Repository navigation
docs: say that browser policies deny by default - #68
Merged
Merged
Conversation
In the browser evaluation, two of 16 agent answers gave the browser install and worker setup with no authorization policy. Both read that a browser policy is not a security boundary and dropped the deny-by-default rule, so the worker they described would answer no call. Step 12 now says plainly that every callback denies by default in the browser too, the install step points to the policy and to runtime.run(signal), and the checks start with the policy. A new Chromium test proves that a worker with no callbacks rejects calls with Unauthorized; with authorizeMessage set, the same test fails.
|
Docs7 for cardmagic/solid-objects-js
Commit |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The consumer skill was evaluated against the v0.17.3 guide with a new set of 24 browser prompts. Two of the 16 suitable answers (both Claude Code) gave the browser install and worker setup with no authorization policy. Both had read that "a browser policy is not a security boundary" and dropped the deny-by-default rule.
authorizeMessagedefaults to() => false, so the worker those answers described would answer no call. Step 12 never said "deny by default" in plain words.What changed
runtime.run(signal).Unauthorizedresult, names theallowNoteDraftspolicy in the example, and only then explains that the browser policy is not a security boundary.test/browser/deny-default.browser.ts: a browser worker with no authorization callbacks rejects actor calls withUnauthorized. WithauthorizeMessage: () => truethe same test fails ("ok": true), so the test separates the two cases.Validation
pnpm run format:check,pnpm run check,pnpm run test:coverage(589 passed, 32 database skips),pnpm run build,pnpm run pack:check,pnpm run test:package,pnpm run test:recovery,pnpm run test:browser(13 passed),pnpm audit --audit-level=high(no known vulnerabilities).