History opens a seat's conversation from the Waiting card, table row and inspector. It pages the whole branch through the CHAT-02 board routes, renders untrusted text inert, polls with the follow cursor, and marks every switch (branch, newer, reconcile, gone). The WebUI proxy passes only the two conversation routes' queries upstream. Dewey authored it. Filbert asked for changes on r1 (24b046af) and approved r2 (d06de6a7) in review 160dd68d. A relaunch shows 'newer', not 'reconcile', a deviation from brief 2.3 item 6 that Filbert accepted. Co-Authored-By: Claude Opus 5.5 <[email protected]>
15 lines
1.0 KiB
Python
15 lines
1.0 KiB
Python
# Proxy mutants for the WebUI conversation routes. Run from a scratch copy of
|
|
# packages/webui (never the served tree): /tmp/dewey-chat02/scratch-board/packages/webui
|
|
import subprocess
|
|
f="src/serve.mjs"; orig=open(f).read()
|
|
M=[("query dropped","upstream + path + (conversation ? search : '')","upstream + path"),
|
|
("query sent on every route","upstream + path + (conversation ? search : '')","upstream + path + search"),
|
|
("conversation routes not proxied","const allowed = path === '/api/board' || conversation ? 'GET'","const allowed = path === '/api/board' ? 'GET'"),
|
|
("conversation routes accept POST","const allowed = path === '/api/board' || conversation ? 'GET'","const allowed = path === '/api/board' ? 'GET' : conversation ? req.method")]
|
|
for n,a,b in M:
|
|
assert orig.count(a)==1,n
|
|
open(f,"w").write(orig.replace(a,b))
|
|
r=subprocess.run(["node","--test","tests/serve.test.mjs"],capture_output=True,text=True,timeout=300)
|
|
print(("CAUGHT " if r.returncode else "MISSED ")+n)
|
|
open(f,"w").write(orig)
|