docs: LangAlpha #378 fixed in #425 (26th fix); treg report delivered - #161
Merged
Merged
Conversation
LangAlpha: the maintainer closed #378 as completed on 2026-09-25, 27 days
after filing, with #425 (2eab033f). The fix is not the accessor swap the
issue proposed. The old /api/v1/preview/{workspace}/{port} route no longer
resolves a signed URL or touches a session: it reads the registered preview
command, gets or creates the app's one link, and redirects to it. That link
opens for the signed-in owner alone, and the workspace UUID stopped being a
credential altogether (report frames load under an expiring HMAC grant). A
regression test names #378.
Re-verified at 2eab033f, differential first: five unauthenticated routes
touched a workspace session at the scanned commit and one called the waking
accessor; at the fix, none do, and every remaining get_session_for_workspace
caller is behind an authenticated owner. The redirect was probed as a new
check, since it still answers any UUID holder: the code it returns is an app
link, and the share_links_app_shape CHECK constraint makes an app link
unshareable, so the code opens nothing for anyone but the owner. The public
metadata route reaches the waking path only past two independent ownership
checks. The redirect cannot rewrite the owner's link (ON CONFLICT DO NOTHING;
the old path rides along as ?path=).
- scan post: status resolved, two timeline entries (fix, re-verification)
- index: outcome open -> fixed; confirmed-fix counters 25 -> 26
- fixed.md: LangAlpha row added; counters had drifted at 109 scans
- scan log: resolution suffix on the 2026-08-29 entry
- work-with-me: counters had drifted at 109 scans; now 111 / 26
treg: the post said the private send "had not gone out when this page was
published". True at 13:31 UTC; Gmail Sent shows it went to the SECURITY.md
address at 13:41 UTC the same day. Added a disclosure timeline and reworded
the status line and the scan-log entry so the page no longer reads as if the
maintainer was never told. The outcome is unchanged: no reply yet, no bounce,
and none of the reported files has changed upstream.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LangAlpha — resolved (26th fix)
ginlix-ai/LangAlpha#378 was closed as completed on 2026-09-25, 27 days after filing, by #425 (
2eab033f).What shipped is not what was proposed. The issue proposed a one-line accessor swap. #425 removed the premise instead: the old preview route no longer resolves a signed URL or touches a session. It reads the registered preview command, gets or creates the app's one link, and redirects to it. That link opens for the signed-in owner alone, and the workspace UUID is no longer a credential anywhere. A regression test names #378.
Re-verified at
2eab033f:share_links_app_shapeCHECK constraint makes app links unshareable, so the code opens nothing for anyone but the owner. The public metadata route reaches the waking path only past two independent ownership checks.Files: the scan post (status + timeline),
index.md(open → fixed, 25 → 26),fixed.md(row added; counters had drifted at 109 scans),scan-log.md(resolution suffix),work-with-me.md(counters had drifted; now 111 / 26).treg — delivery record corrected
The post said the private send "had not gone out when this page was published". That was true at 13:31 UTC, but Gmail Sent shows the report went out at 13:41 UTC the same day. This PR adds a disclosure timeline and rewords the status line and the scan-log entry. The outcome is unchanged: no reply, no bounce, and none of the reported files has changed upstream.
🤖 Generated with Claude Code