SIGN IN SIGN UP

fix: Harden proxy cache repository filter validation (#23762)

* fix: Harden Proxy Cache Repository Filter Validation

Address review findings on the cherry-picked filter feature:

- Reject group-imbalanced regex patterns (e.g. "foo)|(bar") that fail to
  compile bare but compile inside the ^(?:...)$ wrapper with broken
  anchoring, silently widening the filter.
- Propagate the metadata-store lookup error when validating a kind
  change instead of silently skipping cross-validation, which could
  persist a kind incompatible with the stored pattern and fail-close
  every pull in the project.
- Add pattern.ValidateKind as the single owner of the kind contract;
  both write paths (PUT /projects/{id} and the metadata API) now accept
  an empty kind as the documented doublestar default, where previously
  the project update path returned 400.
- Drop dead in-request metadata lookups and unreachable nil-controller
  guards in the metadata validator (the API accepts one key per request
  and the controllers are always set); extract requireProxyProject.
- Declare audit resolver URL patterns once for both registration and
  extraction, and escape the v2.0 dot, mirroring the member resolver.
- Honor x_is_resource_name in the audit resolver so all-digit project
  names are not misattributed to a project ID.
- Note the provenance of the doublestar v4 validator port.

Signed-off-by: Prasanth Baskar <prasanth@8gears.com>

* fix: Carry X-Is-Resource-Name Header Into Audit Metadata

X-Is-Resource-Name is a header parameter, not a query parameter, so the
project audit resolver could not see it in the request URL and still
resolved all-digit project names as project IDs. Capture the header into
commonevent.Metadata in the log middleware and use it in the resolver.

Also list the empty/default option in the ValidateKind error message so
clients receive the full set of accepted values.

Signed-off-by: Prasanth Baskar <prasanth@8gears.com>

* fix: Address Proxy Filter Review Feedback

Validate partial project updates against stored filter metadata and serialize one-key metadata validation and writes under a project-row lock.

Signed-off-by: Prasanth Baskar <prasanth@8gears.com>

---------

Signed-off-by: Prasanth Baskar <prasanth@8gears.com>
P
Prasanth Baskar committed
5d19f26259df76891868cd6ea3c4faaeb42a7f81
Parent: 247b23c
Committed by GitHub <noreply@github.com> on 8/25/2026, 8:42:14 AM