(
db: Pick<WorkerDb, 'execute'>,
params: {
finding: ParsedSecurityFinding;
owner: SecurityReviewOwner;
platformIntegrationId: string;
repoFullName: string;
slaDueAt: string;
}
)
| 655 | await releaseOwnerSyncLeaseLogged(db, owner, runId, chunkIndex, reason); |
| 656 | return null; |
| 657 | } |
| 658 | |
| 659 | const miss = await classifyOwnerMutationMiss(db, owner, runId, chunkIndex); |
| 660 | if (miss?.kind === 'stale_chunk') { |
| 661 | console.info('Security sync checkpoint clear rejected', { |
| 662 | runId, |
| 663 | chunkIndex, |
| 664 | reason: 'stale_chunk', |
| 665 | }); |
| 666 | } else if (miss?.kind !== 'completed') { |
| 667 | console.info('Security sync checkpoint clear rejected', { |
| 668 | runId, |
| 669 | chunkIndex, |
| 670 | reason: 'superseded', |
| 671 | }); |
| 672 | } |
| 673 | const reaction = reactToOwnerMutationMiss(miss, createEmptySyncResult(), { |
| 674 | releaseOnSuperseded: true, |
| 675 | }); |
| 676 | if (reaction.release) { |
| 677 | await releaseOwnerSyncLeaseLogged(db, owner, runId, chunkIndex, reason); |
| 678 | } |
| 679 | return reaction.result; |
| 680 | } |
| 681 | |
| 682 | function createAuthInvalidSyncResult(repositories: string[]): SyncResult { |
| 683 | return { |
| 684 | ...createEmptySyncResult(), |
| 685 | authInvalid: repositories.length, |
| 686 | authInvalidRepos: [...repositories], |
| 687 | reauthRequired: true, |
| 688 | }; |
| 689 | } |
| 690 | |
| 691 | function isOrgOwner( |
| 692 | owner: SecurityReviewOwner |
| 693 | ): owner is { organizationId: string; userId?: never } { |
| 694 | return 'organizationId' in owner && Boolean(owner.organizationId); |
| 695 | } |
| 696 | |
| 697 | function toSecurityAgentCommandOwner(owner: SecurityReviewOwner): SecurityAgentCommandOwner { |
| 698 | return isOrgOwner(owner) |
| 699 | ? { type: 'org', id: owner.organizationId } |
| 700 | : { type: 'user', id: owner.userId }; |
| 701 | } |
| 702 | |
| 703 | function ownerFilter(owner: SecurityReviewOwner) { |
| 704 | if (isOrgOwner(owner)) { |
| 705 | return eq(agent_configs.owned_by_organization_id, owner.organizationId); |
| 706 | } |
| 707 | return eq(agent_configs.owned_by_user_id, owner.userId); |
| 708 | } |
| 709 | |
| 710 | function integrationOwnerFilter(owner: SecurityReviewOwner) { |
| 711 | if (isOrgOwner(owner)) { |
| 712 | return eq(platform_integrations.owned_by_organization_id, owner.organizationId); |
| 713 | } |
| 714 | return eq(platform_integrations.owned_by_user_id, owner.userId); |
no test coverage detected