Skip to content

feat: org-verify-write and org-verify-remove actions for fleet verification - #165

Merged
mortik merged 3 commits into
mainfrom
feat/org-verification
Oct 7, 2026
Merged

mortik merged 3 commits into
mainfrom
feat/org-verification

Conversation

@mortik

@mortik mortik commented Oct 7, 2026

Copy link
Copy Markdown
Member

Lets fleetyards.net verify a fleet's RSI organisation for its manager. Part of fleetyards/fleetyards#5465; the same idea as the handle verification in #155, for the org page.

What changed

  • org-verify-write ({sid, token}) appends a FLEETYARDS-… token to the org's history, after a blank line, and publishes the draft. If the token is already there, it answers changed: false and writes nothing.
  • org-verify-remove removes exactly that appended \n\n<token> and publishes again.
  • Both are listed in the health check's actions.

Safeguards

  • Exact text only. The history is read raw from the <textarea name="history"> on /orgs/<SID>/admin/content, so the org's Textile formatting goes back exactly as it was. Nothing is ever built from the formatted public page.
  • No rights, no write. Without content rights RSI still answers 200, with a page titled "Access denied"; that answers 403.
  • Nothing else pending. publishDraft publishes the org's whole draft, so the action first compares the draft preview (/admin/preview) with the public page, both reduced to plain text with every FLEETYARDS- token removed. Any difference means another officer has unpublished edits, and it answers 409 without writing. Pages it can't read answer 422.
  • Strict inputs. Only a token matching ^FLEETYARDS-[A-Z0-9]{10}$ and an SID matching ^[A-Z0-9]{1,10}$ are accepted.
  • Failed saves stop there. A refused save (200 with success: 0) answers 502, and nothing is published after it.

Requests (captured from an officer session): POST /api/orgs/saveDraft {symbol, history}, POST /api/orgs/publishDraft {symbol}, both with X-Rsi-Token and X-Requested-With.

Test plan

  • pnpm test (71): draft reading, access denied, block comparison, and each answer of both actions
  • pnpm compile, pnpm build
  • End to end from the fleet verification modal with an officer session. The preview page's markup is assumed to match the public page; if it doesn't, the action refuses with 422 rather than writing.

🤖

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 4 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7b0cd7d6-454d-44c1-81df-b567f9302c6f
📥 Commits

Reviewing files that changed from the base of the PR and between 2feaf1a and 71de011.

📒 Files selected for processing (6)
  • __tests__/message-handler.test.ts
  • __tests__/org.test.ts
  • lib/bio.ts
  • lib/message-handler.ts
  • lib/org.ts
  • lib/rsi.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mortik
mortik force-pushed the feat/org-verification branch from ea53912 to 71de011 Compare October 7, 2026 15:31
@mortik
mortik added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit 42e4302 Oct 7, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant