agent-context: enforce session-thread namespace and reject explicit title access - #186
Open
levineam wants to merge 1 commit into
Open
agent-context: enforce session-thread namespace and reject explicit title access#186levineam wants to merge 1 commit into
levineam wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
title/noteTitlevalues and enforcing theJarvOS Session Thread - <threadId>namespace.Description
sessionThreadTitlenow always derives the note title from the normalized thread key and ignoresinput.title/input.noteTitle, removing the explicit-title attack surface insrc/index.js.hasSessionThreadFrontmatterandassertSessionThreadNoteand invoked them before reading or modifying existing files inreadSessionThreadandwriteSessionThreadto reject non-session-thread files.titleproperty from thejarvos_session_thread_readandjarvos_session_thread_writeMCP toolinputSchemainscripts/jarvos-mcp.jsso MCP callers cannot pass an explicit filename.test/agent-context.test.jsthat verify explicit-title attempts do not expose private note bodies and that namespace collisions withoutsession-threadfrontmatter are rejected without modifying the target file.Testing
npm testinmodules/jarvos-agent-context(which executesnode --test test/*.test.js), and all tests passed (55/55).Codex Task