Repository navigation
The rest of the public-surface review (area 1b) - #306
Merged
Merged
Conversation
- Handed-off summaries are model-written and the chat renders HTML, so markup a visitor steered into an answer ran in the browser of whoever opened their link. Summaries now have every '<' made inert (markdown kept); the question was escaped in #301. - Messages wait for an in-progress handoff seed. Running the claim as a task did not hold them: Chainlit's own startup task_end unlocks the box mid-seed whenever the claim arrives first. - The disclaimer had not been shown since Chainlit 2.11, whose footer is a div, not an anchor. custom.js now matches it (checked in a browser). - edit_message is off: an edit removed later turns from the screen but not from the model's history, so edited-out text kept being sent. - Secrets are loaded before chainlit is imported; chainlit reads OAuth client secrets once at import, so a Docker-secret one was never seen. - Caller tokens: 30s leeway for issue and not-before times (expiry stays strict); a verifying key that is not a PEM public key stops startup. - Session ids are redacted from the access log; for a guest the id is the whole credential. - An empty CHAINLIT_URI is treated as unset (it looped the captcha page); a missing site key stops startup (it rendered data-sitekey=None). - reclaim-docker-space.sh: --all removes only anonymous volumes, as its header always said; unknown arguments exit before anything runs. - The beta template and README no longer describe the unset-key bypass or pin an image that has it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This finishes the findings from the max-level review of the public surface. The websocket gate and the captcha cookie went in #305.
inert_html(): every<in a summary is escaped, and markdown is kept<and keeps its boldtask_endunlocks the message box in the middle of seeding.div)custom.jsmatches.watermarkedit_messageon, an edit left the edited-out text in the model's historyedit_message = falseiat/nbf(expiry stays strict). The key must parse as an Ed25519 or RSA public key.RedactSessionIdsfilter onuvicorn.accessCHAINLIT_URIsent the captcha page into a redirect loop; a missing site key renderedNonereclaim-docker-space.sh --allremoved named volumes, and unknown arguments pruned before warningdockeron PATHBrowser checks
Both run against a local instance of this branch.
v2.cookie is set, an answer arrives over the websocket, and the handoff survives the captcha.The follow-up check had earlier failed 3 of 5 times. That turned out to be the test harness: the restored disclaimer gave it enough stable text to declare an answer finished before the model had replied. The scripts in
~/chat-uitestnow ignore the footer.Still open: one decision for Adam
unsafe_allow_html = trueis the root cause behind both HTML findings. It is needed today because answers cite with<a href>anchors. Turning it off means changing answers to cite with markdown links, which touches the answer path the search page shares.🤖 Generated with Claude Code