review fixes: block Codeman's own credential-bearing JSON, make the inside-anchor test bite

Widening the servable extensions to EDITABLE_EXTENSIONS made ~/.codeman
JSON previewable for the first time, and the blocklist named only
state.json. But settings.json holds a credential BY SCHEMA
(voiceSettings.apiKey), push-keys.json holds the VAPID PRIVATE key, and
intents.json is written 0600 precisely because captured prompts can carry
secrets — all three were one authenticated click away once an agent
printed the path. Blocked alongside state.json, whose rule now also
catches state-* siblings.

The never-re-cuts-inside-an-anchor test used an unmatchable URL tail, so
it passed with the guard deleted; the fixture now carries a matchable
/tmp path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-08-16 19:21:43 +02:00
parent da999b130e
commit ea4b940cef
3 changed files with 30 additions and 8 deletions
+8
View File
@@ -79,6 +79,14 @@ describe('isSensitivePath', () => {
// workspace.
['codeman state file', `${HOME}/.codeman/state.json`],
['codeman state file on a named instance', `${HOME}/.codeman-beta/state.json`],
['codeman state sibling (same payload)', `${HOME}/.codeman/state-inner.json`],
// settings.json holds voiceSettings.apiKey by schema; push-keys.json holds
// the VAPID PRIVATE key; intents.json is 0600 because captured prompts can
// contain secrets and is deliberately kept out of /api/search.
['codeman settings (Deepgram key)', `${HOME}/.codeman/settings.json`],
['codeman push keys (VAPID private)', `${HOME}/.codeman/push-keys.json`],
['codeman intent profiles', `${HOME}/.codeman/intents.json`],
['codeman intents on a named instance', `${HOME}/.codeman-beta/intents.json`],
];
it.each(blocked)('blocks the %s', (_label, path) => {