Skip to content

Qualify private provider auth recording and export boundaries - #1484

Merged
piclaw-bot merged 1 commit into
mainfrom
audit/1458-auth-trace-boundaries
Oct 1, 2026
Merged

piclaw-bot merged 1 commit into
mainfrom
audit/1458-auth-trace-boundaries

Conversation

@piclaw-bot

Copy link
Copy Markdown
Collaborator

Provider-auth recording qualification

Extend the existing real Chromium/WebKit callback/public-runtime authentication matrix through production message-storage, timeline recording and SSE recording seams. Each of eight success/denial-retry/cancel/expiry flows now checks full-mode persisted JSONL, persisted-timeline snapshots and real JSON/JSONL/HTML export handlers.

Checks

  • Full mode disables redaction: every written timeline row ID must be recorded, and private provider/input/token sentinel must remain absent.
  • A public fixture-note control survives the raw file and live exports. Every export is parsed and its exact timeline row IDs checked; metadata-only exports cannot pass.
  • Snapshot start uses the real route and persisted timeline. Export responses retain Cache-Control: no-store.
  • Explicit in-memory DB, serial cases, unique chats, finally row deletion and owned recording/profile cleanup.

Validation

  • Chromium/WebKit: 8 passed / 480 assertions.
  • Independent review findings fixed and re-reviewed with no blockers.
  • Scoped strict typing, Oxlint, silent-swallow, environment and diff checks pass.
  • Canonical gate: 5,972 passed / 8 existing or opt-in skips / 0 failures, plus 25 feature tests and 9 web checks. Browser matrix executed separately.
  • Pack hygiene: 24,742 files. All five typechecks pass; compose retains 95 unchanged baseline diagnostics. Private Bun cache, no shared-cache permission changes.

Scope

No production behaviour or redaction-policy changes. Synthetic provider/test HTTP adapter only; production authentication middleware, historical cards/recordings/backups, arbitrary pasted secrets/tool output, external OTel exporters, live providers, Delegate parity and native MCP acceptance are unqualified. No live credentials/history read, inference, deployment or restart. #1442/#1458 stay open.

Initial wrong broadcaster factory import failed at module load and was corrected. Broad standalone fixture typing needed existing repository ambient declarations, which are now included in its strict check.

Refs #1458.

@piclaw-bot
piclaw-bot merged commit 53b9c52 into main Oct 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants