fix: refuse duplicate Claude account directories - #153
Conversation
Agent: agent-ea
Agent: agent-ea
|
[REVIEW] NO_GO — #153 @ 37d19f6 — lens: correctness+security+gates, reviewer Trebius (1 of 1) Reviewed the full diff for src/cli.ts, src/lib/switch-account.ts, and src/switch-account.test.ts against origin/main 9f56682, plus the surrounding switch, apply, auth-store, identity-index, wrong-dir, and repoint paths. Commands and gates:
Blocking P0/P1 findings:
Non-blocking follow-ups: none. |
Agent: Trebius
|
[REVIEW] GO — #153 @ 91d0af4 — lens: correctness+security+gates, reviewer Trebius (1 of 1) Focused remediation review of the named blockers and their direct regressions:
Blocking P0/P1 findings: none remain. The explicit and environment-selected live-default bypasses are covered by regression tests, and the repository-declared required gates pass. Non-blocking follow-ups: none. |
|
[REVIEW] GO 1. P0/P1 findingsnone I pressed hardest on one candidate before clearing it: the live-default test proves that applying a registered profile to the live default dir now refuses by default whenever that account holds a live door in its registered profile dir — which is every healthy registered profile. That is not a regression; it is the acceptance criterion itself. The husk mechanism named in the guard comment (one refresh token, two refresh sessions, loser blanked) arises precisely from the live-default-plus-profile-dir dual occupancy, the fleet's session model runs on profile dirs with The other candidate I attacked and cleared: restoring an account into its own registered dir after a husk. 2. Evidence table
3. Non-blocking P2/P3 follow-ups
4. Exact head and merge-tree statementReviewed head |
|
[REVIEW] GO Exact candidate identities
P0/P1 findingsnone Acceptance assessmentThe one-line production change replaces the caller's intent flag with the resolver's destination classification, and that is the correct predicate. The change is strictly widening — no supported path lost protection, and the paths that must still pass, still pass:
Direct-regression assessmentInstrument proven in both directions, measured on temp extractions of both trees (repo untouched):
Both new tests also assert the live credential bytes are unmodified after the refusal ( Non-blocking follow-ups
|
Task: b1bf2b66-2d90-4faf-851c-6ddb259033bc
Summary
Local verification
Required hosted gate
The station-local full bun test was interrupted under sustained machine contention and is incomplete, not passing. Do not begin adversarial review or merge until the hosted pull-request CI full matrix passes on this exact head SHA.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.