Retry automatic SSL after registration confirmation - #157
Conversation
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1c728ba26e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if errors.Is(err, sql.ErrNoRows) { | ||
| return false, nil |
There was a problem hiding this comment.
Keep stealth fail-closed on database lookup failures
With perSiteDBRouter, sql.ErrNoRows does not only mean that no stealth policy exists: QueryRowContext returns a dummy SELECT 1 WHERE 0 row after routing or database-worker errors, including errSiteDatabaseMissing, so those failures surface here as sql.ErrNoRows. Treating that as disabled lets requests to a stealth-protected domain fall through instead of returning the intended 503; if an established site's database file disappears, the login flow can consequently redirect to registration and allow a new database/admin to be bootstrapped. Limit this exception to a verified pending-registration domain or preserve the underlying router error so other failures remain fail-closed.
Useful? React with 👍 / 👎.
Summary
Validation