refactor: simplify account standing and verification levels (#3130)

This commit is contained in:
Hampus
2026-10-02 18:17:41 +02:00
committed by GitHub
parent 1abde06824
commit 1ec8f31253
488 changed files with 10390 additions and 47117 deletions
+4 -12
View File
@@ -122,14 +122,6 @@ const OUT_OF_BAND_CREDENTIAL = new Map<string, OutOfBandRoute>([
documentedIn: null,
},
],
[
'POST /webhooks/twilio/sms',
{
reason:
'a provider callback that is forwarded untouched to the internal event bus and answers 500 while that bus is unavailable',
documentedIn: null,
},
],
[
'POST /webhooks/livekit',
{
@@ -224,7 +216,7 @@ const EXEMPTION_RULES: ReadonlyArray<ExemptionRule> = [
name: 'out-of-band credential',
justification:
'no ordinary client holds the credential. Each entry states its guard, and five are covered in prose',
anchors: [{file: 'fluxer_api/src/api/app/ControllerRegistry.ts', anchor: 'installSmsWebhookForwarder(routes'}],
anchors: [{file: 'fluxer_api/src/api/app/ControllerRegistry.ts', anchor: 'InternalRpcController(routes);'}],
covers: (shape) => OUT_OF_BAND_CREDENTIAL.has(shape),
},
];
@@ -1973,7 +1965,7 @@ console.log('bot capability flag (from the middleware chain)');
if (documented == null) {
continue;
}
const anyLogin = route.hasLoginRequired || route.hasLoginRequiredAllowSuspicious;
const anyLogin = route.hasLoginRequired;
const sourceAcceptsBot = anyLogin && !route.hasDefaultUserOnly;
const exemption = BOT_EXEMPT.get(key);
if (exemption != null) {
@@ -2033,7 +2025,7 @@ console.log('unauthenticated capability flag (from the middleware chain)');
if (documented == null) {
continue;
}
const anyLogin = route.hasLoginRequired || route.hasLoginRequiredAllowSuspicious;
const anyLogin = route.hasLoginRequired;
const sourceIsOpen = !anyLogin && !route.middlewares.some((name) => /OAuth2Scope/u.test(name));
const exemption = UNAUTHENTICATED_EXEMPT.get(key);
if (exemption != null) {
@@ -2089,7 +2081,7 @@ console.log('spec security field against the middleware chain');
}
const declaredSchemes = declaredSecurity.schemes;
compared += 1;
const anyLogin = route.hasLoginRequired || route.hasLoginRequiredAllowSuspicious;
const anyLogin = route.hasLoginRequired;
const acceptsBot = anyLogin && !route.hasDefaultUserOnly;
const requiresAuthentication =
anyLogin ||