fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(storage): converge the avatars bucket on public read (#316) - #502

Merged
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public
Jul 31, 2026
Merged

fix(storage): converge the avatars bucket on public read (#316)#502
AndresL230 merged 1 commit into
mainfrom
fix/316-avatars-bucket-public

Conversation

@AndresL230

Copy link
Copy Markdown
Collaborator

Part of #316.

The issue's suggested fix would have worked, but not lasted

The issue proposes flipping the staging bucket to public. That fixes staging. It does not explain why staging drifted, and it leaves the same drift possible on the next environment.

Both mechanisms that "create" this bucket decline to correct an existing one:

  • 0011_avatars_bucket.sql inserts it with public = true but ends in ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
  • storage_service.ensure_bucket_exists (called from main.py's lifespan with public=True) treats the Storage API's 409 as success and deliberately does not overwrite settings, "in case an admin has intentionally tuned them in the dashboard".

So a bucket that came into existence private stays private forever, through any number of deploys and migrations. An UPDATE is the only thing that corrects it — hence a new file rather than a re-run of 0011.

The one judgment call

This deliberately overrides ensure_bucket_exists's "an admin may have tuned it" stance, for this bucket only. The read path is an unauthenticated <img src> against /storage/v1/object/public/avatars/..., so private isn't a valid tuning — it's broken avatars. 0029 already recorded the intent ("avatars stays public (intended public read)"); this asserts that state instead of assuming it.

Verification

  • From-empty replay (scripts/local-db-reset.sh, not a normal cycle — e2e-up runs against a DB that already has the schema): the whole chain applies clean with 0041 in it.
  • Effect on a drifted bucket: forced avatars to public=false to reproduce the staging condition, then ran the statement — flips to true, idempotent on re-run, and a safe zero-row no-op against a non-existent bucket id.
  • Full local e2e cycle green (Playwright 37/37, oracles 0 findings).

This does not fix staging by itself

It converges on the next python -m db.migrate against that project. #316 should stay open until that's run — I don't have (and shouldn't use) staging credentials for it.

🤖 Generated with Claude Code

Staging has avatars public=false while prod is public=true and 0029 records
the intent explicitly. Avatar <img> src values are plain public object URLs,
so a private bucket serves 400s and every avatar on staging renders broken.
The reason this never self-heals is the interesting part: BOTH mechanisms
that "create" the bucket decline to fix an existing one.
- 0011_avatars_bucket.sql inserts it with public=true but ends in
ON CONFLICT (id) DO NOTHING — a no-op once the row exists.
- storage_service.ensure_bucket_exists (lifespan, public=True) treats the
Storage API's 409 as success and deliberately does NOT overwrite settings,
"in case an admin has intentionally tuned them in the dashboard".
So a bucket that came into existence private stays private forever, through
any number of deploys and migrations. An UPDATE is the only thing that
corrects it — hence a new file rather than a re-run of 0011.
This deliberately overrides that "an admin may have tuned it" stance for THIS
bucket: the read path is unauthenticated <img src> against
/storage/v1/object/public/avatars/..., so private isn't a valid tuning, it's
broken avatars.
Verified locally: from-empty replay applies the whole chain clean with 0041 in
it; and against a bucket forced private to simulate the staging drift, the
statement flips it to true, is idempotent on re-run, and is a safe zero-row
no-op where the bucket doesn't exist.
Does NOT fix staging by itself — that needs `python -m db.migrate` against
that project.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabaseBot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ybgqdonkoqftwrmweuyv because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 773fa0fb-f283-43fe-a2fe-13ed57415245

📥 Commits

Reviewing files that changed from the base of the PR and between 729a6ff and 201f4cd.

📒 Files selected for processing (1)
  • backend/db/migrations/0041_avatars_bucket_public.sql

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 31, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging201f4cdCommit Preview URL

Branch Preview URL
Jul 31 2026, 06:25 PM

@AndresL230

Copy link
Copy Markdown
CollaboratorAuthor

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Independently verified beyond the diff:

  • Transactionality/idempotencedb/migrate.py commits the migration SQL and the schema_migrations ledger insert together, so this runs exactly once per environment; the UPDATE is a no-op when already true and a zero-row no-op when the bucket is absent. From-empty replay is safe because 0011 (which INSERTs the row) sorts before 0041.
  • Privilege claim is real, not assumed0029 already performed an UPDATE storage.buckets through this same runner, and the prod snapshots in the working tree confirm those changes are live in prod today.
  • Security directionupload_cosmetic_asset writes into the same bucket under cosmetics/, so it's worth stating explicitly: those are admin-managed achievement/role reward assets, not user PII, and docs/security/storage-hardening-plan.md scoped avatars as intended-public while locking down issues-media-files and application_resumes. Prod has had avatars public all along — this converges the drifted staging copy onto already-live, already-reviewed state rather than opening new surface.
  • Numbering — 0041 is the correct next number; no open PR touches db/migrations/.

🤖 Generated with Claude Code

@AndresL230
AndresL230 merged commit ac5e21e into mainJul 31, 2026
7 checks passed
@AndresL230
AndresL230 deleted the fix/316-avatars-bucket-public branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@AndresL230