Skip to content

fix(web): prevent writes from incomplete file previews - #78

Closed
saphid wants to merge 1 commit into
docs/consistency-preview-write-authorityfrom
fix/consistency-preview-write-authority
Closed

saphid wants to merge 1 commit into
docs/consistency-preview-write-authorityfrom
fix/consistency-preview-write-authority

Conversation

@saphid

@saphid saphid commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

A truncated markdown preview could allow task-checkbox edits that replace the full file with only the displayed content. Disable editing for read-only or truncated previews and recheck authoritative cached content at the mutation boundary. Missing raw read data and optimistic drafts alone cannot authorize writes; complete content preserves the existing save path.

Stacked on the proposed contract: pingdotgg#12666. Native markdown previews are already read-only and do not gain editing here.

Validation: 38 focused tests across 6 files passed, including 7 mutation-boundary cases; web typecheck and scoped lint exited 0. A direct SWE-2 Max review (devin -p --model swe-2-max) was attempted on the frozen diff but remained wholly silent; its captured process was stopped with SIGINT and exited 1 without a verdict. No completed independent review is claimed.

Runtime proof (2026-09-20, isolated proof app; base d6f2913 vs this branch): on a 1,099,741-byte markdown fixture past the read limit, clicking a task checkbox in the rendered truncated preview writes the truncated body back on base (file shrank to 1,048,576 bytes); on this branch the checkboxes are disabled and the file size and sha256 are unchanged after clicks.

Before: https://github.com/user-attachments/assets/ef03cca7-8b5d-446e-9297-850eba961a3b
After: https://github.com/user-attachments/assets/f8efcef4-aa90-437c-a12b-2114eee596fc

Native markdown previews were already read-only; no native change is claimed.

Implemented by GPT-6 Astra medium in the Codex harness, informed by SWE-2 Max audit work. Manager handled focused checks and publication.

@github-actions github-actions Bot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Sep 20, 2026
@saphid

saphid commented Sep 21, 2026

Copy link
Copy Markdown
Owner Author

Superseded by pingdotgg#12870 — the implementation PR now lives upstream against main (it contains the docs commit until the paired docs PR merges). Same head branch, same commits; this fork draft is closed to avoid a duplicate review surface.

@saphid saphid closed this Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant