Skip to content

feat(oci): add native foundation - #7444

Merged
waleedlatif1 merged 1 commit into
stagingfrom
feat/oci-foundation
Oct 8, 2026
Merged

waleedlatif1 merged 1 commit into
stagingfrom
feat/oci-foundation

Conversation

@BillLeoutsakosvl346

@BillLeoutsakosvl346 BillLeoutsakosvl346 commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

Adds the native OCI foundation shared by 14 product PRs: API-signing-key validation and encrypted storage, credential setup and reconnect through the shared service-account modal, workspace/service-bound credential loading, request signing, endpoint policies, DNS-pinned transport, cancellation, and bounded requests and responses. Product blocks, tools, selectors, and response schemas remain in their child PRs; this foundation exposes no product integration.

Request bodies above the shared 100 MiB buffer limit are rejected before copying. Private-key PEM input supports multiple lines and masking, with API-key-specific connection labels. Credentials use the normal encrypted workspace credential lifecycle; no shared OAuth app or deployment secret is required.

Validation on head 397998e46ac0abfb2bcaf78a7b23672a0b9ddf19, rebased onto staging d2bbd34d98:

  • Repeated validate-integration against Oracle's official signing/key documentation, including credential boundaries, endpoint trust, memory bounds, cancellation, and shared-modal wiring.
  • 440 focused tests pass, including Oracle and Vanta/Ramp credential paths.
  • Root lint, all 26 workspace type-checks, all 58 audits, generated deployment configuration, docs manifest, and block-registry checks pass.
  • Current-head CI passes: build, lint, both unit shards, all eight database integration shards, HTTP E2E suites, and desktop live tests. No open review threads.
  • Prior full local suite evidence remains in the validation report. The request-cap regression was demonstrated red before its fix.

Live OCI authentication/setup testing is still pending account access; no live-account pass is claimed. Before shipping the 14 product integrations, restack and validate each child against staging. OCI Compute (#7549) must reintroduce OCI_REGION_IDS alongside its real consumer.

@BillLeoutsakosvl346
BillLeoutsakosvl346 requested a review from a team as a code owner September 3, 2026 20:25
@vercel

vercel Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 3:18pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

The PR introduces native server-side OCI API-key credential support, including validation, request signing, endpoint resolution, encrypted storage, API contracts, and setup UI.

  • Adds OCI credential creation and full-tuple rotation flows.
  • Adds bounded OCI transport and a snapshotted region/realm registry.
  • Extends public credential contracts, generated CLI types, documentation, and focused tests.

Confidence Score: 5/5

The PR appears safe to merge because no blocking failure remains in the eligible follow-up review scope.

No blocking failure remains.

Important Files Changed

Filename Overview
apps/sim/lib/internal/oci/client.server.ts Implements server-only OCI credential parsing, Signature v1 request signing, bounded transport, and setup verification.
apps/sim/lib/internal/oci/endpoints.ts Adds a fixed OCI region/realm registry and strict service-endpoint validation.
apps/sim/lib/credentials/oci-api-key-service-account.server.ts Validates OCI API-key material, verifies it against OCI, sanitizes failures, and encrypts the resulting secret.
apps/sim/lib/credentials/orchestration/index.ts Integrates OCI fields into credential updates and enforces complete credential tuples during rotation.
apps/sim/lib/credentials/orchestration/credential-create.ts Integrates OCI verification and sanitized provider errors into credential creation.
apps/sim/lib/api/contracts/v2/credentials.ts Extends V2 credential contracts with OCI identifiers, region, private key, and optional passphrase fields.
apps/sim/app/workspace/[workspaceId]/integrations/components/connect-service-account-modal/connect-service-account-modal.tsx Adds the OCI API-key setup and reconnect form with required-field checks and secret inputs.
apps/sim/lib/credentials/service-account-secret.ts Registers OCI as a supported service-account secret provider and routes its fields through verification.
packages/sim-cli/src/generated/v2-api.ts Updates generated CLI API types to expose the new write-only OCI credential fields.

