fix: Harden proxy cache repository filter validation (#23762)
* fix: Harden Proxy Cache Repository Filter Validation
Address review findings on the cherry-picked filter feature:
- Reject group-imbalanced regex patterns (e.g. "foo)|(bar") that fail to
compile bare but compile inside the ^(?:...)$ wrapper with broken
anchoring, silently widening the filter.
- Propagate the metadata-store lookup error when validating a kind
change instead of silently skipping cross-validation, which could
persist a kind incompatible with the stored pattern and fail-close
every pull in the project.
- Add pattern.ValidateKind as the single owner of the kind contract;
both write paths (PUT /projects/{id} and the metadata API) now accept
an empty kind as the documented doublestar default, where previously
the project update path returned 400.
- Drop dead in-request metadata lookups and unreachable nil-controller
guards in the metadata validator (the API accepts one key per request
and the controllers are always set); extract requireProxyProject.
- Declare audit resolver URL patterns once for both registration and
extraction, and escape the v2.0 dot, mirroring the member resolver.
- Honor x_is_resource_name in the audit resolver so all-digit project
names are not misattributed to a project ID.
- Note the provenance of the doublestar v4 validator port.
Signed-off-by: Prasanth Baskar <prasanth@8gears.com>
* fix: Carry X-Is-Resource-Name Header Into Audit Metadata
X-Is-Resource-Name is a header parameter, not a query parameter, so the
project audit resolver could not see it in the request URL and still
resolved all-digit project names as project IDs. Capture the header into
commonevent.Metadata in the log middleware and use it in the resolver.
Also list the empty/default option in the ValidateKind error message so
clients receive the full set of accepted values.
Signed-off-by: Prasanth Baskar <prasanth@8gears.com>
* fix: Address Proxy Filter Review Feedback
Validate partial project updates against stored filter metadata and serialize one-key metadata validation and writes under a project-row lock.
Signed-off-by: Prasanth Baskar <prasanth@8gears.com>
---------
Signed-off-by: Prasanth Baskar <prasanth@8gears.com> P
Prasanth Baskar committed
5d19f26259df76891868cd6ea3c4faaeb42a7f81
Parent: 247b23c
Committed by GitHub <noreply@github.com>
on 8/25/2026, 8:42:14 AM