Skip to content

docs: LangAlpha #378 fixed in #425 (26th fix); treg report delivered - #161

Merged
elfrost merged 1 commit into
mainfrom
daily/2026-09-26-langalpha-resolved
Sep 26, 2026
Merged

elfrost merged 1 commit into
mainfrom
daily/2026-09-26-langalpha-resolved

Conversation

@elfrost

@elfrost elfrost commented Sep 26, 2026

Copy link
Copy Markdown
Owner

LangAlpha — resolved (26th fix)

ginlix-ai/LangAlpha#378 was closed as completed on 2026-09-25, 27 days after filing, by #425 (2eab033f).

What shipped is not what was proposed. The issue proposed a one-line accessor swap. #425 removed the premise instead: the old preview route no longer resolves a signed URL or touches a session. It reads the registered preview command, gets or creates the app's one link, and redirects to it. That link opens for the signed-in owner alone, and the workspace UUID is no longer a credential anywhere. A regression test names #378.

Re-verified at 2eab033f:

  • Differential re-run: at the scanned commit, 1 of 5 unauthenticated session-touching routes woke sandboxes. At the fix, 0 do, and every remaining caller of the waking accessor is behind an authenticated owner.
  • New check probed: the redirect still answers anyone holding a UUID, but it hands back an app link code. The share_links_app_shape CHECK constraint makes app links unshareable, so the code opens nothing for anyone but the owner. The public metadata route reaches the waking path only past two independent ownership checks.

Files: the scan post (status + timeline), index.md (open → fixed, 25 → 26), fixed.md (row added; counters had drifted at 109 scans), scan-log.md (resolution suffix), work-with-me.md (counters had drifted; now 111 / 26).

treg — delivery record corrected

The post said the private send "had not gone out when this page was published". That was true at 13:31 UTC, but Gmail Sent shows the report went out at 13:41 UTC the same day. This PR adds a disclosure timeline and rewords the status line and the scan-log entry. The outcome is unchanged: no reply, no bounce, and none of the reported files has changed upstream.

🤖 Generated with Claude Code

LangAlpha: the maintainer closed #378 as completed on 2026-09-25, 27 days
after filing, with #425 (2eab033f). The fix is not the accessor swap the
issue proposed. The old /api/v1/preview/{workspace}/{port} route no longer
resolves a signed URL or touches a session: it reads the registered preview
command, gets or creates the app's one link, and redirects to it. That link
opens for the signed-in owner alone, and the workspace UUID stopped being a
credential altogether (report frames load under an expiring HMAC grant). A
regression test names #378.

Re-verified at 2eab033f, differential first: five unauthenticated routes
touched a workspace session at the scanned commit and one called the waking
accessor; at the fix, none do, and every remaining get_session_for_workspace
caller is behind an authenticated owner. The redirect was probed as a new
check, since it still answers any UUID holder: the code it returns is an app
link, and the share_links_app_shape CHECK constraint makes an app link
unshareable, so the code opens nothing for anyone but the owner. The public
metadata route reaches the waking path only past two independent ownership
checks. The redirect cannot rewrite the owner's link (ON CONFLICT DO NOTHING;
the old path rides along as ?path=).

- scan post: status resolved, two timeline entries (fix, re-verification)
- index: outcome open -> fixed; confirmed-fix counters 25 -> 26
- fixed.md: LangAlpha row added; counters had drifted at 109 scans
- scan log: resolution suffix on the 2026-08-29 entry
- work-with-me: counters had drifted at 109 scans; now 111 / 26

treg: the post said the private send "had not gone out when this page was
published". True at 13:31 UTC; Gmail Sent shows it went to the SECURITY.md
address at 13:41 UTC the same day. Added a disclosure timeline and reworded
the status line and the scan-log entry so the page no longer reads as if the
maintainer was never told. The outcome is unchanged: no reply yet, no bounce,
and none of the reported files has changed upstream.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@elfrost
elfrost merged commit 47dc2da into main Sep 26, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant