Files
truf-server/openspec/changes/harden-dockerhub-search-pagination/tasks.md
T
2026-09-30 20:30:56 +03:00

1.4 KiB

1. Runtime Safety

  • 1.1 Canonically stop the live supervisor and verify all managed child processes are down before editing app

2. Authenticated Search Implementation

  • 2.1 Make Hub bearer acquisition endpoint-aware and add a hub_search response path with explicit-pool fail-closed behavior, account rotation, and two-attempt transient request bounds
  • 2.2 Raise the search safety cap to 30 pages and make standard pagination fetch page one first, derive the expected range, and reject any incomplete expected page set
  • 2.3 Route recent-mode repository search through the same authenticated bounded response path
  • 2.4 Add a DockerHub discovery transport failure path that records a failed source cycle without advancing the query cursor

3. Regression Coverage

  • 3.1 Cover bearer authorization, token refresh, account rotation/cooldown, and explicit-pool no-fallback behavior without exposing secrets
  • 3.2 Cover the 30-page cap, page-one count boundary, ordered complete results, one transient retry, and rejection of unresolved partial pagination
  • 3.3 Cover failed-cycle cursor retention and successful-cycle compatibility
  • 3.4 Run focused and broader relevant scanner/runner test suites

4. Runtime Verification

  • 4.1 Canonically restart the supervisor and verify PostgreSQL, pipeline workers, DockerHub source health, restart counters, and absence of app bytecode artifacts