chore(deps): bump time from 0.3.36 to 0.3.47 in the cargo group across 1 directory - #1
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump time from 0.3.36 to 0.3.47 in the cargo group across 1 directory#1dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the cargo group with 1 update in the / directory: [time](https://github.com/time-rs/time). Updates `time` from 0.3.36 to 0.3.47 - [Release notes](https://github.com/time-rs/time/releases) - [Changelog](https://github.com/time-rs/time/blob/main/CHANGELOG.md) - [Commits](time-rs/time@v0.3.36...v0.3.47) --- updated-dependencies: - dependency-name: time dependency-version: 0.3.47 dependency-type: direct:production dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Free Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
yacosta738
added a commit
that referenced
this pull request
Jun 2, 2026
Four pre-existing issues caught by inline review of the PR-A stack. Finding 5 (SESSION_NOT_FOUND redirect) was verified invalid and skipped — the dashboard redirect is driven by currentUser, not by rejection codes. ## Finding 1: stream paths bypassed forbidden/rate-limit HTTP mapping chat_completions_stream and anthropic_messages_stream were returning SSE 200 with a generic internal_error event when the upstream execute_stream_with_format returned a forbidden or rate_limited error. This means a model-restricted key streaming chat completions got 200 + a confusing SSE error event instead of a clean HTTP 403. Added Err-arms for is_forbidden() and is_rate_limited() in both stream handlers so streaming and non-streaming requests share identical auth/rate-limit behavior. New helpers map_forbidden_openai and map_rate_limited return typed HttpError for the IntoResponse path. ## Finding 2: restrictions_from_headers failed open on missing headers The function used unwrap_or_default() on header lookups, so a missing x-authz-allowed-models or x-authz-allowed-providers header was silently treated as 'unrestricted'. The authz middleware must always stamp these headers, so a missing header indicates either a routing bug or a middleware bypass — both should be loud, not silent. Restructured into a parse_csv_header helper that returns Result<Vec<String>, HttpError> and propagates AUTHZ_HEADER_MISSING or AUTHZ_HEADER_INVALID 500 responses. Empty header value (public subject) still maps to empty Vec, which the domain treats as unrestricted. ## Finding 3: scopes_from_json rejected pre-#83 legacy scope strings auth-sqlite used ApiKeyScope::parse (strict) in scopes_from_json, which rejects any unknown scope string. Existing API keys created before #83 with legacy values ('read', 'write') would fail to load. Switched to ApiKeyScope::parse_lenient, which is the documented method for reading from the database (accepts unknowns, logs warning). Added regression test read_key_with_legacy_scope_string_is_preserved. ## Finding 4: required_scope fallback allowed POST with read-only key required_scope returned Some("chat:read") for ANY /v1/* path that wasn't /v1/providers/* or /v1/chat/* — regardless of HTTP method. This meant a key with only the chat:read scope could hit POST /v1/messages (Anthropic) and pass the authz check, then rely on downstream luck. Updated the fallback to inspect the method: GET → chat:read, all others → chat:write. The special-cases for /v1/providers* and /v1/chat/* are preserved. Added regression test client_api_with_chat_read_scope_rejected_on_post_to_messages.
