fix(security): enforce purpose scope validation for recovery tokens

Analysed against 9099df982 files changedby d-oit
Open PR on GitHub

Change-risk score

7.2out of 10Typical
Repository health
5.1to5.4base against this head

This change sits in the middle third of this repository's own risk distribution, so it is about as risky as the work around it. It is riskier than 61% of this repository's own commits.

No changed file lost health in this diff. Nothing outside this PR depends on a contract it changed.

Files changed
2
in this diff
Contracts changed
0
removed or signature
Outside callers
0
not in this diff
Findings added
0
0 resolved

Blast radius on the repo map

Every file in the repository, grouped into its own directories and sized by lines. The ones this PR changes are lit, and everything that imports them is marked.

.agentsappsdocspackagesplansscriptsskillswebworkerreader-coreschemashareduiarchiveagent-browserdo-web-doc-reso…github-…srcsrcsrcsrcsrcsrcscripts__tests__componentsfeaturesi18nlib__tests__routes__tests____tests____storie…__tests__
changed, health fellchanged, health rosechanged, health heldimports a changed fileuntouchedchanged by this PR

Drawing 1,005 of 1,037 files at a readable size, grouped by directory and sized by lines of code. 2 changed here reach 4 more by import. 32 are too small to see at this width, which is what the frame below is for.

Inside apps/worker/src

__tests__auditauthlibmiddlewareroutes__tests__adminreaderadmin-m…audit.t…cors.te…edge-ca…epub-va…fixtures.tsmiddleware.b…middleware.o…middleware.t…password-cov…password.tes…rate-limit…rate-limit…rate-limit…recovery.t…routes.acc…routes.admin.test.tsrout…ro…routes…rou…routes.ex…routes.fi…routes.in…routes.no…routes.re…routes.se…routes…securi…securi…securi…security.com…secu…sess…signed-u…signed-u…tenant-i…ten…upload-st…validation.test…index.tsadmin-middl…middleware…passwo…se…client.tsedge-cache…ema…obser…rate…reda…resp…secu…tenant…aut…bod…rate-li…valid…access.tsbooks…ca…comments.tsexport.…files.tsnotific…sea…sec…tel…signed-url.tsredact.t…au…auth.tsbooks.tsgr…stats.tshigh…insight…progress…

97 files, 2 changed by this PR and 0 that import one. Click any directory above to frame it instead.

Changed

Who else knows this code

The primary author of each changed file by share of its recent commits, mined from git history. Advisory: it says who has context, not who must review.

  • apps/worker/src/__tests__/recovery.test.tsgoogle-labs-jules[bot] 95% of 5 commits
  • apps/worker/src/routes/access.tsDominik Oswald 56% of 14 commits

Tests that cover this change

Test files that import a file this PR changes. Not a coverage measurement: it is the import graph, so it says which tests are worth running, not which lines they reach.

  • apps/worker/src/__tests__/middleware.test.ts
  • apps/worker/src/__tests__/routes.access.test.ts
  • apps/worker/src/__tests__/validation.test.ts

1 changed file has no test importing it.

AI-authored against human-authored

Each changed file attributed to whichever author class contributed more of its added lines, then scored. File-level, because a line-level blame index is not persisted.

Files changed
AI 2Human 0
Findings introduced
AI 0Human 0
Share of the regression
AI 0.00Human 0.00

Get this on your own pull requests

This page came from an index of d-oit/do-epub-studio. No model calls, no configuration, and it refreshes on every push. Install the bot and every pull request gets one of these.