Skip to content

fix(queen): /queen/actors is guarded by the trusted-origin check, like needs-you - #1735

Merged
gHashTag merged 1 commit into
actors-nextfrom
queen-actors-route-guard
Oct 10, 2026
Merged

gHashTag merged 1 commit into
actors-nextfrom
queen-actors-route-guard

Conversation

@gHashTag

Copy link
Copy Markdown
Owner

The ship PR #1730 failed the route-guard audit: /queen/actors was mounted bare. It serves telemetry counts and the logged card decisions, operator information like /queen/needs-you. It now sits behind requireTrustedAppOrigin() in its own sub-app. The audit's pinned counts are re-measured in the test, with the reasons. route-guard.test.ts passes 6/6.

Part of #1712.

🤖 Generated with Claude Code

@t27-bees

t27-bees Bot commented Oct 10, 2026

Copy link
Copy Markdown

Summary by t27-bees

Checked by the t27 compiler

t27c parse, parse-complete and typecheck on each changed .t27 file at aa4f157. Nothing was generated, built or run. A pass means the file is well formed, not that it is right.

  • trios/agent-server/specs/automation/queen-contributor-keys.t27: parses and typechecks.
  • trios/agent-server/specs/jobs/release_t27c.t27: parses and typechecks.
  • trios/agent-server/specs/policy/issue_shape.t27: parses and typechecks.
  • trios/agent-server/specs/queen/actors.t27: parses and typechecks.
  • trios/agent-server/specs/queen/app.t27: parses and typechecks.
  • trios/agent-server/specs/queen/control.t27: parses and typechecks.
  • trios/agent-server/specs/queen/dashboard.t27: parses and typechecks.
  • trios/agent-server/specs/queen/dispatch_exit.t27: parses and typechecks.
  • trios/agent-server/specs/queen/events.t27: parses and typechecks.
  • trios/agent-server/specs/queen/holds.t27: parses and typechecks.
  • 15 more .t27 file(s) were not checked (at most 10 per review).

Read by the model

The PR guards /queen/actors with requireTrustedAppOrigin() middleware, fixing a route-guard audit failure where the endpoint was mounted without authentication. The endpoint serves telemetry counts and logged card decisions (operator information), similar to /queen/needs-you, and now sits behind the trusted-origin check in its own sub-app.

Worth a look

  • trios/agent-server/apps/server/src/api/server.ts (+111 -1): The main server mounting point—verify the new /queen/actors sub-app is correctly mounted with requireTrustedAppOrigin() applied and that no other queen routes were accidentally left unguarded during the refactor.
  • trios/agent-server/apps/server/src/api/routes/queen-actors-metrics.ts (+44 -0): New route file for the actors metrics endpoint—confirm it doesn't export any unguarded handlers that could be mounted elsewhere without the middleware.
  • trios/agent-server/apps/server/src/api/services/queen-actors.ts (+1229 -0): Core actors service—ensure telemetry/card-decision data access paths are only reachable through the guarded routes and not exposed via other service methods.
  • trios/agent-server/specs/automation/route-guard.test.ts (not in file list but implied by description): The description claims 6/6 tests pass—verify the test actually asserts the trusted-origin check on /queen/actors and isn't just testing the pre-existing routes.
  • trios/agent-server/apps/server/src/api/services/queen-dispatch.ts (+3004 -105): Large modification to dispatch logic—check that no new internal routes or handlers were added that bypass the origin guard.

Read: 290 files, +63310 -581, a summary only: the diff is larger than 4000 changed lines, so it was not read line by line. Head aa4f157. Model: openai-compatible/nvidia/nemotron-3-ultra-550b-a55b. Commands: @t27-bees review | summary | help | pause | resume. Free for every repository.

…e needs-you (Refs #1712)

Lane 1 mounted /queen/actors (telemetry counts and the logged card
decisions: pids, kinds, card names and arguments) bare, while its comment
said it was operator information like /queen/needs-you. The route-guard
audit in tests/api/routes/route-guard.test.ts caught it on the ship PR
#1730. It now sits in its own sub-app behind requireTrustedAppOrigin().
The audit's pins are re-measured: 62 mounts (+/queen/actors, +/queen/waits),
20 guarded sub-apps, 39 /queen mounts with 13 wrapper-guarded; unguarded
stays the ten allowlisted shells.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag
gHashTag force-pushed the queen-actors-route-guard branch from aa4f157 to e5e2cad Compare October 10, 2026 12:15
@gitguardian

gitguardian Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant