Repository navigation
feat(realtime): add delivery identity - #87
Conversation
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ed4bac0c90
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| def _capture_postgres_delivery_identity(self) -> _PostgresDeliveryIdentity: | ||
| _generation, lineage, _session = ( | ||
| self._realtime._client_context._capture_session_binding() | ||
| ) |
There was a problem hiding this comment.
Bind the session lineage to the subscription epoch
When sign_in(), sign_out(), or set_session() changes authentication while a Postgres subscription remains live, this captures the new client lineage even though the existing socket and subscription are still authorized with the previous session; auth transitions do not reconnect or resubscribe them. Consequently, a publication received from the old session after the transition gets an identity that immediately passes _postgres_delivery_is_current(), allowing an old user's RLS-scoped event to be fetched or delivered in the new user's context. Capture the lineage when the subscription epoch begins and reject publications until that subscription has been rebound after an auth-lineage change.
Useful? React with 👍 / 👎.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: efe5f26342
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| _generation, lineage, _session = ( | ||
| self._realtime._client_context._capture_session_binding() | ||
| ) | ||
| self._postgres_session_lineage = lineage |
There was a problem hiding this comment.
Bind new epochs to the connection-auth lineage
If a realtime connection is established as user A, the client signs in as user B, and then subscribes to a Postgres channel, _connect_locked() reuses the socket authenticated with A while this callback records B's current lineage. The resulting delivery identity therefore passes _postgres_delivery_is_current() even though publications remain A-scoped, allowing a later row fetch or callback to cross authentication boundaries. Fresh evidence in this revision is that binding at on_subscribed still does not identify the session used to authenticate the reused connection; retain that connection's lineage and reject or reconnect when it differs.
Useful? React with 👍 / 👎.
|
@codex review |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
This slice adds internal identity tracking only. Worker integration and the public fetch option remain separate follow-up slices.
Verification
uv run python scripts/check_openapi.pyuv run ruff check .uv run ruff format --check .uv run mypyuv run pyrightuv run pytest tests/unit -q(393 passed)uv run behave features/contract --dry-run --no-snippetsuv run python -m buildnpm test --prefix tests/sdk-contractbash scripts/ci/run-sdk-contract-tests_test.sh