fix(submit): 审阅绑定上下文 sha256,批准须带摘要,构建只从内部 API 取上下文并校验字节
This commit is contained in:
30 files changed
+910
-98
No files matched your search
@@ -0,0 +1,12 @@
|
||||
-- Binds a submission's review to the exact bytes that get built. The upload
|
||||
-- records the sha256 of the stored context tarball; an admin approves naming
|
||||
-- the digest they reviewed, and the approve CAS only wins while the row still
|
||||
-- carries it. A re-upload while pending replaces both the blob and the digest,
|
||||
-- so an approval issued against the old digest loses instead of building
|
||||
-- content nobody saw. NULL marks a context uploaded before digests were kept
|
||||
-- (or no upload yet); such a row cannot be approved until it is uploaded again.
|
||||
ALTER TABLE image_submissions ADD COLUMN context_sha256 text;
|
||||
|
||||
-- The digest the build was allowed to consume. The context-fetch step refuses
|
||||
-- any other bytes, so a context swapped after approval fails the build.
|
||||
ALTER TABLE image_builds ADD COLUMN context_digest text;
|
||||
Reference in new issue
Block a user