fix: scope playlist and subscription group changes to their owners - #8
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughPlaylist and subscription group database operations now enforce account ownership and use cascading membership deletes. The subscription handler maps missing owned groups to ChangesOwnership-scoped database operations
Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: ⚪ Minimal · up to Playlist and subscription-group mutations now prevent cross-account changes while preserving expected rename, delete, and not-found behavior. No merge-blocking risk is evident. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The audit found that playlist deletion and subscription-group mutations could affect another account's records. Scope those database mutations to the authenticated owner, update only group titles, and use the existing foreign-key cascades to remove memberships.
Existing clients keep the same endpoints, request bodies, and successful responses. The change needs no migration or protocol bump. Updating a missing or unowned group returns the existing 404 error used by group reads.
Validation: regression tests cover two accounts sharing a playlist ID, unauthorized group updates and deletions, and legitimate rename/delete behavior. All 52 offline SQLite tests pass; PostgreSQL compilation and formatting checks pass. Four existing tests that fetch live YouTube feeds were excluded.
Detailed report issues will follow after merge and deployment, as requested.