Skip to content

Retry automatic SSL after registration confirmation - #157

Merged
matveynator merged 2 commits into
mainfrom
fix/registration-stealth-missing-site-db
Sep 27, 2026
Merged

matveynator merged 2 commits into
mainfrom
fix/registration-stealth-missing-site-db

Conversation

@matveynator

Copy link
Copy Markdown
Owner

Summary

  • Start automatic SSL observation when a registration email confirmation page is opened.
  • Treat a missing stealth-policy row as disabled instead of propagating sql.ErrNoRows.
  • Extend the registration regression test to verify SSL observation starts before account setup creates the site database.

Validation

  • GOCACHE=/private/tmp/sitebrush-registration-gocache GOPROXY=off go test . -run '^(TestRegisterCreatesSiteDatabaseOnlyAfterConfirmedVerifiedDomain|TestRegisterRejectsUnverifiedDomainBeforeCreatingSiteDatabase|TestAutomaticSSL)' -count=1

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1c728ba26e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sitebrush.go Outdated
Comment on lines +9896 to +9897
if errors.Is(err, sql.ErrNoRows) {
return false, nil

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep stealth fail-closed on database lookup failures

With perSiteDBRouter, sql.ErrNoRows does not only mean that no stealth policy exists: QueryRowContext returns a dummy SELECT 1 WHERE 0 row after routing or database-worker errors, including errSiteDatabaseMissing, so those failures surface here as sql.ErrNoRows. Treating that as disabled lets requests to a stealth-protected domain fall through instead of returning the intended 503; if an established site's database file disappears, the login flow can consequently redirect to registration and allow a new database/admin to be bootstrapped. Limit this exception to a verified pending-registration domain or preserve the underlying router error so other failures remain fail-closed.

Useful? React with 👍 / 👎.

@matveynator
matveynator merged commit 9d4a3ab into main Sep 27, 2026
7 checks passed
@matveynator
matveynator deleted the fix/registration-stealth-missing-site-db branch September 27, 2026 08:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants