Skip to content

chore: update XContest token - #487

Merged
vicb merged 2 commits into
masterfrom
vicb/xctoken
Oct 5, 2026
Merged

vicb merged 2 commits into
masterfrom
vicb/xctoken

Conversation

@vicb

@vicb vicb commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Summary by Sourcery

Update the XContest token and align dependency checks with the project’s Vite and PWA tooling.

Enhancements:

  • Update ESLint dependency-check configuration to account for Vite and PWA configuration files and dependencies.

Chores:

  • Rotate the XContest token in the secrets configuration.

Summary by CodeRabbit

  • Chores
    • Updated internal project checks to account for Vite and PWA configuration and related dependencies.
    • Refreshed encrypted authentication settings.
    • These maintenance changes do not add or remove end-user features or change the app’s visible functionality.

@sourcery-ai

sourcery-ai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

The PR rotates the XContest token and adjusts Nx ESLint dependency-check exclusions so Vite, PWA, and Workbox build-time dependencies used by configuration files do not trigger dependency validation errors.

File-Level Changes

Change Details Files
Updated Nx dependency-check configuration to ignore Vite/PWA configuration files and their build-time dependencies.
  • Excluded project and root-level Vite and PWA config files from dependency checks.
  • Added Vite PWA and Workbox build packages to the ignored dependency list.
  • Applied equivalent Vite config exclusions to the common library lint configuration.
apps/fxc-front/eslint.config.js
libs/common/eslint.config.js
Rotated the XContest token stored in the environment secrets file.
  • Replaced the existing token value with an updated secret.
secrets.env

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. The new XContest JWT changes the credential used for authentication; if it is invalid, expired, or issued for the wrong account, requests can fail or be made with unintended access. Reverting restores the previous value unless the credential rotation has already invalidated it, so the impact is generally bounded but may not be fully reversible.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a6936758-b41d-4476-a4b7-6b74409bc6a4
📥 Commits

Reviewing files that changed from the base of the PR and between 3396e03 and 8be458e.

📒 Files selected for processing (3)
  • apps/fxc-front/eslint.config.js
  • libs/common/eslint.config.js
  • secrets.env

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


Walkthrough

The frontend and common-library ESLint configurations now exclude specified Vite and PWA files from dependency checks. The frontend configuration also ignores two dependencies. The encrypted value assigned to XCONTEST_JWT changed.

Changes

Dependency-check configuration

Layer / File(s) Summary
Configure dependency-check exclusions
apps/fxc-front/eslint.config.js, libs/common/eslint.config.js
The configurations now exclude Vite and PWA configuration files. The frontend configuration also ignores vite-plugin-pwa and workbox-build.

Encrypted JWT value

Layer / File(s) Summary
Update encrypted JWT value
secrets.env
The encrypted value assigned to XCONTEST_JWT changed. The variable name and encrypted-value format remain the same.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 8be45

No actionable issue is established for this change. Confirm the replacement XContest credential in the deployment environment as part of normal release checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8be45

The PR preserves the existing credential-loading and XContest request paths. No introduced security weakness was demonstrated, but the replacement token’s identity, permissions, deployment activation, and rollback validity remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated credential-use surface is the fetcher’s two existing XContest request sites and its credential-bearing build artifact. The replacement token’s maximum provider-side asset and authorization scope cannot be bounded from the encrypted assignment.

Trust Boundaries and Controls

  • observed — The credential crosses from encrypted repository configuration through build-time parsing into outbound service authentication. The inspected request URLs retain a fixed HTTPS XContest origin; account selection and provider-returned flight identifiers do not select a new origin in these call sites. Decryption-key ownership and the replacement token’s effective identity remain unresolved.

Resilience and Maintainability Implications

  • observed — Existing non-success responses are recorded as global or per-device errors, and track updates are produced only after successful response parsing. The replacement introduces no unauthenticated fallback or alternate credential retry path in the inspected consumer. These controls do not establish issuer-side rotation or rollback safety.

Hardening Proposals

  • proposed — Validate rotation using non-secret metadata: expected provider identity and permissions, authorized build-key ownership, successful artifact decryption, activation and retirement timing, and a rollback credential that remains valid. This addresses unresolved evidence rather than an observed vulnerability.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the updated XContest token in secrets.env, which is a real part of the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the config with care,
Vite files and PWA files are spared.
Two dependencies leave the check,
A changed JWT value joins the spec.
Then hops away through fields of green.

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
flyxc-workers 8be458e Commit Preview URL

Branch Preview URL
Oct 05 2026, 04:01 PM

@vicb
vicb merged commit afdd65f into master Oct 5, 2026
7 checks passed
@vicb
vicb deleted the vicb/xctoken branch October 5, 2026 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant