/** * @fileoverview File Viewer edit-mode policy (issue #212). * * Pure, IO-free policy for which workspace files the in-viewer editor may read * for editing and write back. Consumed by the `edit=1` branch of * `GET /api/sessions/:id/file-content` and by `PUT /api/sessions/:id/file-content` * in `src/web/routes/file-routes.ts`. * * Design (docs/file-viewer-edit-plan.md): * - ALLOWLIST of text extensions/basenames, not a blocklist — matching the * attachment-guard precedent. `svg` and `env` are deliberately absent: svg is * treated as untrusted on the read side, and `.env` is sensitive-path blocked * anyway; excluding them here keeps a single obvious refusal. * - The `.git/` subtree is denied outright: `.git/hooks/*` is code execution and * a corrupted index looks unrecoverable to a user who wanted to fix a typo. * - EOL helpers exist because a browser