You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two small VS Code webview hardening items deferred from the final checks of #4810 and #4813. Neither is a user-facing bug today.
Agent toggle while unscoped. Since 🤖 fix: reload the VS Code webview agent list after the connection recovers #4810, AgentProvider gets no workspace ID in file mode (and, since 🤖 fix: allow agents.list from the VS Code webview for known workspaces #4792, before the workspace list arrives). The composer is disabled then, but SimpleAgentToggle in vscode/src/webview/ChatComposer.tsx stays clickable and writes the webview's global agent key (agentId:__global__). Workspace scopes do not read that key, so nothing leaks into a workspace; the click is just misleading. Fix: also disable the toggle while the provider has no workspace scope.
Stream chunks bypass redaction.redactWebviewOrpcResult runs on value responses in handleOrpcCall (vscode/src/extension.ts), but pumpOrpcStream forwards stream items unchanged. The allowed streams (providers.onConfigChanged, config.onConfigChanged, policy.onChanged) emit only void change signals, so nothing leaks today. Fix (defense in depth): run stream items through the same redactor, so a future structured stream on a redacted path cannot bypass it.
Problem
Two small VS Code webview hardening items deferred from the final checks of #4810 and #4813. Neither is a user-facing bug today.
AgentProvidergets no workspace ID in file mode (and, since 🤖 fix: allow agents.list from the VS Code webview for known workspaces #4792, before the workspace list arrives). The composer is disabled then, butSimpleAgentToggleinvscode/src/webview/ChatComposer.tsxstays clickable and writes the webview's global agent key (agentId:__global__). Workspace scopes do not read that key, so nothing leaks into a workspace; the click is just misleading. Fix: also disable the toggle while the provider has no workspace scope.redactWebviewOrpcResultruns on value responses inhandleOrpcCall(vscode/src/extension.ts), butpumpOrpcStreamforwards stream items unchanged. The allowed streams (providers.onConfigChanged,config.onConfigChanged,policy.onChanged) emit only void change signals, so nothing leaks today. Fix (defense in depth): run stream items through the same redactor, so a future structured stream on a redacted path cannot bypass it.Refs #4797, #4766
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$4.48