Repository navigation
fix: dedupe tg subscriptions with a chat id - #102
Merged
Merged
Conversation
azebuado
commented
Sep 23, 2026
Contributor
Author
There was a problem hiding this comment.
⚠️ AI Review (Claude Opus 4.8, worked ~3m): 1 non-blocking note; no blockers
Focused security fix; the eviction and unlink-scoping changes are correct. One note on the "dedupe" guarantee.
Finding: [NON-BLOCKING] Dedup is best-effort — concurrent redemptions can still duplicate
- Location:
src/api/telegram-subscription/services/telegram-subscription.ts—linkSubscriptionViaBot - The dedup is a
find-then-createwith no DB-level uniqueness on(account, chatId). Two near-simultaneous/startredemptions from the same chat can both pass thealreadyLinkedcheck and insert duplicate rows. Not a security issue (same chat, no eviction), but the PR title says "dedupe", so worth noting the guarantee is app-level only. - Deliberate simple-version choice — flagging for the record, not requesting a change.
Suggested fix (optional, if hardening later)
- Add a composite unique index on
(account, chat_id)via a Knex migration, andcatchthe unique-violation increateto keep it idempotent. Ship those two together. - No regression test accompanies this security fix; the repo has no test harness, so non-blocking, but a small guard against reintroducing the eviction would be worthwhile if a runner is ever added.
Review scope and related context
No prior review comments to dedupe against. Verified independently:
- Eviction fixed: a different
chatIdnow adds a row instead of overwriting the incumbent; same chat re-link is an idempotent no-op. - Unlink scoped to the calling chat's rows only;
removeSubscriptions(the delete-all primitive) removed with no remaining references insrc/orlib/. - Deploy order correct: controller now hard-requires
chatId, so BFF (#261) must deploy first — already stated in the PR body. - Existing rows are safe: schema unchanged,
database/migrations/empty, no lifecycle hook — nothing runs at deploy. Not fixed by this PR: already-evicted victims (their oldchatIdwas overwritten pre-fix and is unrecoverable).
🤖 Prompt for AI agents
Verify against current code. Fix only if still valid; keep the change minimal.
Context:
- src/api/telegram-subscription/services/telegram-subscription.ts, linkSubscriptionViaBot
- find-then-create dedup has a TOCTOU window: no unique constraint on (account, chatId), so concurrent /start redemptions from the same chat can insert duplicate rows.
- If hardening: add a Knex migration for a composite unique index on (account, chat_id) in database/migrations/*.js (must be .js, idempotent/IF NOT EXISTS, self-healing dedupe of existing dups, with a down()), and catch the unique-violation in create() to stay idempotent.
Generated using the pr-review skill from the CoW Protocol skills repo.
Contributor
Author
There was a problem hiding this comment.
Intentional decision to not change the db.
kernelwhisperer
approved these changes
Sep 29, 2026
shoom3301
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Must be deployed after cowprotocol/bff#261