Skip to content

Surface subscription validation errors instead of a generic message - #1919

Draft
schneems wants to merge 12 commits into
mainfrom
schneems/doc-generation-trust-gating
Draft

schneems wants to merge 12 commits into
mainfrom
schneems/doc-generation-trust-gating

Conversation

@schneems

@schneems schneems commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Doc generation is the most expensive work CodeTriage does. For each repo it clones the source from GitHub and runs YARD over it. Until now, a single doc subscription was enough to trigger that work forever, even if the subscriber had stopped opening the emails years ago. It also meant anyone could sign up and point that pipeline at whatever repos they liked.

It is also a resource exploitation vector (as seen with Rubygems.org/RubyDoc.info. The large hole is already plugged there, but I also want to "flatten the curve" (or rather raise the difficulty/cost) of using thses resources if a zero-day is found such that agents might be able to exploit them, but they wouldn't be able to do so opportunistically in the same day/session for additional compute.

This PR ties doc generation to real engagement:

  • Turning on docs requires some trust: New accounts can enable docs once they’re 7 days old. This means an attacker would have to do some pre-planning.
  • Reduce docs generation for repos no one is actively reading/consuming: Clicking a doc link in an email records activity on that subscription. A repo keeps getting docs generated only while at least one doc subscriber has clicked within the last 90 days. Repos nobody reads stop costing us anything.
  • Lapsed subscribers can come back in one click: When a doc subscription goes quiet, a scheduled sweep sends one email with a signed link that turns docs back on. No login needed. The link expires after 30 days.
  • Added a global kill switch. Setting SKIP_DOC_GENERATION=1 stops doc generation and the inactivity sweep without a deploy. Lets me turn it off from my phone if I need to.

@schneems
schneems force-pushed the schneems/doc-generation-trust-gating branch 4 times, most recently from 197e2c6 to 3c29d10 Compare October 1, 2026 15:28
@schneems
schneems force-pushed the schneems/doc-generation-trust-gating branch from 3c29d10 to 96d7108 Compare October 1, 2026 16:08

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant