fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env - #277

Merged
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual
May 29, 2026
Merged

fix: deduplicate safeEqual in auth.ts by importing from dispatch-env#277
joryirving merged 2 commits into
mainfrom
fix/268-deduplicate-safeEqual

Conversation

@itsmiso-ai

Copy link
Copy Markdown
Contributor

Deduplicates safeEqual in src/lib/auth.ts by importing from @/lib/dispatch-env instead of maintaining a local copy.

This eliminates code duplication and ensures all timing-safe string comparisons use the same implementation (crypto.timingSafeEqual).

#Fixes#268

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: #277 — fix: deduplicate safeEqual in auth.ts by importing from dispatch-env

Summary

This PR removes a 13-line duplicate safeEqual function from src/lib/auth.ts and imports it from ./dispatch-env instead. This is a straightforward deduplication that eliminates code duplication and ensures consistent timing-safe string comparison across the codebase.

Change-by-Change Findings

FileChangeAssessment
src/lib/auth.tsRemoved timingSafeEqual import from node:crypto, added safeEqual to ./dispatch-env import, deleted local safeEqual function (13 lines)✅ Correct - delegates to the canonical implementation

Technical Analysis

Before (duplicate):

import{timingSafeEqual}from"node:crypto";functionsafeEqual(a: string,b: string): boolean{if(a.length!==b.length)returnfalse;constaBuf=Buffer.from(a);constbBuf=Buffer.from(b);returntimingSafeEqual(aBuf,bBuf);}

After (canonical import):

import{ ...,safeEqual}from"./dispatch-env";

The local function was functionally equivalent to the dispatch-env implementation—both use crypto.timingSafeEqual for constant-time comparison. The deduplication is clean and correct.

Standards Compliance

No hardcoded agent/repo names - Pure refactoring, no identity assumptions
Error handling - Not applicable (no new logic introduced)
Validation - Not applicable (import substitution only)
No secrets - No sensitive data involved
TypeScript conventions - Import statement properly formatted

Linked Issue Fit

Issue #268 specifically called for:

  • "Recommended: Import safeEqual from @/lib/dispatch-env" - ✅ Addressed
  • The issue noted the duplicate in middleware AND auth.ts - both files now import from dispatch-env (see src/middleware.ts:4:import { safeEqual } from "@/lib/dispatch-env")
  • The fix follows the exact recommended approach from the issue

Evidence Provider Findings

No evidence providers configured for this repository.

Tool Harness Findings

No tool harness output available (planning warning noted, but no failures reported).

Unknowns / Needs Verification

None - the change is straightforward and the diff is complete.

Recommendation

Approve. This PR correctly implements the fix for issue #268 by removing the duplicate safeEqual function and importing from the canonical dispatch-env source. The change is minimal (+1/-13 lines), eliminates code duplication, and improves maintainability by ensuring all timing-safe string comparisons use the same implementation.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic)

PR Review: Deduplicate safeEqual in auth.ts

Recommendation: Approve

This PR cleanly addresses Issue #268 by deduplicating the safeEqual function in src/lib/auth.ts through import from @/lib/dispatch-env, which uses crypto.timingSafeEqual.


Change-by-Change Findings

1. src/lib/auth.ts

  • Removed: Local safeEqual function (13 lines) which had a length-check early return that could leak timing information
  • Removed: Direct timingSafeEqual import from node:crypto
  • Added: safeEqual to the existing import from ./dispatch-env
  • Assessment: The deduplication is correct. The imported safeEqual from dispatch-env uses crypto.timingSafeEqual as specified in the issue recommendation.

2. src/app/api/sync/route.test.ts

  • Added: safeEqual: vi.fn((a: string, b: string) => a === b) to the mock for @/lib/dispatch-env
  • Assessment: Appropriate test update to mock the newly imported function. The simple equality mock is acceptable for test isolation.

Standards Compliance

  • TypeScript/Code Standards: Deduplication reduces code duplication and centralizes security-sensitive comparison logic. ✅
  • Error Handling: The imported safeEqual function already exists with proper error handling. ✅
  • No agent-specific names: N/A - refactoring change. ✅
  • No secrets logged: No change to token handling. ✅

Linked Issue Fit

Issue #268 specifically recommended:

Recommended: Import safeEqual from @/lib/dispatch-env in middleware, or deduplicate to a shared src/lib/crypto.ts.

Assessment: The PR follows the import-from-dispatch-env recommendation (though for auth.ts rather than middleware.ts as cited in the issue). The existing middleware.ts already imports safeEqual from dispatch-env per git history (commit d5caa96). The auth.ts deduplication completes the task for that file. ✅


Evidence Provider Findings

No evidence providers configured for this PR.


Tool Harness Findings

  • Planning warning: Could not parse planning response as JSON - No impact on this PR review as the changes are straightforward refactoring.

Unknowns / Needs Verification

None. The diff is clean and self-contained. Git history confirms this is a follow-up to merged PR #256 which fixed the middleware duplication.


Summary

This is a well-scoped, low-risk refactor that:

  1. Reduces code duplication (-13 lines local code)
  2. Ensures consistent timing-safe comparison via centralized safeEqual
  3. Updates the test mock to reflect the import change
  4. Does not change behavior - only reuses existing, verified implementation

@joryirving
joryirving merged commit fbc76e6 into mainMay 29, 2026
3 checks passed
@joryirving
joryirving deleted the fix/268-deduplicate-safeEqual branch May 29, 2026 18:53
joryirving added a commit that referenced this pull request Sep 2, 2026
…he body has none (#923)
extractLinkedIssue read only the PR title and body. A PR whose body carries no
reference is never linked, so it has no linked-issue health, is never enqueued
for a fix, and a CHANGES_REQUESTED review on it is never acted on — the PR sits
blocked indefinitely with nothing watching it.
That is not hypothetical: misospace/pr-reviewer-action#535 and
misospace/llmkube-images#284 both opened with an empty body while the commit
that did the work said 'Fixes#534' and 'Fixes#277'. The link existed; we were
not looking where it survived.
Fall back to the PR's commit messages, fetched only when title and body yield
nothing. Commits are matched more strictly than the body — a closing keyword is
required, since a bare '#123' in a commit is as likely to reference a prior PR
as to declare what this one fixes, and a wrong link is worse than none.
Claude-Session: https://claude.ai/code/session_01YSuDvZq9ncvyX85Uzx3cQh
Co-authored-by: Jory Irving <jory.irving@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deduplicate safeEqual in middleware

2 participants

@itsmiso-ai@joryirving