Skip to content

(janitor/dedupe): consolidate bounded stream body reads in git-token-service - #7239

Open
kilo-code-bot[bot] wants to merge 1 commit into
mainfrom
janitor/dedupe/bounded-stream-read
Open

kilo-code-bot[bot] wants to merge 1 commit into
mainfrom
janitor/dedupe/bounded-stream-read

Conversation

@kilo-code-bot

@kilo-code-bot kilo-code-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Summary

Five near-identical bounded JSON-body readers in services/git-token-service each re-implemented the same security-critical logic: enforce a byte cap while reading, validate that every chunk is a Uint8Array, cancel the stream and fail closed when the cap is exceeded, and strict UTF-8 decode before JSON.parse.

  • src/index.ts — readBoundedInternalJsonRequest
  • src/bitbucket-api.ts — readBoundedJson
  • src/bitbucket-code-review-service.ts — readBoundedJson
  • src/gitlab-oauth-credential-refresher.ts — readBoundedJson
  • src/gitlab-runtime-token-resolver.ts — readBoundedProjectIdentity

These copies had already drifted (differing reader.cancel() error handling, differing Uint8Array chunk guards, differing byte-cap constants and decode paths), so a fix to one would not reliably propagate to the others.

Change

Introduce src/lib/bounded-read.ts with:

  • readBoundedJsonBody(stream, maxBytes) — bounded read + strict UTF-8 decode + JSON.parse
  • ResponseTooLargeError — the single signal callers use to distinguish overflow from other failures

Each caller becomes a thin adapter that keeps its own error type (BitbucketApiError, BitbucketCodeReviewProviderError, Error, or a null return) and pre-flight Content-Length/Content-Type checks. No runtime behavior changes: overflow still fails closed, invalid chunks still reject, and AbortSignal timeouts in bitbucket-api still map to request_timed_out.

Net: 157 lines deleted, 22 added across callers plus one 51-line module.

Verification

  • pnpm --filter cloudflare-git-token-service typecheck — clean
  • pnpm -w exec oxlint ... on changed files — 0 errors
  • pnpm --filter cloudflare-git-token-service test — 24 files, 662 tests passed

Five near-identical implementations of the bounded JSON-body read
(enforce a byte cap, validate Uint8Array chunks, cancel on overflow,
strict UTF-8 decode) had drifted across bitbucket-api,
bitbucket-code-review-service, gitlab-oauth-credential-refresher,
gitlab-runtime-token-resolver, and the request entrypoint. Consolidate
the size-limit and chunk-validation logic into a single
lib/bounded-read module, leaving each caller's error mapping intact.
@kilo-code-bot kilo-code-bot Bot added the janitor Automated dead-code/duplication cleanup label Oct 7, 2026
@kilo-code-bot
kilo-code-bot Bot enabled auto-merge (squash) October 7, 2026 07:17
@kilo-code-bot

kilo-code-bot Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor Author

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (6 files)
  • services/git-token-service/src/lib/bounded-read.ts
  • services/git-token-service/src/bitbucket-api.ts
  • services/git-token-service/src/bitbucket-code-review-service.ts
  • services/git-token-service/src/gitlab-oauth-credential-refresher.ts
  • services/git-token-service/src/gitlab-runtime-token-resolver.ts
  • services/git-token-service/src/index.ts

Verified the consolidated readBoundedBytes/readBoundedJsonBody reproduces each caller's original behavior: per-chunk Uint8Array guard, byte-cap enforcement with reader.cancel() before failing closed, releaseLock() in finally, and strict UTF-8 decode before JSON.parse. Each caller keeps its own error mapping (response_too_large, invalid_response, request_timed_out, or null), and the pre-flight Content-Length/Content-Type checks are preserved. No further duplicate getReader()/TextDecoder call sites remain in the service.


Reviewed by deepseek-v4.1-flash · Input: 67.3K · Output: 16.9K · Cached: 600.7K

Review guidance: REVIEW.md from base branch main

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

janitor Automated dead-code/duplication cleanup

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants