Close four disclosure and injection paths (review, area 1a) - #301
Merged
Merged
Conversation
From the code review of src/api and src/handoff: - A search question handed off to the chat was rendered unescaped, and the chat renders HTML. A shared Continue-in-chat link put live markup into the chat of whoever opened it. Escaped; checked in a browser both ways (with the escape removed, the markup rendered as a live element). - httpx logs every request URL at INFO, and Analysis Service URLs carry the reader's analysis token. httpx and httpcore now log at WARNING. - The gene-list result seeded into the model's history included the Pathway Browser link, which embeds the analysis token. The model now gets the reply without it. - A thread seeded with a reader's analysis no longer runs the web search, whose query is rephrased from that history: the reader agreed to show the model provider, not a search engine. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
These four come from the max-level code review of
src/apiandsrc/handoff. The reviewer confirmed each one by running code, and I checked each again before fixing it.unsafe_allow_html, rehype-raw). A shared Continue-in-chat link therefore put live markup into whoever opened it, including script inside a srcdoc iframe running in the chat's origin.escape(handoff.question)httpxandhttpcorelog at WARNINGOverrepresentation.for_modeldrops the linkThe browser check is
~/chat-uitest/handoff_markup.py.The other 11 findings from area 1a will follow in separate PRs.
🤖 Generated with Claude Code