Skip to content

feat(realtime): add delivery identity - #87

Merged
swkeever merged 3 commits into
mainfrom
skeever/realtime-delivery-identity
Sep 3, 2026
Merged

swkeever merged 3 commits into
mainfrom
skeever/realtime-delivery-identity

Conversation

@swkeever

@swkeever swkeever commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • capture auth session lineage and subscription epoch for Postgres deliveries
  • keep delivery identity stable across token refreshes
  • invalidate captured deliveries after reauthentication or resubscription

This slice adds internal identity tracking only. Worker integration and the public fetch option remain separate follow-up slices.

Verification

  • uv run python scripts/check_openapi.py
  • uv run ruff check .
  • uv run ruff format --check .
  • uv run mypy
  • uv run pyright
  • uv run pytest tests/unit -q (393 passed)
  • uv run behave features/contract --dry-run --no-snippets
  • uv run python -m build
  • npm test --prefix tests/sdk-contract
  • bash scripts/ci/run-sdk-contract-tests_test.sh

@swkeever

swkeever commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-03T16:44:47.313479Z fd78443 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ed4bac0c90

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/volcano_sdk/realtime.py Outdated
Comment on lines +592 to +595
def _capture_postgres_delivery_identity(self) -> _PostgresDeliveryIdentity:
_generation, lineage, _session = (
self._realtime._client_context._capture_session_binding()
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind the session lineage to the subscription epoch

When sign_in(), sign_out(), or set_session() changes authentication while a Postgres subscription remains live, this captures the new client lineage even though the existing socket and subscription are still authorized with the previous session; auth transitions do not reconnect or resubscribe them. Consequently, a publication received from the old session after the transition gets an identity that immediately passes _postgres_delivery_is_current(), allowing an old user's RLS-scoped event to be fetched or delivered in the new user's context. Capture the lineage when the subscription epoch begins and reject publications until that subscription has been rebound after an auth-lineage change.

Useful? React with 👍 / 👎.

@swkeever

swkeever commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: efe5f26342

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/volcano_sdk/realtime.py Outdated
Comment on lines +602 to +605
_generation, lineage, _session = (
self._realtime._client_context._capture_session_binding()
)
self._postgres_session_lineage = lineage

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind new epochs to the connection-auth lineage

If a realtime connection is established as user A, the client signs in as user B, and then subscribes to a Postgres channel, _connect_locked() reuses the socket authenticated with A while this callback records B's current lineage. The resulting delivery identity therefore passes _postgres_delivery_is_current() even though publications remain A-scoped, allowing a later row fetch or callback to cross authentication boundaries. Fresh evidence in this revision is that binding at on_subscribed still does not identify the session used to authenticate the reused connection; retain that connection's lineage and reject or reconnect when it differs.

Useful? React with 👍 / 👎.

@swkeever

swkeever commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: fd784437e4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@swkeever
swkeever marked this pull request as ready for review September 3, 2026 16:45
@swkeever
swkeever merged commit aa55d98 into main Sep 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant