Skip to content

docs: say that browser policies deny by default - #68

Merged
cardmagic merged 2 commits into
mainfrom
docs/browser-deny-by-default
Oct 8, 2026
Merged

cardmagic merged 2 commits into
mainfrom
docs/browser-deny-by-default

Conversation

@cardmagic

Copy link
Copy Markdown
Owner

Why

The consumer skill was evaluated against the v0.17.3 guide with a new set of 24 browser prompts. Two of the 16 suitable answers (both Claude Code) gave the browser install and worker setup with no authorization policy. Both had read that "a browser policy is not a security boundary" and dropped the deny-by-default rule. authorizeMessage defaults to () => false, so the worker those answers described would answer no call. Step 12 never said "deny by default" in plain words.

What changed

  • Install in step 12 now says that every authorization callback denies by default in the browser too. It points to the browser policy and to runtime.run(signal).
  • Authorize in the browser opens with the deny-by-default rule and the Unauthorized result, names the allowNoteDrafts policy in the example, and only then explains that the browser policy is not a security boundary.
  • Verify a browser implementation starts with a policy check.
  • New Chromium test, test/browser/deny-default.browser.ts: a browser worker with no authorization callbacks rejects actor calls with Unauthorized. With authorizeMessage: () => true the same test fails ("ok": true), so the test separates the two cases.
  • Version 0.17.4 and its changelog section.

Validation

pnpm run format:check, pnpm run check, pnpm run test:coverage (589 passed, 32 database skips), pnpm run build, pnpm run pack:check, pnpm run test:package, pnpm run test:recovery, pnpm run test:browser (13 passed), pnpm audit --audit-level=high (no known vulnerabilities).

In the browser evaluation, two of 16 agent answers gave the browser
install and worker setup with no authorization policy. Both read that a
browser policy is not a security boundary and dropped the deny-by-default
rule, so the worker they described would answer no call.

Step 12 now says plainly that every callback denies by default in the
browser too, the install step points to the policy and to
runtime.run(signal), and the checks start with the policy. A new Chromium
test proves that a worker with no callbacks rejects calls with
Unauthorized; with authorizeMessage set, the same test fails.
@context7

context7 Bot commented Oct 8, 2026

Copy link
Copy Markdown

Docs7 for cardmagic/solid-objects-js

Result Status Action
Deployment ➖ Not used —
Content review ✅ Passed. No problems found. View findings

Commit e61ff64

@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low impact] The PR appears safe to merge.

Summary

Clarifies that browser authorization denies calls by default, adds a Chromium test for rejected actor calls, and updates the release to 0.17.4.

  • The browser guidance matches the runtime’s defaults.
  • The new test checks for Unauthorized, not just any failure.
  • No actionable issues found. Tests were not run during this review.

Reviews (1) · Last reviewed commit: "chore: prepare version 0.17.4" · Reviewed by Greptile

@cardmagic
cardmagic merged commit 880515e into main Oct 8, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant