Skip to content

fix: restrict change log api - #354

Merged
barredterra merged 3 commits into
version-15-hotfixfrom
restrict-changelog
Sep 22, 2026
Merged

barredterra merged 3 commits into
version-15-hotfixfrom
restrict-changelog

Conversation

@barredterra

@barredterra barredterra commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

The public change_log endpoint (allow_guest=True) returned more data than the other public endpoints, and it was expensive to call without authentication.

Problems

  • Data leak: The water_body endpoint returns only Water Bodies that are active and displayed in the fishing guide. The change log did not apply these filters. It returned the names of hidden Water Bodies and the new value of every changed field, including fields that are not public, for example number, is_property_water_body, blacklisted_fish_species or current_information_expires_on. The Firebase notifications use the same formatting, so they had the same problem.
  • Load: The endpoint has no cache. A request with an old from_datetime reads and formats the full Version history of all tracked DocTypes.
  • Crash: Some old Versions have no added or changed keys. A request that includes them failed with a TypeError.

Changes

  • The change log contains only the fields that the water_body, fish_species and legal endpoints return. An event without public changes is dropped.
  • The change log skips Water Bodies that are not public now.
  • A change to is_active or display_in_fishing_guide is reported as "Created" (the Water Body is now public) or "Deleted" (the Water Body is now hidden), so that clients can add or remove it.
  • change_log allows 30 requests per minute for each IP address.
  • Missing Version keys no longer cause a crash.
  • docs/api.md describes the new behavior.

Notes for clients

  • Clients no longer receive changes to fields that are not public.
  • Clients can receive "Deleted" and "Created" events for Water Bodies that were hidden or shown again.
  • A Water Body that was never public and is then deleted still appears as a "Deleted" event.

Tests

landa/water_body_management/test_change_log.py covers public, hidden and re-published Water Bodies.

@barredterra barredterra changed the title restrict changelog fix: restrict change log api Sep 22, 2026
@greptile-apps

greptile-apps Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no outstanding correctness, security, or repository-rule violations.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Guest change_log request] --> B{Within rate limit?}
    B -->|No| C[Reject request]
    B -->|Yes| D[Read Version and Deleted Document entries]
    D --> E[Build change-log events]
    E --> F{Water Body event?}
    F -->|No| I[Filter changes to public fields]
    F -->|Yes| G{Visibility transition?}
    G -->|Yes| H[Emit Created or Deleted]
    G -->|No| J{Currently public?}
    J -->|No| K[Drop event]
    J -->|Yes| I
    I --> L{Public changes remain?}
    L -->|No| K
    L -->|Yes| M[Return event]
    H --> M
Loading

Reviews (2) · Last reviewed commit: "test: deletion of hidden water body is r..."

Comment thread landa/water_body_management/change_log.py
Comment thread landa/water_body_management/change_log.py
Comment thread landa/water_body_management/change_log.py
@barredterra

Copy link
Copy Markdown
Member Author

@greptileai

@barredterra
barredterra merged commit a182426 into version-15-hotfix Sep 22, 2026
10 of 11 checks passed
@barredterra
barredterra deleted the restrict-changelog branch September 22, 2026 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant