Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix/evault access guard permission issue - #646

Merged
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue
Jan 3, 2026
Merged

Fix/evault access guard permission issue#646
coodos merged 5 commits into
mainfrom
fix/evault-access-guard-permission-issue

Conversation

@coodos

@coodoscoodos commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#645

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added Docker Compose configurations for core and socials service deployments.
    • Introduced JWT Bearer token authentication for API requests.
  • Bug Fixes

    • Enhanced URL validation in webhook delivery logic.
  • Documentation

    • Added GraphQL authorization testing guide with examples.
  • Chores

    • Upgraded Node.js runtime from version 18 to 20.
    • Removed legacy provisioning and verification services.
    • Added Docker management scripts for streamlined deployment.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 3, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

Introduces comprehensive infrastructure and authentication overhaul: adds Docker Compose configurations for core and social services with updated Node.js base images (18→20), adds Bearer token authentication to eVault-core GraphQL operations, removes provisioning-related entities and services, and expands Docker management scripts in package.json.

Changes

Cohort / File(s)Summary
Docker Compose Configurations
docker-compose.core.yml, docker-compose.socials.yml
New multi-service deployment stacks defining PostgreSQL, Neo4j, registry, eVault-core, and social platform services with networking, healthchecks, and inter-service dependencies.
Dockerfile Base Image & Tooling Updates
docker/Dockerfile.blabsy, docker/Dockerfile.blabsy-w3ds-auth-api, docker/Dockerfile.evault-core, docker/Dockerfile.pictique, docker/Dockerfile.pictique-api, docker/Dockerfile.registry
Upgraded base images from node:18-alpine to node:20-alpine, added build dependencies (python3, make, g++), updated pnpm to 10.25.0 and turbo to ^2, restructured multi-stage builds with explicit builder/runner stages, added healthchecks, and replaced dev commands with production execution.
Dockerfile Deletions
docker/Dockerfile.cerberus, docker/Dockerfile.dreamsync-api, docker/Dockerfile.eVoting, docker/Dockerfile.ereputation, docker/Dockerfile.evault, docker/Dockerfile.evault-prod, docker/Dockerfile.evoting-api, docker/Dockerfile.group-charter-manager, docker/Dockerfile.group-charter-manager-api, docker/Dockerfile.marketplace
Removed entire multi-stage Dockerfile configurations for 10 services, eliminating all build orchestration, dependency installation, and runtime setup for these containers.
eVault-core Authentication
infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
Added validateAuthentication() method to enforce Bearer token validation for non-store operations and X-ENAME header requirement for storeMetaEnvelope operations.
eVault-core Protocol Updates
infrastructure/evault-core/src/core/protocol/graphql-server.ts
Added try/catch around URL normalization in webhook filtering to gracefully handle invalid requestingPlatform URLs.
eVault-core Testing & Documentation
infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts, infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts, infrastructure/evault-core/GRAPHQL_TEST_POCS.md, infrastructure/evault-core/src/test-utils/mock-registry-server.ts
Added JWT-based Bearer token generation in tests, expanded authentication test coverage with multiple security scenarios, added GraphQL authorization test proof-of-concepts guide, and replaced mock tokens with real signed JWTs.
eVault-core Provisioning Removal
infrastructure/evault-core/src/core/provisioning/config/database.ts, infrastructure/evault-core/src/core/provisioning/entities/Verification.ts, infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts, infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
Removed ProvisioningDataSource, Verification entity, ProvisioningService class with provisionEVault method, and VerificationService class with all CRUD operations.
Configuration & Build
infrastructure/evault-core/tsconfig.json, infrastructure/w3id/tests/utils/codec.test.ts, package.json
Excluded e2e tests from TypeScript build, fixed minor test indentation, and added docker:core/docker:socials scripts for Docker Compose orchestration.

