Repository navigation
fix(integrations): enforce current task ownership - #1867
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
PR Summary by QodoEnforce current task ownership across integration sync
AI Description
Diagram
High-Level Assessment
Files changed (31)
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 85e07cf4bf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Code Review by Qodo
1.
|
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8787420435
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 394cd414ec
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ca29c96133
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71e2a3e0aa
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f2e252753b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 802c5bd338
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (!task) | ||
| throw new Error("Task no longer belongs to the integration project"); |
There was a problem hiding this comment.
Compensate provider issue creation when ownership changes
When a newly created task is moved while the asynchronous task.created integration handler is awaiting GitHub, Gitea, or GitLab, those handlers create the provider issue before calling createExternalLink; this new ownership failure then leaves the remote issue orphaned and the moved task permanently unlinked. For Gitea and GitLab, the resulting issue-opened webhook can also import that orphan as a second task in the source project. Use a durable ownership reservation or compensate by closing/deleting the provider issue when the final link cannot be committed.
AGENTS.md reference: AGENTS.md:L32-L32
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
This is the same remote-creation compensation race already reviewed in PRRT_kwDONkPybM6nQtaK and deferred as a separate delivery/recovery change. The final ownership guard must reject the moved task to protect workspace isolation. Provider cleanup would need durable recovery and webhook handling across GitHub, Gitea and GitLab; ordinary association or label failures already have the same orphan outcome. Keeping this isolation PR scoped and reporting compensation as a follow-up.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ca6e4f7e15
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cf2b030ca5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b62c486f6f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const priority = extractIssuePriority(adaptedLabels); | ||
| const status = extractIssueStatus(adaptedLabels); | ||
|
|
||
| const comments = await fetchIssueComments(issue.number, config, client); |
There was a problem hiding this comment.
Recheck issue links after fetching comments
When an issue is initially unlinked and its opened webhook creates a task while this potentially paginated provider request is pending, existingLink remains null and the importer proceeds down the creation branch without rechecking. Because external_link has no uniqueness constraint for an integration/resource/external ID, both paths can commit separate tasks and links for the same provider issue. Serialize creation with the webhook or recheck under a shared lock after the fetch; the GitLab notes path at import-gitlab-issues.ts:196 has the same race.
AGENTS.md reference: AGENTS.md:L5-L5
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Verified this creation race, including in the pre-PR main implementation: it checks for an issue link before creation but does not recheck under a creation lock or enforce an external-resource uniqueness constraint. Moving comment/notes requests outside ownership transactions widens an existing window; the current ownership guards still prevent writes crossing project/workspace boundaries. Coordinating importer and opened-webhook creation is separate provider-creation idempotency work, alongside the previously reported remote-orphan compensation followup. I am reporting it without expanding this ownership PR into that lifecycle redesign.
|
@codex review |
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
### Features - **web:** redesign settings: usekaneo#1905 - **site:** link community projects from resources: [69ba99d](69ba99d) - **site:** add a community projects page: [961c309](961c309) - **site:** sync product preview with home, inbox and my tasks: [30ba825](30ba825) - missing french translation: usekaneo#1903 - add short task links like /acme/task/KAN-12: usekaneo#1891 - **web:** add home, inbox and my tasks pages: usekaneo#1898 - **web:** wire the task copy shortcuts: usekaneo#1897 - **web:** move task delete into the action group: usekaneo#1896 - **site:** add guides and retarget alternatives: [58f6d47](58f6d47) - **web:** track the cloud signup funnel: [abacad7](abacad7) - **docker:** support file-backed secrets for container deployments: usekaneo#1853 - sort labels alphabetically: usekaneo#1856 - **web:** select task ranges with shift-click: usekaneo#1838 - clickable task PR list, task link matching, and reopen completed tasks for new work: usekaneo#1864 - **mcp:** get tasks by ticket ID: usekaneo#1839 - **web:** guide cloud users through invites and plan choice during onboarding: usekaneo#1840 - rank new issue priority with Jev: [594e016](594e016) - **web:** cloud sign-up and onboarding layout: usekaneo#1832 - gitlab integration: usekaneo#1727 - **tasks:** show subtask progress on cards and list rows: usekaneo#1703 - added project backgrounds: usekaneo#1654 - multiselect for customfield: usekaneo#1735 - **ci:** discord actions webhook: usekaneo#1792 - **ci:** adding zizmor: usekaneo#1790 - **project:** move a project to another workspace: usekaneo#1525 - duplicate a task from the card context menu: usekaneo#1609 - allow manual external resource links: usekaneo#1661 - **ci:** trufflehog implementation: usekaneo#1787 - **task:** let images be resized in the task description: usekaneo#1529 - **web:** add a change-password screen under account settings: usekaneo#1719 - **auth:** add password recovery from the login screen: usekaneo#1773 - add instance user administration panel: usekaneo#1400 - **site:** bring product