Robustness fixes from review (area 1a) - #302
Merged
Merged
Conversation
- /api/answer deletes its one-shot graph thread afterwards. Each answer left ~15 KiB of checkpoints for the life of the process, which also serves the chat (measured: 600 answers grew RSS by 22 MiB). - verify() refuses every malformed token. InvalidKeyError -- a header naming the allowed algorithm that does not match the key -- is not an InvalidTokenError and became an unauthenticated 500 on three routes. Tokens over 4,096 characters are refused before parsing. - One handoff claim per session. The window-message channel accepts posts from any page and has no rate limit; every distinct id was redeemed, each costing a message, a log line and state. The claimed id is kept as a string: a set in user_session does not survive being saved as JSON. - A claim runs as a task, like a message, so sending is blocked while the analysis data loads. A question asked meanwhile ran on the same thread and the seed was lost, while the chat said it was continuing. - Claim ids are fullmatched; `^...$` with match() accepted a newline. - Handoff refusals and claims log their reason in the message: the only formatter does not print `extra=`, so every refusal read the same. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
These are the second group of fixes from the max-level code review of
src/apiandsrc/handoff./api/answerleft each one-shot thread's checkpoints in memory for the life of the process. The reviewer measured RSS growing 22 MiB over 600 answers.AgentGraph.forget_threadis called in afinally, as a task so it is safe during cancellationverify()letInvalidKeyErrorthrough. A header naming the allowed algorithm that doesn't match the key gave an unauthenticated 500 on three routes. Reproduced.PyJWTError,ValueError,TypeErrorandRecursionError. Tokens over 4,096 characters are refused before parsing.run_as_task), so sending is blocked and Stop is shown while it loadsfullmatchextra=handoff refused: no_summary (no stored summary at tier identifiers)Verified
./checks.shpasses.🤖 Generated with Claude Code