fix: code cleanup — path traversal, test leaks, dead code, consistency

- Add path traversal protection to GET /api/cases/:name and fix-plan
- Use safePathSchema for LinkCaseSchema.path
- Fix QR auth test timer leak (afterAll → afterEach) and env var try/finally
- Remove dead terminal size check after Zod validation in resize route
- Remove no-op sampleCount guard in adaptive timing
- Replace hardcoded values with constants in notification-manager and subagent-windows
- Add Zod validation to POST /api/auth/revoke
- Use _apiPut instead of raw fetch in subagent-windows
- Add SwipeHandler.cleanup() for consistency with other mobile handlers
- Move NiceConfig/ProcessStats from types/plan.ts to types/common.ts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
arkon
2026-03-01 17:26:31 +01:00
co-authored by Claude Opus 4.6
parent f94ab08cbe
commit d094d9ec50
11 changed files with 94 additions and 71 deletions
+3 -7
View File
@@ -111,11 +111,7 @@ Object.assign(CodemanApp.prototype, {
// Save to server for cross-browser persistence
try {
await fetch('/api/subagent-window-states', {
method: 'PUT',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(windowStates)
});
await this._apiPut('/api/subagent-window-states', windowStates);
} catch (err) {
console.error('Failed to save subagent window states to server:', err);
}
@@ -178,7 +174,7 @@ Object.assign(CodemanApp.prototype, {
if (windowData && windowData.element) {
// Parse position values and clamp to viewport
let left = parseInt(position.left, 10) || 50;
let top = parseInt(position.top, 10) || 120;
let top = parseInt(position.top, 10) || WINDOW_INITIAL_TOP_PX;
const viewportWidth = window.innerWidth;
const viewportHeight = window.innerHeight;
const windowWidth = 420;
@@ -545,7 +541,7 @@ Object.assign(CodemanApp.prototype, {
} else {
// Normal positioning
startX = 50;
startY = 120;
startY = WINDOW_INITIAL_TOP_PX;
maxCols = Math.floor((viewportWidth - startX - 50) / (windowWidth + gap)) || 1;
}