fix(backend): harden principal child isolation
This commit is contained in:
@@ -48,3 +48,24 @@ enforced, new sessions had no trusted principal binding, and settings were globa
|
||||
- Existing dependency-injected route fakes without `sessionShow` retain a narrow test seam;
|
||||
production `ThtRunner` always has that method, so deployed requests cannot bypass the
|
||||
repository authorization check.
|
||||
|
||||
## Review follow-up
|
||||
|
||||
### RED
|
||||
|
||||
Focused regressions initially failed exactly at the three review findings: stale ambient
|
||||
display names survived into both `tht` and Pi child environments; mutation/document runner
|
||||
methods dropped the selected workspace; and `expandLocalHome` did not exist.
|
||||
|
||||
### GREEN
|
||||
|
||||
- Child environments now remove all four `THT_PRINCIPAL_*` keys from their cloned base
|
||||
environment before applying the exact request principal. Regression tests prove an absent
|
||||
display name does not inherit a stale ambient value in either child path.
|
||||
- `setName`, `setGroup`, `archive`, `unarchive`, and `documents` now take and retain an
|
||||
optional workspace. The rename route regression proves `session show` authorization and
|
||||
the mutation use the same non-default workspace.
|
||||
- Local principal paths expand `~`/`~/...`; existing local home and identity file modes are
|
||||
repaired to POSIX `0700`/`0600` when applicable, with Windows left unchanged.
|
||||
- Focused suite: `74 passed`; full backend suite: `213 passed` across `22` files, followed by
|
||||
TypeScript typecheck, production build, and diff check.
|
||||
|
||||
Reference in New Issue
Block a user