preview up to date with current app: [dd855f7](dd855f7) - **site:** refresh marketing site and interactive product previews: [90aec99](90aec99) - **calendar:** add label-filtered project calendar feeds: usekaneo#1763 ### Bug Fixes - **web:** send subscription revenue as a property: [445b735](445b735) - **site:** list GitLab with the git integrations: [3c01517](3c01517) - **site:** serve favicon.ico: [e7ef050](e7ef050) - **docs:** load the docs font from its real path: [22c7a02](22c7a02) - **tasks:** make bulk status changes atomic: usekaneo#1873 - **integrations:** preserve rapid legitimate edits: usekaneo#1874 - **integrations:** enforce current task ownership: usekaneo#1867 - **ws:** revoke removed workspace members: usekaneo#1865 - **migrations:** record workflow migration completion: usekaneo#1872 - **auth:** enforce api key quotas and rate limits: usekaneo#1869 - **mcp:** share tools and support workspace label deletion: usekaneo#1871 - **reminders:** persist notification and claim atomically: usekaneo#1870 - **integrations:** require task update permission for imports: usekaneo#1868 - **ci:** publish npm provenance on GitHub-hosted runners: [50779a4](50779a4) - **gitea:** reject saved tokens for changed servers: usekaneo#1866 - **ci:** pass the GitHub token to AgentScan: usekaneo#1862 - **ci:** resolve nightly warnings and errors: usekaneo#1858 - **api:** make legacy MCP HTTP requests replica independent: usekaneo#1850 - **docker:** disable wget proxy for loopback health checks: usekaneo#1841 - **billing:** resize Creem seats by subscription item id: usekaneo#1836 - **gitea:** prevent outbound comment echoes: usekaneo#1834 - **deps:** migrate Sentry SDKs together to v11 (usekaneo#1826): usekaneo#1826 - **ci:** grant nightly reusable CI scan permission: [0216067](0216067) - **board:** allow column moves while sorting by task number: usekaneo#1816 - **auth:** backfill instance admin on legacy installations: [b7c6aee](b7c6aee) - **admin:** harden the user administration panel: usekaneo#1805 - **admin:** allow updating your own email without changing role: [3d57439](3d57439) - **security:** close permission and integration gaps: usekaneo#1802 - **project:** secure integrations across workspace moves: usekaneo#1801 - **editor:** preserve formatting when pasting Markdown: usekaneo#1797 - **auth:** report invitation email delivery failures: usekaneo#1798 - **gitea:** verify saved repository connections: usekaneo#1796 - **mcp:** keep OAuth requests valid outside UTC: usekaneo#1795 - **i18n:** translate calendar in remaining locales: [1d61ceb](1d61ceb) - **ci:** zizmor findings: usekaneo#1791 - **integrations:** resolve PRs through linked issue identities: usekaneo#1739 - **auth:** prevent repeated 401s for pending invitations after session expiry: usekaneo#1715 - **auth:** gate sign-in emails to deliverable addresses: usekaneo#1758 - **web:** preserve image uploads across editor recreation: usekaneo#1738 - **reminders:** calculate deadlines from the end of the due day: usekaneo#1762 - **mcp:** support whoami with API keys: usekaneo#1748 - **web:** respect DISABLE_WORKSPACE_CREATION on the onboarding screen: usekaneo#1744 - **backlog:** prevent task remounts during list interactions: usekaneo#1734 - **auth:** prevent role changes from removing the last admin: usekaneo#1733 - **npm:** fixing GHSA-2xp9-vwfh-vxw4: usekaneo#1777 - **web:** guard tiptap setHardBreak against invalid-content schema error: [be3ffb5](be3ffb5) - **i18n:** prevent locale module crash on stale dynamic import: usekaneo#1775 - **site:** improve search metadata and product discovery: [121183e](121183e) - **web:** allow non-root runtime configuration writes: usekaneo#1767 - **site:** poof away preview cursor on interaction: [08dcaee](08dcaee) - **nginx:** allow larger OAuth session headers: usekaneo#1761 - **deps:** resolve open dependabot advisories: [b8432a0](b8432a0) - **web:** preserve comment markdown spacing: usekaneo#1521 ### Performance Improvements - **project:** stop returning tasks with project details: usekaneo#1800 ### Documentation - update sponsors: [1c51887](1c51887) - add AI Policy badge to README: [011c8ee](011c8ee) - update sponsors: [e45c8ac](e45c8ac) - assign issue types from templates: [4725cfa](4725cfa) - simplify issue and pull request templates: [cb6ce20](cb6ce20) - adopt Human Voice AI contribution policy: [b090123](b090123) - overhaul agents.md: [4d619aa](4d619aa) - **readme:** highlight cloud and current features: usekaneo#1831 - update contributors and sponsors: [c200d70](c200d70) - rebuild guides around current Kaneo workflows: usekaneo#1814 - acknowledge BrowserStack testing: [e389a68](e389a68) - update contributors and sponsors: [fa07f10](fa07f10) - **site:** add Blacksmith partner badge to site and README: [08a93b8](08a93b8) - update contributors and sponsors: [8432a45](8432a45) - **site:** refresh press kit with product screenshots: [3470b0a](3470b0a) - update blog comparisons for current Kaneo features: [b97bf7d](b97bf7d) - update contributors and sponsors: [6c7001c](6c7001c) ### Credits Huge thanks to @tinsever, @MonsPropre, @andrejsshell, @tuttucodes, @druwan, @randoneering, @mazzz1y, @zaralX, @TymekV, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!
what changed?
stale integration links could update tasks after they moved out of the integration’s project or workspace. check ownership inside locked transactions for imports and webhooks, and remove incompatible links during moves.
finding 06 from the codebase review.
how did you check it?
provider unit tests and postgres ownership/move regressions, including stale links and concurrent scope changes.
checked the combined fix tree with the full workspace test run, uncached workspace typechecks, lint, i18n and openapi checks. postgres integration tests used disposable local test databases; provider and s3 calls were mocked.
Native GitHub stack #1885 (bottom to top): #1867 (this PR) → #1874. Stack base:
main. The independent board stack #1886 (#1873 → #1876 → #1877 → #1878 → #1879) also depends on this foundation.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.