Skip to content

Close four disclosure and injection paths (review, area 1a) - #301

Merged
adamjohnwright merged 1 commit into
mainfrom
review-1a-disclosure
Oct 3, 2026
Merged

adamjohnwright merged 1 commit into
mainfrom
review-1a-disclosure

Conversation

@adamjohnwright

Copy link
Copy Markdown
Contributor

These four come from the max-level code review of src/api and src/handoff. The reviewer confirmed each one by running code, and I checked each again before fixing it.

Finding Fix Test
A search question handed off to the chat was rendered unescaped, and the chat renders HTML (unsafe_allow_html, rehype-raw). A shared Continue-in-chat link therefore put live markup into whoever opened it, including script inside a srcdoc iframe running in the chat's origin. escape(handoff.question) Unit test. Also checked in a browser: with the fix, 0 live elements and the markup shown as text; with the escape removed, 1 live element.
httpx logs request URLs at INFO, and Analysis Service URLs carry the reader's analysis token, a bearer capability for the full result. httpx and httpcore log at WARNING Unit test, sabotaged
The gene-list result seeded into the model's history kept the Pathway Browser link, which contains the token. Overrepresentation.for_model drops the link Unit test, sabotaged
A thread seeded with a reader's analysis still ran the web search (Tavily), whose query is rephrased from that history. Web search is off on such threads Not unit-tested: it's in the Chainlit handler, which the tests don't import. It changes one boolean.

The browser check is ~/chat-uitest/handoff_markup.py.

The other 11 findings from area 1a will follow in separate PRs.

🤖 Generated with Claude Code

From the code review of src/api and src/handoff:
- A search question handed off to the chat was rendered unescaped, and the
  chat renders HTML. A shared Continue-in-chat link put live markup into the
  chat of whoever opened it. Escaped; checked in a browser both ways (with
  the escape removed, the markup rendered as a live element).
- httpx logs every request URL at INFO, and Analysis Service URLs carry the
  reader's analysis token. httpx and httpcore now log at WARNING.
- The gene-list result seeded into the model's history included the
  Pathway Browser link, which embeds the analysis token. The model now gets
  the reply without it.
- A thread seeded with a reader's analysis no longer runs the web search,
  whose query is rephrased from that history: the reader agreed to show
  the model provider, not a search engine.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@adamjohnwright
adamjohnwright merged commit 12d11c0 into main Oct 3, 2026
10 checks passed
@adamjohnwright
adamjohnwright deleted the review-1a-disclosure branch October 3, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant