fix(ci): align lint-safe security paths

This commit is contained in:
elky
2026-09-05 03:19:53 +08:00
parent f5e1420ee6
commit 33d5cd5993
45 changed files with 180 additions and 132 deletions
@@ -118,6 +118,11 @@ impl std::fmt::Debug for LdapBindPasswordUpdate {
}
}
// The successful branch intentionally returns the complete persisted
// configuration so callers can continue with the exact CAS snapshot. Boxing
// it would change this public repository contract and add needless allocation
// on the normal (successful) path.
#[allow(clippy::large_enum_variant)]
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum CompareAndSwapLdapConfigResult {
Applied(StoredLdapModuleConfig),
@@ -455,6 +455,10 @@ impl std::fmt::Debug for UpsertOAuthProviderConfigRecord {
}
}
// Keep the returned provider value inline: this outcome is part of the
// repository API and the successful value is consumed immediately by callers.
// Boxing would be an API/ownership change for no security benefit.
#[allow(clippy::large_enum_variant)]
#[derive(Debug, Clone, PartialEq)]
pub enum UpsertOAuthProviderConfigOutcome {
Upserted(StoredOAuthProviderConfig),
@@ -513,6 +517,10 @@ impl UpsertOAuthProviderConfigRecord {
}
}
// Validation tests are kept beside the validation implementation so changes
// to endpoint policy are reviewed together. The repository traits below are
// intentionally declared after this focused test module for API readability.
#[allow(clippy::items_after_test_module)]
#[cfg(test)]
mod tests {
use super::{
@@ -311,6 +311,10 @@ impl BindUserOAuthLinkSessionExpectation {
}
}
// Returning the full linked-user record avoids a second repository lookup and
// is the established public contract. Keep the success value inline rather
// than changing every adapter/caller to an allocated box.
#[allow(clippy::large_enum_variant)]
#[derive(Debug, Clone, PartialEq)]
pub enum ResolveOAuthLinkedUserOutcome {
Linked(StoredUserAuthRecord),