Sequence Diagram(s)

sequenceDiagram
participant Client
participant GraphQL as GraphQL Server
participant Guard as VaultAccessGuard
participant Resolver as Resolver Logic
participant DB as Database
Client->>GraphQL: GraphQL Query/Mutation
Note over GraphQL: Inspect operation type
alt Store Operation (storeMetaEnvelope)
GraphQL->>Guard: validateAuthentication(context, true)
Guard->>Guard: Check X-ENAME header
alt X-ENAME present & non-empty
Guard->>Guard: Extract eName
rect rgb(200, 220, 200)
Note over Guard: Optional: parse Bearer token
end
Guard->>GraphQL: ✓ Auth passed
else X-ENAME missing/empty
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
else Read/Update Operation
GraphQL->>Guard: validateAuthentication(context, false)
Guard->>Guard: Check Authorization header
alt Valid Bearer token
Guard->>Guard: Validate JWT
rect rgb(200, 220, 200)
Note over Guard: Extract tokenPayload
end
Guard->>GraphQL: ✓ Auth passed
GraphQL->>Resolver: Execute resolver
Resolver->>DB: Perform operation
DB->>Resolver: Return data
Resolver->>GraphQL: Return result
GraphQL->>Client: 200 Result
else No token or invalid token
Guard->>GraphQL: ✗ Throw error
GraphQL->>Client: 401 Unauthorized
end
end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • Feat/evault provisioning via phone #188 — Removes Verification entity and ProvisioningService logic alongside provisioning database config, directly related to provisioning code removal in this PR.
  • Feat/evault core #100 — Modifies vault-access-guard.ts and graphql-server.ts authentication/authorization logic, same code areas as the Bearer token authentication additions.
  • Chore/evault pitstop refactor #395 — Modifies provisioning surface (ProvisioningService, Verification entity, database config), shares the same code artifacts being removed in this PR.

Suggested labels

evault-refactor

Suggested reviewers

  • sosweetham
  • xPathin

Poem

🐰 Dockerfiles renovated, node twenty takes the stage,
Bearer tokens guard the gates in auth's bright new age,
Provisioning fades away, provisions rest their case,
GraphQL queries now authenticate their place!

✨ Finishing touches
  • 📝 Generate docstrings

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6b5b420 and 080759f.

📒 Files selected for processing (31)
  • docker-compose.core.yml
  • docker-compose.socials.yml
  • docker/Dockerfile.blabsy
  • docker/Dockerfile.blabsy-w3ds-auth-api
  • docker/Dockerfile.cerberus
  • docker/Dockerfile.dreamsync-api
  • docker/Dockerfile.eVoting
  • docker/Dockerfile.ereputation
  • docker/Dockerfile.evault
  • docker/Dockerfile.evault-core
  • docker/Dockerfile.evault-prod
  • docker/Dockerfile.evoting-api
  • docker/Dockerfile.group-charter-manager
  • docker/Dockerfile.group-charter-manager-api
  • docker/Dockerfile.marketplace
  • docker/Dockerfile.pictique
  • docker/Dockerfile.pictique-api
  • docker/Dockerfile.registry
  • infrastructure/evault-core/GRAPHQL_TEST_POCS.md
  • infrastructure/evault-core/src/core/protocol/graphql-server.spec.ts
  • infrastructure/evault-core/src/core/protocol/graphql-server.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.spec.ts
  • infrastructure/evault-core/src/core/protocol/vault-access-guard.ts
  • infrastructure/evault-core/src/core/provisioning/config/database.ts
  • infrastructure/evault-core/src/core/provisioning/entities/Verification.ts
  • infrastructure/evault-core/src/core/provisioning/services/ProvisioningService.ts
  • infrastructure/evault-core/src/core/provisioning/services/VerificationService.ts
  • infrastructure/evault-core/src/test-utils/mock-registry-server.ts
  • infrastructure/evault-core/tsconfig.json
  • infrastructure/w3id/tests/utils/codec.test.ts
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 3fdea04 into mainJan 3, 2026
6 of 7 checks passed
@coodos
coodos deleted the fix/evault-access-guard-permission-issue branch January 3, 2026 17:20
This was referenced Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] (eVault-core) Bulk endpoints allow all requests without authorization to be used

2 participants

@coodos@sosweetham