Conversation
Channel deletes and their authorization lookups now use the casefolded sequence target as well as the msgid. This prevents a copy under another target from being selected or deleted. Direct-message lookup behavior stays unchanged. Add a SQLite regression test with the same msgid under two channel targets; deleting one target must leave the other copy intact.
bitbonsai
force-pushed
the
histserv-delete-target
branch
from
October 3, 2026 14:17
664a3ad to
5a278e9
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A single IRC message sent to multiple targets has the same msgid in each target's history.
DeleteMessagereceives a target and checks permission against it, but persistent-history lookup used only the msgid withLIMIT 1. It could select and delete a copy from another target, leaving the requested copy in place. In some paths, the wrong row could also trigger a permission failure for a valid request.Deleting every row with that msgid would be worse: it would erase history from targets the delete did not name, without a corresponding REDACT there.
Change
Scope history lookup and deletion by both msgid and the casefolded
sequence.targetin SQLite, MySQL, and PostgreSQL. Only the requested target's row is affected; copies in other targets remain intact. This keeps the database mutation aligned with the target used for authorization and avoids cross-target data loss.Regression test
TestDeleteMsgidIsTargetScopedstores one msgid under two targets, verifies lookup selects the requested target, deletes that copy, and confirms the unrelated copy remains.Checked in
golang:1.27:go test -tags "i18n mysql postgresql sqlite" ./...andgo vetpass;gofmtis clean. MySQL and PostgreSQL were compile-tested, not run against live databases.I am new to this codebase, so please flag it if I have misunderstood the target-scoping semantics.