refactor: update Trigger.dev configuration and encryption strategy - #116
Conversation
- Update trigger configs to include new trigger directories - Modify encryption method to use Node.js native scrypt instead of argon2 - Remove Deel-specific tasks and update workflow to include trigger directory - Add SECRET_KEY to deployment workflow - Simplify key derivation and remove external dependency
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
|
Caution Review failedThe pull request is closed. WalkthroughThis update modifies several components across the repository. The workflow configuration now triggers on pushes affecting additional file patterns and includes an extra secret environment variable for deployment. The encryption module switches from an asynchronous Argon2-based key derivation to a synchronous scrypt-based method, updating function signatures and imports accordingly. In the Deel trigger logic, the access token retrieval now includes decryption with enhanced error handling, while a minor case sensitivity change is applied in the schedule query. Finally, the trigger configuration files are updated with added directory paths and clarifying comments. Changes
Sequence Diagram(s)sequenceDiagram
participant S as syncDeelEmployees
participant C as Check API Key
participant D as Decrypt Function
participant E as Error Logger
S->>C: Retrieve api_key from integration settings
alt api_key contains "encrypted" property
C->>D: Attempt decryption of accessToken
alt Decryption succeeds
D->>S: Return decrypted token
else Decryption fails
D->>E: Log decryption error
E->>S: Return error & check SECRET_KEY fallback
end
else
C->>S: Use api_key as plain token
end
Poem
📜 Recent review detailsConfiguration used: CodeRabbit UI 📒 Files selected for processing (6)
✨ Finishing Touches
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
…3411) Fixes CodeQL js/request-forgery (alert #116, critical). callEnterpriseApi builds `new URL(endpoint, enterpriseApiUrl)` then fetches it; getAutomationRunStatus interpolated a user-provided runId straight into the endpoint path (`/api/tasks-automations/runs/${runId}`), so a crafted runId could inject path segments into the request URL. - Encode the user value in the path (encodeURIComponent(runId)). - Add an origin allowlist guard in callEnterpriseApi: resolve the URL against the configured enterprise API base and reject anything whose origin differs, so no caller can redirect the request to another host. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15) ### Bug Fixes * **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024)) * **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd)) * **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c)) * **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f)) * **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37)) * **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c)) * **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b)) * **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116) * **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85) ### Features * **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
Summary by CodeRabbit
Chores
Refactor
Bug Fixes