mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 09:16:15 +00:00
* 🐛 Attribute audit events to the caller, not the response prepare-rpc-event took the event profile-id from the result map whenever it carried one, before falling back to the caller. Any command returning a response with a :profile-id key silently credited the action to somebody else. get-error-report returns the report with its decoded content merged in, and that content holds the profile that owned the report, so privileged reads were logged against the users whose crashes were being inspected. verify-token on a team invitation returns the inviter's profile-id, so accepting an invitation was logged against the inviter. Resolution is now ::audit/profile-id metadata, then ::rpc/profile-id, then the zero uuid; the response is never consulted. The two verify-token branches that relied on it now declare the profile in the result metadata. Every other command either already declared it or returns no :profile-id; all 30 registered command namespaces were checked. The tests that pinned the old behavior are replaced by ones covering the new contract. AI-assisted-by: space-bunny-free * 🐛 Coerce the audit profile-id override to a uuid The only sanctioned way for a command to override the profile of an audit event is the ::audit/profile-id metadata, and the value is set by hand in a dozen commands, some of them reading it from token claims or other sources we do not type. schema:event requires a uuid and submit* swallows the validation error, so a string did not fail loudly: the row was dropped silently. Values that cannot become a uuid are now discarded with a warning and the event falls back to the caller, which is always a valid uuid. A uuid, the common case, exits on the first check. AI-assisted-by: space-bunny-free