Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Address intake review follow-ups - #346

Merged
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups
Jun 28, 2026
Merged

Address intake review follow-ups#346
michaelmwu merged 2 commits into
mainfrom
michaelmwu/intake-review-followups

Conversation

@michaelmwu

@michaelmwumichaelmwu commented Jun 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Preserve sanitized raw Google Forms intake webhook payloads for audit/debug storage.
  • Avoid retrying resume download/scan after create/update flows already attempted preparation and got no usable file.
  • Add regression coverage for Google raw payload preservation and single-attempt resume preparation failures.

Testing

  • ./scripts/pyrefly.sh --output-format=full-text
  • ./scripts/lint.sh
  • ./scripts/test.sh

Follow-up for review threads from #335:

  • PRRT_kwDOQGJDqs6MzZfQ
  • PRRT_kwDOQGJDqs6MzZfN

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions now handle attached resume data more reliably, avoiding repeated retry attempts when resume preparation fails.
    • Stored webhook payloads are now cleaned more consistently, including nested data and sensitive URL query strings.
    • Google Forms and Tally intake data now preserve the expected submission details while keeping signed links sanitized in stored raw data.

@coderabbitai

coderabbitaiBot commented Jun 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@michaelmwu, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 44 minutes and 28 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 451fd060-2f8b-496d-aa50-0ab3507ce727

📥 Commits

Reviewing files that changed from the base of the PR and between 95ffed1 and 7de656c.

📒 Files selected for processing (3)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
📝 Walkthrough

Walkthrough

Replaces the Tally-specific raw payload sanitizer with a generic _sanitize_intake_raw_payload that strips URL query params from string values. Google Forms intake gains a raw_payload field in enqueued jobs. A sentinel value _RESUME_FILE_NOT_PROVIDED is introduced to prevent duplicate resume preparation when _prepare_resume_file returns None.

Intake Sanitization and Resume Sentinel

Layer / File(s)Summary
Generic intake payload sanitizer and webhook wiring
apps/api/src/five08/backend/api.py
Replaces _sanitize_tally_raw_payload with _sanitize_intake_raw_payload, which recursively normalizes mapping keys to strings, walks lists, and strips URL query params from string values. Google Forms intake adds raw_payload to the enqueued job; Tally intake switches to the same sanitizer.
Resume file sentinel and _build_resume_updates logic
apps/worker/src/five08/worker/crm/intake_form_processor.py
Adds _ResumeFileNotProvided sentinel class and _RESUME_FILE_NOT_PROVIDED constant. Updates _build_intake_updates and _build_resume_updates to resolve prepared_resume_file from the payload only when the sentinel is passed, otherwise using the provided value directly.
Tests for sanitizer contract and resume sentinel
tests/unit/test_backend_api.py, tests/unit/test_intake_form_processor.py
Updates test_google_forms_intake_enqueues_job to assert raw_payload strips URL query params while the normalized resume_url retains them. Adds two tests confirming _prepare_resume_file is invoked exactly once when it returns None, for both create and update prospect paths.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • 508-dev/508-workflows#74: Modifies the Google Forms intake webhook handler and enqueue payload, directly overlapping with the raw_payload and resume_url handling changed here.

Poem

🐇 A sentinel hops in, distinct from None,
No resume retried when the first fetch is done.
URL query params? Stripped from the store,
The raw payload keeps what the job needn't more.
Keys become strings, lists walk in a row—
Clean data flows where webhooks go! 🌿

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 69.23% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the PR’s focus on addressing intake-related review follow-ups.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch michaelmwu/intake-review-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens intake processing across the API and worker to improve audit/debug traceability and avoid redundant resume preparation work, with regression tests to lock in behavior.

Changes:

  • Preserve a sanitized raw_payload for Google Forms intake jobs (and unify raw-payload sanitization for both Google Forms and Tally).
  • Ensure resume download/scan preparation is attempted at most once per create/update flow in the worker.
  • Add unit coverage for raw payload preservation and the single-attempt resume preparation behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

FileDescription
apps/api/src/five08/backend/api.pyAdds sanitized raw_payload for Google Forms jobs and unifies intake raw-payload sanitization.
apps/worker/src/five08/worker/crm/intake_form_processor.pyIntroduces a sentinel to distinguish “not provided” vs explicit None, preventing resume prepare retries.
tests/unit/test_backend_api.pyAdds assertions for resume_url passthrough + sanitized raw_payload preservation.
tests/unit/test_intake_form_processor.pyAdds regression tests ensuring resume preparation isn’t retried in create/update flows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +714 to +718
prepared_resume_file: IntakeResumeFile | None
if isinstance(resume_file, _ResumeFileNotProvided):
prepared_resume_file = self._prepare_resume_file(payload)
else:
prepared_resume_file = resume_file

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/api/src/five08/backend/api.py`:
- Around line 822-828: The shared sanitizer in _sanitize_intake_raw_payload
currently strips query strings but still preserves URL fragments, so sensitive
fragment data can be persisted in onboarding_intake_submissions.raw_payload.
Update the URL handling in this sanitizer to remove fragments as well as queries
before storage, and keep the change localized to the shared raw-payload path so
all callers benefit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b16700bf-1138-499c-8774-dbd2fc37b70f

📥 Commits

Reviewing files that changed from the base of the PR and between f568641 and 95ffed1.

📒 Files selected for processing (4)
  • apps/api/src/five08/backend/api.py
  • apps/worker/src/five08/worker/crm/intake_form_processor.py
  • tests/unit/test_backend_api.py
  • tests/unit/test_intake_form_processor.py

Comment threadapps/api/src/five08/backend/api.py
@michaelmwu
michaelmwu merged commit 80f1c8e into mainJun 28, 2026
11 checks passed
@michaelmwu
michaelmwu deleted the michaelmwu/intake-review-followups branch June 28, 2026 14:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@michaelmwu