build: Re-cut the two path-hardenings from stranded build 89773b06 against current main. In src/main.ts: (1) relPath() (around #8

Merged
Joel merged 1 commit from build/202ea266 into main 2026-09-04 14:18:52 +00:00
Owner

Re-cut the two path-hardenings from stranded build 89773b06 against current main. In src/main.ts: (1) relPath() (around :583-590 in the merged shape) must reject any path segment beginning with '.', so dotfiles and dot-dirs like .obsidian and .git cannot be read or listed; (2) the read handler (around :593-598) and the list handler (around :606-614) must be gated on an allowed text-extension set, so binaries and non-text files are refused rather than streamed. 89773b06's own implementation is at ~/.local/state/connor/frontend-work/89773b06/src/main.ts:537-543 (segment rule), :545-550 and :610 (extension set) — copy its rules, NOT its file: do not bring across its MCP server, which is already merged and would duplicate. FIRST, verify the copy you were given is post-merge main: it must contain ChangeFeed, VaultLink, writePermits and CommandsModal in src/main.ts. If those are missing, the checkout is stale (local main is 177fd83, origin/main is cfb0318) — STOP and report that instead of editing blind. Add tests if the repo has a runner; if it has no suite, say so plainly and park for manual review.


Built by Connor's frontend backburner (dispatch 202ea266) in an isolated clone; shipped deterministically by ship.py. The full build notes were spoken in conversation and stored in memory (agent-dispatch:202ea266). Review is the gate. Gate: npm run gate.

Re-cut the two path-hardenings from stranded build 89773b06 against current main. In src/main.ts: (1) relPath() (around :583-590 in the merged shape) must reject any path segment beginning with '.', so dotfiles and dot-dirs like .obsidian and .git cannot be read or listed; (2) the read handler (around :593-598) and the list handler (around :606-614) must be gated on an allowed text-extension set, so binaries and non-text files are refused rather than streamed. 89773b06's own implementation is at ~/.local/state/connor/frontend-work/89773b06/src/main.ts:537-543 (segment rule), :545-550 and :610 (extension set) — copy its rules, NOT its file: do not bring across its MCP server, which is already merged and would duplicate. FIRST, verify the copy you were given is post-merge main: it must contain ChangeFeed, VaultLink, writePermits and CommandsModal in src/main.ts. If those are missing, the checkout is stale (local main is 177fd83, origin/main is cfb0318) — STOP and report that instead of editing blind. Add tests if the repo has a runner; if it has no suite, say so plainly and park for manual review. --- Built by Connor's frontend backburner (dispatch `202ea266`) in an isolated clone; shipped deterministically by `ship.py`. The full build notes were spoken in conversation and stored in memory (`agent-dispatch:202ea266`). Review is the gate. Gate: `npm run gate`.
build: Re-cut the two path-hardenings from stranded build 89773b06 against curr
All checks were successful
gate / gate (pull_request) Successful in 8s
a93049507f
Re-cut the two path-hardenings from stranded build 89773b06 against current main. In src/main.ts: (1) relPath() (around :583-590 in the merged shape) must reject any path segment beginning with '.', so dotfiles and dot-dirs like .obsidian and .git cannot be read or listed; (2) the read handler (around :593-598) and the list handler (around :606-614) must be gated on an allowed text-extension set, so binaries and non-text files are refused rather than streamed. 89773b06's own implementation is at ~/.local/state/connor/frontend-work/89773b06/src/main.ts:537-543 (segment rule), :545-550 and :610 (extension set) — copy its rules, NOT its file: do not bring across its MCP server, which is already merged and would duplicate. FIRST, verify the copy you were given is post-merge main: it must contain ChangeFeed, VaultLink, writePermits and CommandsModal in src/main.ts. If those are missing, the checkout is stale (local main is 177fd83, origin/main is cfb0318) — STOP and report that instead of editing blind. Add tests if the repo has a runner; if it has no suite, say so plainly and park for manual review.

Built by my frontend backburner (dispatch 202ea266), diff verified by git; shipped by ship.py. Nothing merges without review.
Joel approved these changes 2026-09-04 14:18:49 +00:00
Joel merged commit a86cd27f85 into main 2026-09-04 14:18:52 +00:00
Joel deleted branch build/202ea266 2026-09-04 14:18:53 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ZSDev/obsidian-connor!8
No description provided.