yacosta738
added a commit
that referenced
this pull request
Jun 2, 2026
…nt (#89) * feat(api-key): typed ApiKeyScope with canonical scope values (#83) Add KnownScope enum with five canonical values: chat:read, chat:write, providers:read, providers:write, admin. ApiKeyScope::parse now rejects unknown values with UnknownScope error. ApiKeyScope::parse_lenient is introduced for DB reads — accepts any non-empty value and emits a tracing::warn for unrecognised scopes. ManageApiKeys::create and update validate all scopes before touching the repository. Fixes pre-existing sha2 0.11 compilation breakage in login.rs, validate_session.rs, and auth.rs. * feat(authz): scope enforcement per route class in client API policy (#84) Add required_scope(method, path) mapping routes under /v1/* to their canonical scope requirement. Add check_scope helper that allows requests when the subject holds the required scope or the admin superset scope, and rejects with HTTP 403 INSUFFICIENT_SCOPE otherwise. Thread method and path through evaluate_policy and client_api_policy. Update env-fallback credentials to use canonical scope names. Update all affected tests to use canonical scope values. * fix: apply CodeRabbit auto-fixes Fixed 8 file(s) based on 3 unresolved review comments. Co-authored-by: CodeRabbit <noreply@coderabbit.ai> * feat(api-key): add allowed_models/allowed_providers and enforce in routing (#85, #86) (#90) * chore(deps-rust)(deps): bump axum-test from 15.7.4 to 20.1.0 (#78) Bumps [axum-test](https://github.com/JosephLenton/axum-test) from 15.7.4 to 20.1.0. - [Release notes](https://github.com/JosephLenton/axum-test/releases) - [Commits](https://github.com/JosephLenton/axum-test/commits) --- updated-dependencies: - dependency-name: axum-test dependency-version: 20.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(api-key): add allowed_models and allowed_providers restriction fields (#85) * feat(routing): enforce allowed_models and allowed_providers restrictions (#86) --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(deps): add hex crate version 0.4.3 to Cargo.lock * fix(dashboard): update API key scope options to canonical chat:read/chat:write The dashboard was still emitting pre-#83 scope values ('read', 'write') in the create/edit modals, which the backend now rejects with 400 'unknown API key scope'. This was surfaced by 'just ci-local' failing the Playwright e2e suite after #83/#84 landed. Without this fix, every dashboard user creating an API key via the UI would have hit the same 400 error. - ApiKeysView.vue: dropdown values updated to canonical scopes - api-keys.spec.ts: helper defaults + 2 call sites updated; UI selector tightened to '^chat read$' to avoid accidental matches * fix(authz): address code review findings (#1-#4) Four pre-existing issues caught by inline review of the PR-A stack. Finding 5 (SESSION_NOT_FOUND redirect) was verified invalid and skipped — the dashboard redirect is driven by currentUser, not by rejection codes. ## Finding 1: stream paths bypassed forbidden/rate-limit HTTP mapping chat_completions_stream and anthropic_messages_stream were returning SSE 200 with a generic internal_error event when the upstream execute_stream_with_format returned a forbidden or rate_limited error. This means a model-restricted key streaming chat completions got 200 + a confusing SSE error event instead of a clean HTTP 403. Added Err-arms for is_forbidden() and is_rate_limited() in both stream handlers so streaming and non-streaming requests share identical auth/rate-limit behavior. New helpers map_forbidden_openai and map_rate_limited return typed HttpError for the IntoResponse path. ## Finding 2: restrictions_from_headers failed open on missing headers The function used unwrap_or_default() on header lookups, so a missing x-authz-allowed-models or x-authz-allowed-providers header was silently treated as 'unrestricted'. The authz middleware must always stamp these headers, so a missing header indicates either a routing bug or a middleware bypass — both should be loud, not silent. Restructured into a parse_csv_header helper that returns Result<Vec<String>, HttpError> and propagates AUTHZ_HEADER_MISSING or AUTHZ_HEADER_INVALID 500 responses. Empty header value (public subject) still maps to empty Vec, which the domain treats as unrestricted. ## Finding 3: scopes_from_json rejected pre-#83 legacy scope strings auth-sqlite used ApiKeyScope::parse (strict) in scopes_from_json, which rejects any unknown scope string. Existing API keys created before #83 with legacy values ('read', 'write') would fail to load. Switched to ApiKeyScope::parse_lenient, which is the documented method for reading from the database (accepts unknowns, logs warning). Added regression test read_key_with_legacy_scope_string_is_preserved. ## Finding 4: required_scope fallback allowed POST with read-only key required_scope returned Some("chat:read") for ANY /v1/* path that wasn't /v1/providers/* or /v1/chat/* — regardless of HTTP method. This meant a key with only the chat:read scope could hit POST /v1/messages (Anthropic) and pass the authz check, then rely on downstream luck. Updated the fallback to inspect the method: GET → chat:read, all others → chat:write. The special-cases for /v1/providers* and /v1/chat/* are preserved. Added regression test client_api_with_chat_read_scope_rejected_on_post_to_messages. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: CodeRabbit <noreply@coderabbit.ai> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the cargo group with 1 update in the / directory: time.
Updates
timefrom 0.3.36 to 0.3.47Release notes
Sourced from time's releases.
Changelog
Sourced from time's changelog.
... (truncated)
Commits
d5144cdv0.3.47 releasef6206b0Guard against integer overflow in release mode1c63dc7Avoid denial of service when parsing Rfc28225940df6Add builder methods to avoid verbose construction00881a4Manually format macros everywherebb723b6Addtrailing_inputmodifier toend31c4f8ePermitW12indate!macro490a17bMark error paths in well-known formats as cold6cb1896OptimizeRfc2822parsing6d264d5Remove erroneous#[inline(never)]attributesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.