Skip to content

fix(reliability): reject accessor-backed document snapshot JSON without invoking getters #219

Description

@seonghobae

Current authoritative state

This accessor-safety defect is repaired on canonical Draft PR #218 / fix/document-snapshot-cycle-217. Protected shipped truth remains main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is eafd5462db71654e7fa85fd3aa8804d7c51c55f6, 23 ahead / 0 behind from that exact merge base with only four intended snapshot files changed.

Current snapshot validation uses own keys/descriptors and never evaluates accessors; hostile reflection/proxy failures become stable payload-redacted RangeError boundaries. Representative accessor RED is 5e054c157a0b5c7c592185e62689d5bdec0da29d. Exact-head CI 32101276070, Security 32101276077, and SAST 32101276001 are completed / success; formal submitted reviews are 0.

The repair is active-PR truth only. Keep #218 Draft/unmerged while #118 owns v0.6.0 operational acceptance and independent latest-push approval plus every applicable central gate remain incomplete. Do not create a competing snapshot writer, transfer predecessor evidence, self-approve, weaken gates, move protected main, or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: operationsOperability, observability, readiness, SLO, backup, or retentionarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions