Conversation
schneems
force-pushed
the
schneems/doc-generation-trust-gating
branch
4 times, most recently
from
October 1, 2026 15:28
197e2c6 to
3c29d10
Compare
On a failed create/update, show the actual validation messages (e.g. the doc trust-gate reason, or an invalid email-limit) via errors.full_messages, falling back to "Something went wrong" only when no message is present. Previously a user blocked by the <7-day doc gate through the controller saw a generic error and never the carefully-worded reason.
schneems
force-pushed
the
schneems/doc-generation-trust-gating
branch
from
October 1, 2026 16:08
3c29d10 to
96d7108
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Doc generation is the most expensive work CodeTriage does. For each repo it clones the source from GitHub and runs YARD over it. Until now, a single doc subscription was enough to trigger that work forever, even if the subscriber had stopped opening the emails years ago. It also meant anyone could sign up and point that pipeline at whatever repos they liked.
It is also a resource exploitation vector (as seen with Rubygems.org/RubyDoc.info. The large hole is already plugged there, but I also want to "flatten the curve" (or rather raise the difficulty/cost) of using thses resources if a zero-day is found such that agents might be able to exploit them, but they wouldn't be able to do so opportunistically in the same day/session for additional compute.
This PR ties doc generation to real engagement:
SKIP_DOC_GENERATION=1stops doc generation and the inactivity sweep without a deploy. Lets me turn it off from my phone if I need to.