Skip to content

Add a name squatting view to the admin dashboard - #2267

Open
netomi wants to merge 5 commits into
mainfrom
name-squatting-dashboard
Open

netomi wants to merge 5 commits into
mainfrom
name-squatting-dashboard

Conversation

@netomi

@netomi netomi commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Split out of #2081 (the dashboard/moderation half). Adds a "Name Squatting" page to the admin dashboard that surfaces the extensions already flagged by the existing NAME_SQUATTING publish-time check (Levenshtein-distance similarity, unenforced, logged only). An administrator can, per flagged extension:

  • Clear the finding as a false positive
  • Soft-delete the extension if it is judged to be squatting

Every admin action is recorded in the admin activity log. This PR does not change publish-time behavior at all — it is read/moderate only, over data the existing check already produces.

The other half of #2081 — a new publish-time check that blocks an exact-match display name collision — is split out as #2268, since the two are independent (no shared code beyond two non-overlapping additions to RepositoryService).

Test plan

  • ./gradlew compileJava compileTestJava spotlessCheck passes
  • ./gradlew test --tests NameSquattingAPITest --tests AdminServiceTest --tests NameSquattingAdminServiceTest passes (Postgres-backed suites couldn't be run here — no Docker daemon in this environment)
  • yarn lint passes
  • yarn test --run test/unit/pages/admin-dashboard passes (72 tests)

🤖 Generated with Claude Code

autumnfound and others added 3 commits September 29, 2026 11:46
To best fulfill the requirements of an easy to use system to manage typosquatting, this PR was created. This leverages the existing NAME_SQUATTING publish check that uses levenshtein distance to check for similarly named extensions post-publish. The new dashboard view allows an admin to either mark a found check as a false positive and clear the check, or to soft-delete any extensions that are found to be maliciously typo squatting another extension. Any admin action taken will also be logged in the admin log table to make auditing these changes possible.

This check is left as unenforced as the check is too sensitive, and has many false positives. This does provide all of the features that were requested in the initial PRD for management of the system, outside of exclusion keywords.

Part of #1949

Assisted-by: Claude Opus 5
Restores the LocalDateTime import ExtensionValidationFailureRepository
lost in the rebase's auto-merge, and applies spotlessApply/eslint --fix
to match the tooling versions current on main.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
netomi and others added 2 commits September 29, 2026 13:53
These files predate main's license-header harmonization
(3fee51b, #2265) and weren't touched by merging main in, so
server/scripts/format.sh's LicenseHeaderHarmonize step (run by the
"analyse" CI job's pre-commit hooks) still flagged them.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants