chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: fix signing service message comparison - #431

Merged
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison
Nov 14, 2025
Merged

chore: fix signing service message comparison#431
coodos merged 1 commit into
mainfrom
fix/evoting-message-comparison

Conversation

@coodos

@coodoscoodos commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Description of change

fix signing service issue with message comparison

Issue Number

Type of change

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Enhanced security validation during vote submission with identity verification checks.
    • Improved input validation and session status verification for signed payloads.
  • New Features
    • Added support for multiple voting modes (normal, point, and rank voting).
    • Extended vote submission to handle both private and public polls.

@coderabbitai

coderabbitaiBot commented Nov 14, 2025

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

Walkthrough

This pull request adds verbose logging to SigningController and significantly enhances SigningService with comprehensive runtime validation, security checks, and dynamic vote submission logic. Changes include session validation, w3id verification against user ename, message parsing and comparison, poll-based routing, and extensive observability improvements.

Changes

Cohort / File(s)Summary
Logging Enhancement
platforms/evoting-api/src/controllers/SigningController.ts
Adds verbose logging throughout handleSignedPayload: request body and headers at start, validation failures, success confirmations, and processing results.
Security & Validation Enhancements
platforms/evoting-api/src/services/SigningService.ts
Adds session existence/status checks, dynamic UserService import for security verification, w3id-to-ename comparison with security_violation marking, robust JSON message parsing with field validation, poll lookup and visibility-based branching (private/public), vote submission with mode determination (normal/point/rank), and session completion with subscriber notifications.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant SigningController
participant SigningService
participant SessionStore
participant UserService
participant VotingSystem
participant Subscribers
Client->>SigningController: handleSignedPayload(request)
SigningController->>SigningController: Log request body & headers
rect rgb(200, 220, 255)
Note over SigningController: Validation Phase
alt Missing fields
SigningController->>SigningController: Log missing fields
SigningController-->>Client: Error response
else All fields present
SigningController->>SigningController: Log success
end
end
SigningController->>SigningService: processSignedPayload(payload)
SigningService->>SigningService: Log input payload
rect rgb(220, 200, 255)
Note over SigningService: Session Verification
SigningService->>SessionStore: Check session exists & status
alt Session not found / expired / completed
SigningService->>SigningService: Log error
SigningService-->>SigningController: Error result
else Valid session
SigningService->>SigningService: Continue
end
end
rect rgb(240, 200, 200)
Note over SigningService: Security Verification
SigningService->>UserService: Retrieve user by session.userId
SigningService->>SigningService: Compare w3id vs user.ename
alt w3id mismatch
SigningService->>SessionStore: Mark security_violation
SigningService->>Subscribers: Notify violation
SigningService-->>SigningController: Security error
else w3id match
SigningService->>SigningService: Proceed
end
end
rect rgb(200, 240, 200)
Note over SigningService: Message & Vote Processing
SigningService->>SigningService: Parse message JSON
alt Parse failure
SigningService-->>SigningController: Invalid format error
else Parse success
SigningService->>SigningService: Compare pollId, userId, voteData
alt Field mismatch
SigningService-->>SigningController: Verification failure
else Fields match
SigningService->>VotingSystem: Lookup poll & determine vote mode
alt Private poll
SigningService->>VotingSystem: Submit blind vote
else Public poll
SigningService->>VotingSystem: Submit vote (normal/point/rank mode)
end
SigningService->>SessionStore: Update status to completed
SigningService->>Subscribers: Notify with completion payload
SigningService-->>SigningController: Success result
end
end
end
SigningController->>SigningController: Log processing result
SigningController-->>Client: Response
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

  • SigningService.ts requires careful attention to the new security verification workflow, including dynamic UserService import, w3id-to-ename comparison logic, and message field validation against session data.
  • Vote submission branching based on poll visibility (private vs. public) and vote mode determination (normal/point/rank) involves multiple control paths that need verification.
  • Session status transitions and subscriber notification logic must be traced to ensure proper state management.
  • Error handling paths across multiple validation checkpoints should be reviewed for completeness and consistency.

Possibly related PRs

  • chore: signing bug #315: Introduces similar security verification workflow with dynamic UserService import to validate w3id matches session owner's ename.

Suggested reviewers

  • sosweetham
  • ananyayaya129

Poem

🐰 With signings secured and sessions now checked,
w3ids verified, security-wrecked-then-protected,
Blind votes drift private, polls branch with grace,
Each vote finds its path in the right voting place!

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/evoting-message-comparison

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ec9e514 and e25bf44.

📒 Files selected for processing (2)
  • platforms/evoting-api/src/controllers/SigningController.ts (2 hunks)
  • platforms/evoting-api/src/services/SigningService.ts (3 hunks)

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 490ae34 into mainNov 14, 2025
3 of 4 checks passed
@coodos
coodos deleted the fix/evoting-message-comparison branch November 14, 2025 08:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@coodos@kulmin@sosweetham