Uh oh!
There was an error while loading. Please reload this page.
docs: record Wave 3 (security wave + production RLS lockdown) in PROGRAM.md - #237
Conversation
…RAM.md Adds a Wave 3 section: the eleven merged security PRs (#219-#230) one line each, the #234 ruff-gate hotfix + lesson, and — the part that lives in no PR — the out-of-band production RLS lockdown (exposure, remediation, clean blast-radius audit, and the summary_json/messages.content plaintext caveat). Open follow-up tracks (storage hardening, realtime JWT bridge, encrypt summary_json/content, #235/#236, prod deploy) recorded in the backlog.
Caution Review failedPull request was closed or merged during review 📝 WalkthroughWalkthrough
ChangesWave 3 Security Hardening Documentation
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Deploying with |
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs | frontend | d9f7b0c | Commit Preview URL Branch Preview URL | Jun 15 2026, 04:43 AM |
Uh oh!
There was an error while loading. Please reload this page.
Docs-only. Adds a Wave 3 section to PROGRAM.md, consistent with how Waves 1–2 are recorded.
mainis clean under a new lint gate at merge).ENABLE RLS+REVOKEremediation applied via the Supabase SQL Editor (SQL kept in DRAFT (#231): RLS lockdown SQL + storage & realtime(a) remediation plans — do not merge/apply #232 as the applied record), the clean blast-radius audit (oauth_tokens encrypted → no rotation; sessions no replayable credential; admin audit clean), and thesummary_json/messages.contentplaintext caveat.No code changes.
Summary by CodeRabbit