Sequence Diagram

sequenceDiagram
  participant User
  participant API as Credential API
  participant Validator as OCI Credential Validator
  participant OCI as OCI GetNamespace
  participant Store as Encrypted Credential Store
  User->>API: Submit OCI API-key fields
  API->>Validator: Validate OCIDs, region, fingerprint, and RSA key
  Validator->>OCI: Send signed, bounded GetNamespace request
  OCI-->>Validator: Return namespace
  Validator->>Store: Encrypt and persist validated credential
  Store-->>API: Return sanitized credential metadata
  API-->>User: Credential created or rotated
Loading

Reviews (17): Last reviewed commit: "fix(oci): preserve transport size errors" | Re-trigger Greptile

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 12 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/internal/oci/endpoints.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/endpoints.ts Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@greptile review this PR

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 12 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@greptile review this PR

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 12 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@greptile review this PR

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 12 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/internal/oci/client.server.ts
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/client.server.ts Outdated
Comment thread apps/sim/lib/internal/oci/client.server.test.ts Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@greptile review this PR

@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@BillLeoutsakosvl346 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

5 issues found across 12 files

Confidence score: 2/5

  • apps/sim/lib/internal/oci/errors.ts can leave provider-supplied signatures in sanitized OCI diagnostics, including authorization fragments with spaces around =; broaden the signature guard or fail closed for the full fragment and classify signature as sensitive.
  • apps/sim/lib/internal/oci/client.server.ts may expose credential-bearing serviceHeaders values when providers echo them in errors, creating a credential-leak risk; include caller-supplied signed-header values in the shared redaction set.
  • apps/sim/lib/internal/oci/client.server.ts fully buffers and parses large non-2xx response bodies before applying the diagnostic cap, increasing memory and resource-exhaustion risk; use the bounded response reader with a 64 KiB limit and cancel oversized reads.
  • apps/sim/lib/internal/oci/client.server.test.ts does not actually exercise redaction because the echoed percent-encoded URL causes sanitizeOciErrorField to fail closed; revise the fixture and assertions to verify the intended secret removal.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/internal/oci/client.server.ts">

<violation number="1" location="apps/sim/lib/internal/oci/client.server.ts:130">
P2: When `serviceHeaders` contains a credential-bearing value, the sanitized OCI error can expose it if the service echoes the header. Include credential values from the caller-supplied signed headers using the shared header extractor before parsing the diagnostic.</violation>

<violation number="2" location="apps/sim/lib/internal/oci/client.server.ts:136">
P2: When a caller allows a large response, a non-2xx OCI response is fully buffered and JSON-parsed before the diagnostic cap applies. Read error bodies through the bounded response-reader with a 64 KiB limit, cancel on overflow, and fall back to the status-only `OciRequestError`.</violation>
</file>

<file name="apps/sim/lib/internal/oci/errors.ts">

<violation number="1" location="apps/sim/lib/internal/oci/errors.ts:10">
P1: When an OCI response contains a serialized `signature` diagnostic field, `flattenJsonDiagnostic` emits the provider-supplied signature because neither key policy classifies it. Add `signature` to the OCI sensitive-key set so the request signature cannot reach `OciRequestError.message`.

(Based on your team's feedback about remaining credential-shaped fragments in provider diagnostics.)</violation>

<violation number="2" location="apps/sim/lib/internal/oci/errors.ts:113">
P1: When a provider echoes an OCI authorization fragment with spaces around `=`, this regex does not match and the unknown signature remains in the error message. Broaden the Signature guard or fail closed on the whole fragment before returning the diagnostic.

(Based on your team's feedback about remaining credential-shaped fragments in provider diagnostics.)</violation>
</file>

<file name="apps/sim/lib/internal/oci/client.server.test.ts">

<violation number="1" location="apps/sim/lib/internal/oci/client.server.test.ts:238">
P3: This test never exercises redaction. The echoed message includes the percent-encoded request URL (encodeURIComponent of the https origin), which contains %3A/%2F; sanitizeOciErrorField in errors.ts fails closed on any percent-encoded octet and returns a status-only error. All four not.toContain assertions then pass against the generic 'OCI request failed with status 401' message, so a regression in encoded-credential redaction would go undetected. Drop the percent-encoded URL from the echoed message so the diagnostic passes the percent guard, and assert the encoded fingerprint/passphrase are actually replaced with [REDACTED].</violation>
</file>

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Re-trigger cubic

Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/errors.ts Outdated
Comment thread apps/sim/lib/internal/oci/client.server.ts Outdated
Comment thread apps/sim/lib/internal/oci/client.server.ts Outdated
Comment thread apps/sim/lib/internal/oci/client.server.test.ts Outdated
@BillLeoutsakosvl346

Copy link
Copy Markdown
Contributor Author

@greptile review this PR

@waleedlatif1
waleedlatif1 force-pushed the feat/oci-foundation branch 2 times, most recently from 5f7ab5a to 397998e Compare October 8, 2026 15:11
@waleedlatif1
waleedlatif1 merged commit ba614dc into staging Oct 8, 2026
46 checks passed
@waleedlatif1
waleedlatif1 deleted the feat/oci-foundation branch October 8, 2026 18:42

This branch was successfully deployed

1 active deployment
Preview — 397998e4 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants