Repository navigation
Conversation
To best fulfill the requirements of an easy to use system to manage typosquatting, this PR was created. This leverages the existing NAME_SQUATTING publish check that uses levenshtein distance to check for similarly named extensions post-publish. The new dashboard view allows an admin to either mark a found check as a false positive and clear the check, or to soft-delete any extensions that are found to be maliciously typo squatting another extension. Any admin action taken will also be logged in the admin log table to make auditing these changes possible. This check is left as unenforced as the check is too sensitive, and has many false positives. This does provide all of the features that were requested in the initial PRD for management of the system, outside of exclusion keywords. Part of #1949 Assisted-by: Claude Opus 5
Assisted-by: Claude Opus 5
Restores the LocalDateTime import ExtensionValidationFailureRepository lost in the rebase's auto-merge, and applies spotlessApply/eslint --fix to match the tooling versions current on main. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Split out of #2081 (the dashboard/moderation half). Adds a "Name Squatting" page to the admin dashboard that surfaces the extensions already flagged by the existing
NAME_SQUATTINGpublish-time check (Levenshtein-distance similarity, unenforced, logged only). An administrator can, per flagged extension:Every admin action is recorded in the admin activity log. This PR does not change publish-time behavior at all — it is read/moderate only, over data the existing check already produces.
The other half of #2081 — a new publish-time check that blocks an exact-match display name collision — is split out as #2268, since the two are independent (no shared code beyond two non-overlapping additions to
RepositoryService).Test plan
./gradlew compileJava compileTestJava spotlessCheckpasses./gradlew test --tests NameSquattingAPITest --tests AdminServiceTest --tests NameSquattingAdminServiceTestpasses (Postgres-backed suites couldn't be run here — no Docker daemon in this environment)yarn lintpassesyarn test --run test/unit/pages/admin-dashboardpasses (72 tests)🤖 Generated with Claude Code