Repository navigation
fix(queen): /queen/actors is guarded by the trusted-origin check, like needs-you - #1735
Conversation
Summary by t27-beesChecked by the t27 compilert27c parse, parse-complete and typecheck on each changed .t27 file at
Read by the modelThe PR guards Worth a look
Read: 290 files, +63310 -581, a summary only: the diff is larger than 4000 changed lines, so it was not read line by line. Head |
…e needs-you (Refs #1712) Lane 1 mounted /queen/actors (telemetry counts and the logged card decisions: pids, kinds, card names and arguments) bare, while its comment said it was operator information like /queen/needs-you. The route-guard audit in tests/api/routes/route-guard.test.ts caught it on the ship PR #1730. It now sits in its own sub-app behind requireTrustedAppOrigin(). The audit's pins are re-measured: 62 mounts (+/queen/actors, +/queen/waits), 20 guarded sub-apps, 39 /queen mounts with 13 wrapper-guarded; unguarded stays the ten allowlisted shells. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
aa4f157 to
e5e2cad
Compare
️✅ There are no secrets present in this pull request anymore.If these secrets were true positive and are still valid, we highly recommend you to revoke them. 🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request. |
The ship PR #1730 failed the route-guard audit:
/queen/actorswas mounted bare. It serves telemetry counts and the logged card decisions, operator information like/queen/needs-you. It now sits behindrequireTrustedAppOrigin()in its own sub-app. The audit's pinned counts are re-measured in the test, with the reasons.route-guard.test.tspasses 6/6.Part of #1712.
🤖 Generated with Claude Code