Skip to content

🤖 refactor: VS Code webview hardening follow-ups (unscoped agent toggle, stream redaction) #4820

Description

@ThomasK33

Problem

Two small VS Code webview hardening items deferred from the final checks of #4810 and #4813. Neither is a user-facing bug today.

  1. Agent toggle while unscoped. Since 🤖 fix: reload the VS Code webview agent list after the connection recovers #4810, AgentProvider gets no workspace ID in file mode (and, since 🤖 fix: allow agents.list from the VS Code webview for known workspaces #4792, before the workspace list arrives). The composer is disabled then, but SimpleAgentToggle in vscode/src/webview/ChatComposer.tsx stays clickable and writes the webview's global agent key (agentId:__global__). Workspace scopes do not read that key, so nothing leaks into a workspace; the click is just misleading. Fix: also disable the toggle while the provider has no workspace scope.
  2. Stream chunks bypass redaction. redactWebviewOrpcResult runs on value responses in handleOrpcCall (vscode/src/extension.ts), but pumpOrpcStream forwards stream items unchanged. The allowed streams (providers.onConfigChanged, config.onConfigChanged, policy.onChanged) emit only void change signals, so nothing leaks today. Fix (defense in depth): run stream items through the same redactor, so a future structured stream on a redacted path cannot bypass it.

Refs #4797, #4766


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $4.48

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions