Skip to content

test(destination): lock exact proxy, redirect, and freshness bounds - #335

Open
seonghobae wants to merge 2 commits into
mainfrom
test/destination-policy-bounds
Open

seonghobae wants to merge 2 commits into
mainfrom
test/destination-policy-bounds

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Destination tests now accept the exact maximum proxy and PAC authority sets and still reject a set that exceeds those ceilings.
  • The redirect guard walks every hop at the maximum hop budget and continues to reject a downgrade, a cycle, and an extra hop.
  • Freshness checks stay fail-closed at the published validity bounds.

Test plan

  • cargo test -p originweave-destination --offline (40 passed)
  • cargo fmt -p originweave-destination -- --check

Summary by CodeRabbit

  • 테스트
    • 프록시 서버 32개와 PAC 출처 16개의 허용 한도 및 초과·미등록 항목 거부를 검증했습니다.
    • 리디렉션 최대 홉 수, 해석 정보의 유효 기간 경계, 만료 시각 계산 및 관련 오류 메시지를 확인하는 회귀 테스트를 보강했습니다.
    • 기본 포트가 명시된 HTTPS IPv6 프록시 주소의 파싱 결과도 검증했습니다.
  • 문서
    • 프록시 및 PAC 경로 정책의 허용 한도와 회귀 테스트 기준을 테스트 전략에 추가했습니다.

Destination policy now has executable evidence for the maximum proxy and
PAC authority sets, a full walk of the maximum redirect hop budget, and
freshness limits that stay fail-closed at the published ceilings.
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 9a30dc77-c45f-4bbb-a5df-17f3b30899dc

📥 Commits

Reviewing files that changed from the base of the PR and between 87c4daa and 9d0cd1f.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • crates/originweave-destination/tests/error_contract.rs
  • crates/originweave-destination/tests/proxy_authority_literal_bounds.rs
  • crates/originweave-destination/tests/proxy_route_policy.rs
  • crates/originweave-destination/tests/proxy_server_identity.rs
  • crates/originweave-destination/tests/redirect_policy.rs
  • crates/originweave-destination/tests/resolution_freshness.rs
  • docs/TEST_STRATEGY.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

프록시/PAC 권한 한도, 프록시 주소 정규화, 리다이렉트 및 해석 유효 기간 경계값에 대한 회귀 테스트를 추가했습니다. 오류 표시 테스트도 보강했습니다. 프로덕션 경로 정책과 네트워크 권한은 변경하지 않았습니다.

Changes

정책 경계값 테스트

Layer / File(s) Summary
프록시/PAC 경로 계약 및 권한 한도
crates/originweave-destination/tests/proxy_authority_literal_bounds.rs, crates/originweave-destination/tests/proxy_route_policy.rs, crates/originweave-destination/tests/proxy_server_identity.rs, docs/TEST_STRATEGY.md, CHANGELOG.md
프록시 32개와 PAC origin 16개의 승인을 확인합니다. 목록에 없는 항목과 한도를 초과한 입력의 거부, 경로 메타데이터, HTTPS IPv6 주소의 기본 포트 정규화도 검사합니다. 테스트 전략과 변경 로그에 경계값 검증을 기록합니다.
목적지 시간 경계값 및 오류 표시
crates/originweave-destination/tests/redirect_policy.rs, crates/originweave-destination/tests/resolution_freshness.rs, crates/originweave-destination/tests/error_contract.rs
최대 리다이렉트 홉과 최대 해석 유효 기간을 검증합니다. 0 또는 오버플로하는 유효 기간, 승인 시각 전 사용, 유효 종료 시각과 같은 시각의 사용에 대한 오류 문자열도 확인합니다.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 9d0cd

The added tests cover the stated policy boundaries without changing production behavior. No issue identified here prevents merging.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR 제목은 proxy, redirect, freshness의 정확한 상한을 검증하는 테스트 추가라는 주요 변경을 명확하고 간결하게 설명합니다.
Docstring Coverage ✅ Passed Docstring coverage is 84.62% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 6 files. (2 skipped: 2 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant