Fix WhatsApp country-code handling on Mobile Safari - #828
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe WhatsApp pairing form now requests a phone number with an explicit international prefix. The request handler validates nonblank numbers before saving normalized digits. Blank submissions continue to use the saved-number fallback. ChangesWhatsApp phone pairing
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to The pairing change is ready to merge after normal checks; no unresolved issue was established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change rejects ambiguous phone numbers before saving them and preserves the existing saved-number fallback. No new privilege or access-control bypass was established. Assurance remains limited because live pairing, concurrent submissions, and deployed access controls were not fully verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 2 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|



Why
Mobile Safari can offer a saved
+1...phone number for the WhatsApp pairing field but insert only its national form. The settings handler accepted that 10-digit value as if it still carried a country code, so pairing could proceed with a different number than the operator selected.Changes
+, then validate and normalize the same punctuation the form already accepted.LOCAL_WHATSAPP_PHONEsecret fallback.User-visible and security effects
The field now says that the number must start with
+and its country code. A national-format substitution receives a readable 400 response instead of changing the saved pairing number. Credential storage and bridge permissions are unchanged; the phone continues to be normalized to digits before it is saved.Verification
python3 tests/test-connect-card.py- 38 passed.python3 tests/test_agentbox.py- 156 passed, 1 skipped.nix build -L --keep-going .#ci-native- passed after the final commit.git diff --checkand Python compilation passed.Delivery checklist
Fixes #820.