Repository navigation
Improve mobile navigation and assistant access - #12
Merged
Merged
Conversation
2witstudios
pushed a commit
that referenced
this pull request
Jan 24, 2026
Adds adminRoleVersion field to users schema to detect role changes and prevent timing attacks during admin role modifications. Changes: - Add adminRoleVersion field to users table (default: 0) - Update SessionClaims to include adminRoleVersion - Create updateUserRole function that bumps version on role changes - Create validateAdminAccess function for DB-level validation - Enhance verifyAdminAuth to validate adminRoleVersion at request time - Update BaseAuthDetails and VerifiedUser interfaces - Add comprehensive integration and unit tests - Generate database migration (0044) Security: This prevents race conditions where a user's admin status changes between token issuance and request validation. Addresses vulnerability #12 from security hardening plan.
2witstudios
added a commit
that referenced
this pull request
Jan 24, 2026
* feat(auth): P4-T2 Admin Role Versioning Adds adminRoleVersion field to users schema to detect role changes and prevent timing attacks during admin role modifications. Changes: - Add adminRoleVersion field to users table (default: 0) - Update SessionClaims to include adminRoleVersion - Create updateUserRole function that bumps version on role changes - Create validateAdminAccess function for DB-level validation - Enhance verifyAdminAuth to validate adminRoleVersion at request time - Update BaseAuthDetails and VerifiedUser interfaces - Add comprehensive integration and unit tests - Generate database migration (0044) Security: This prevents race conditions where a user's admin status changes between token issuance and request validation. Addresses vulnerability #12 from security hardening plan. * fix: add missing adminRoleVersion to test mocks, mark unused var - Add adminRoleVersion: 0 to mock user objects in user-validator.test.ts - Rename isNewUser to _isNewUser in desktop auth exchange (unused param) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix: remove unused isNewUser variable in desktop auth Desktop tsconfig has noUnusedLocals: true which doesn't allow underscore-prefixed unused variables. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(desktop): restore isNewUser param and pass to dashboard URL The isNewUser param is sent from web OAuth callback to indicate new signups vs returning users. Pass it through to the dashboard URL so the web app can show appropriate welcome flow. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(tests): add adminRoleVersion to all test mocks Add adminRoleVersion: 0 to SessionAuthResult, MCPAuthResult, SessionClaims, and User mock objects across 60 test files to match updated schema. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com>
2witstudios
added a commit
that referenced
this pull request
Jul 29, 2026
…d doc accuracy #12 — the shell-io send path overwrote `session.lastViewerUserId` from a caller-supplied field with no re-authorization. That field is what the periodic re-auth tick evicts on, so whoever is recorded there is who the session's continued right to run is checked against. The endpoint is HMAC-gated, but a signature says WHO IS CALLING, not on whose behalf — a forged identity would keep a revoked user's session alive. The identity is now only refreshed to a user this request has ESTABLISHED authorization for: `started` (the start path re-decides auth in the same request, which is exactly what `startSession` does), or an injected `reauthorizeViewer` saying so. With neither, the field is ignored — failing closed, because a stale identity risks a spurious eviction while a forged one defeats revocation entirely. The reviewer flagged this as unexploitable today (no callers); fixing it now means the seam is correct before callers land rather than after. 4 tests, including the fail-closed default. Accessibility — `XtermTerminal` rendered into a bare div, so a screen reader had no way to name the region or report output arriving without a focus change. It is now `role="log"` + `aria-live="polite"` (polite, not assertive: shell output is a stream, and interrupting on every chunk is worse than silence), labelled per shell so multiple panes are distinguishable. The sandbox status description was reachable only by hovering for a tooltip — invisible to assistive tech and to anyone not using a mouse — and is now on `aria-label` too. Doc accuracy — three comments claimed `resolveAgentSessionPayerId` was "the only place" the payer rule lives, while the storage reconcile inlined its own branch. They are NOT interchangeable and should not be unified: the function falls back to the session owner on a failed page lookup, which is right at charge time (someone must pay for compute already consumed) and wrong during a storage sweep, where a failed lookup usually means a stale read of a page mid-delete and billing it would be a misattributed money movement we cannot take back. The comments now say that, instead of asserting a centralization that never existed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017V3eqwRX5cFy3Tdu2Syoro
3 of 10 tasks
2witstudios
added a commit
that referenced
this pull request
Aug 9, 2026
Fix the two HIGH defects (#1, #2) and the MEDIUM-HIGH (#3) from `.pu-reports/pu-rev-phase1.md`. All are latent — nothing writes these tables yet — and each would be a hand-written DELETE against production later. Finding #1 — `applyNodeWrite` prescribed drop-then-put. The composite self-FK is ON DELETE cascade, so dropping a container took its whole subtree with it. The collapse path drops a split whose children are being reparented, not deleted, and those children are only in `put`. Drop-first cascades them away and `put` cannot resurrect them. Fixed: put before drop, with the cascade named in the docblock so nobody tidies it back. Finding #2 — `create` accepted an empty `nodeId` and a blank `targetId`. Postgres stores both (text NOT NULL is satisfied by ''), and the read then rejects the whole set rather than filtering, so the workspace becomes permanently unreadable. Fixed: `create` refuses both with typed codes; `validateTree` refuses them too (the gate every write path runs, especially `put(nodes[])`); the false comment in `bind` is corrected; the untested compensating guard in `open` is removed, with a new test for the split path it covered. Finding #3 — `validateTree` skipped the finiteness sweep for parked panes, so a NaN/Infinity share on a detached pane passed. Fixed: the sweep is hoisted out of the group loop entirely, ahead of the per-container fraction rules, with a comment that parking does not make a share a number. Also fixed: finding #6 (the byte-identical round-trip claim is false; corrected to structural identity, with the change-test hazard named), #10 (the FK's truncated live name is recorded), #11 (`put`'s ordering guarantee is stated), and #12 (`validateTree`'s cast is removed, using the idiom `descendantsOf` already follows). Report with mutation table and the deferrable-FK argument (no, tested against PostgreSQL 17.5): `.pu-reports/pu-fix-review.md` Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Y4EZg67rRbxgutMEFi2UZJ
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Testing
https://chatgpt.com/codex/tasks/task_e_68d5651f446c8320a5a695ef41aa4da5