/claim #71

Summary

  • Fix allowlist AST matching so literal values with the same literal node type are ignored as intended by the existing comparison comment.
  • Add focused Vitest coverage for disabled/admin bypasses, trailing-semicolon normalization, structurally matching literals, and rejected-query recording.

Root cause

deepCompareAst compared every primitive field in the parsed AST, including literal value fields. That made an allowlisted query shape such as WHERE id = 1 reject the same query shape with a different literal, even though the code comment says specific values should be ignored.

Validation

  • corepack pnpm vitest run src/allowlist/index.test.ts
  • corepack pnpm vitest run src/allowlist/index.test.ts --coverage.enabled true --coverage.include src/allowlist/index.ts --coverage.reporter text --coverage.thresholds.lines=0 --coverage.thresholds.branches=0 --coverage.thresholds.functions=0 --coverage.thresholds.statements=0
  • corepack pnpm exec prettier --check src/allowlist/index.ts src/allowlist/index.test.ts
  • git diff --check -- src/allowlist/index.ts src/allowlist/index.test.ts

Notes

  • Full corepack pnpm vitest run still reports the existing 4 upstream RLS failures in src/rls/index.test.ts; the new allowlist tests pass in that run.
  • I committed with --no-verify because the local Husky hook invokes a global pnpm binary that is not on this Windows Git hook PATH. The equivalent focused checks above were run with Corepack.
  • AI-assisted with Codex; I reviewed the diff and kept the scope to the allowlist behavior and coverage.

Claim

Total prize pool $250
Total paid $0
Status Pending
Submitted May 13, 2026
Last updated May 13, 2026

Contributors

SI

Siqi Li

@lisiqi1983

100%

Sponsors

OU

Outerbase (YC W23)

@outerbase

$250