Repository navigation
feat(merge_requests): validate captured fork review context - #631
Conversation
Keep fork identities distinct and require fresh reported target and global MR identity before future original commit reviews. Reject malformed detail identities before generated numeric coercion and discard obsolete captured reads. Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
sjungwon03-ai
left a comment
There was a problem hiding this comment.
Review of commit e549c2c: Reviewed separate nullable fork identities, strict status-first detail parsing and raw positive integer identity checks, IID/project consistency, redirect options and captured read-only OAuth behavior, plus global MR/explicit target confirmation and obsolete-result/error isolation in the repository. Primary GitLab API/model contracts checked; generated files and all 10 PR file blobs match the reviewed local head. Local format/analyze and all 7,698 tests pass (104 new test-first cases). Unknown source is preserved and unknown target is never inferred. No blocking findings. Original parent/reference validation, membership/availability/literal coordinate checks and guarded private-save/recovery UI remain follow-ups; this read does not establish atomic context or write eligibility.
Summary
Preserve source and target project IDs separately for fork merge requests. Harden the detail GET against malformed integer identities, mismatched IID/project metadata, redirect responses and malformed error bodies. Add a captured-account context read that confirms the known global MR and a reported target project, discarding obsolete results and failures without guessing missing metadata.
Closes #630
Validation
dart format .flutter analyzereports no warningsflutter testin all five workspace packagesbuild_runnerChecklist
devand closes one linked issueNotes for reviewers
General detail viewing still permits absent/null optional project metadata. The context reader requires an explicit target ID and known global MR identity. Missing/deleted source remains unknown; list/search metadata is not a fresh authoritative context. Captured read-only OAuth recovery remains available, and the caller must recheck currency after awaiting. No new UI/private write, original coordinates, membership/availability proof or atomic snapshot is exposed. Original parent/reference validation and guarded literal selection/save/recovery remain follow-ups; MW-07 remains in progress. See
docs/mr-commit-review-context.mdand its primary sources.