internal/oci/client.server.ts:130">
P2: When `serviceHeaders` contains a credential-bearing value, the sanitized OCI error can expose it if the service echoes the header. Include credential values from the caller-supplied signed headers using the shared header extractor before parsing the diagnostic.</violation>
<violation number="2" location="apps/sim/lib/internal/oci/client.server.ts:136">
P2: When a caller allows a large response, a non-2xx OCI response is fully buffered and JSON-parsed before the diagnostic cap applies. Read error bodies through the bounded response-reader with a 64 KiB limit, cancel on overflow, and fall back to the status-only `OciRequestError`.</violation>
</file>
<file name="apps/sim/lib/internal/oci/errors.ts">
<violation number="1" location="apps/sim/lib/internal/oci/errors.ts:10">
P1: When an OCI response contains a serialized `signature` diagnostic field, `flattenJsonDiagnostic` emits the provider-supplied signature because neither key policy classifies it. Add `signature` to the OCI sensitive-key set so the request signature cannot reach `OciRequestError.message`.
(Based on your team's feedback about remaining credential-shaped fragments in provider diagnostics.)</violation>
<violation number="2" location="apps/sim/lib/internal/oci/errors.ts:113">
P1: When a provider echoes an OCI authorization fragment with spaces around `=`, this regex does not match and the unknown signature remains in the error message. Broaden the Signature guard or fail closed on the whole fragment before returning the diagnostic.
(Based on your team's feedback about remaining credential-shaped fragments in provider diagnostics.)</violation>
</file>
<file name="apps/sim/lib/internal/oci/client.server.test.ts">
<violation number="1" location="apps/sim/lib/internal/oci/client.server.test.ts:238">
P3: This test never exercises redaction. The echoed message includes the percent-encoded request URL (encodeURIComponent of the https origin), which contains %3A/%2F; sanitizeOciErrorField in errors.ts fails closed on any percent-encoded octet and returns a status-only error. All four not.toContain assertions then pass against the generic 'OCI request failed with status 401' message, so a regression in encoded-credential redaction would go undetected. Drop the percent-encoded URL from the echoed message so the diagnostic passes the percent guard, and assert the encoded fingerprint/passphrase are actually replaced with [REDACTED].</violation>
</file>
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Re-trigger cubic
|
@greptile review this PR |
26c2e76 to
3fa59e7
Compare
10f2438 to
5f7ab5a
Compare
5f7ab5a to
397998e
Compare
Adds the native OCI foundation shared by 14 product PRs: API-signing-key validation and encrypted storage, credential setup and reconnect through the shared service-account modal, workspace/service-bound credential loading, request signing, endpoint policies, DNS-pinned transport, cancellation, and bounded requests and responses. Product blocks, tools, selectors, and response schemas remain in their child PRs; this foundation exposes no product integration.
Request bodies above the shared 100 MiB buffer limit are rejected before copying. Private-key PEM input supports multiple lines and masking, with API-key-specific connection labels. Credentials use the normal encrypted workspace credential lifecycle; no shared OAuth app or deployment secret is required.
Validation on head
397998e46ac0abfb2bcaf78a7b23672a0b9ddf19, rebased onto stagingd2bbd34d98:Live OCI authentication/setup testing is still pending account access; no live-account pass is claimed. Before shipping the 14 product integrations, restack and validate each child against staging. OCI Compute (#7549) must reintroduce
OCI_REGION_IDSalongside its real consumer.