Skip to content

fix(fleet): keep local project APIs off peer sessions - #133

Merged
devswha merged 1 commit into
mainfrom
fix/fleet-local-api-boundaries
Sep 6, 2026
Merged

fix(fleet): keep local project APIs off peer sessions#133
devswha merged 1 commit into
mainfrom
fix/fleet-local-api-boundaries

Conversation

@devswha

@devswha devswha commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Selecting a peer project could read the hub's same-ID files and token usage, expose local Git/new-chat actions, or open an editor from an old file lookup after a host switch. Require both route and project locality, reject stale Git/file callbacks, discard late responses, and remove local editor access when its owning project is no longer selected. Peer token usage continues to come from host-qualified history.

Validation: two mounted regressions failed before the fix and passed afterward; npm run verify passed all gates with 2,382 repository tests (1,650 server, 50 real tmux/PTY, 682 client), plus Rust checks/tests. Chrome verified peer → local → peer palette transitions with simulated responses: no hub requests or local file/Git rows on peers, existing local behavior preserved. This is component browser evidence, not release-grade CUA.

Reproduction steps and screenshots: docs/evidence/issue131/README.md; runnable fixture: scripts/cua/fleet-local-api-fixture.html.

Refs #131 (local-only API guards; follow-tail coverage already exists through #99). The preserved branch is not merged wholesale, and the remaining behavior groups are reviewed separately.

@devswha
devswha merged commit 6e1a2b5 into main Sep 6, 2026
5 checks passed
@devswha
devswha deleted the fix/fleet-local-api-boundaries branch September 6, 2026 14:33
devswha added a commit that referenced this pull request Sep 6, 2026
#136)

OpenCode's session watcher traversed unrelated cache subtrees even
though its synchronizer only accepts `opencode.db`. Retain the parent
directory to observe database creation and replacement, but limit
traversal to depth zero and ignore every path except that root and its
database. The historical direct-file-only approach missed a
removal/replacement case in a real filesystem regression, so it is not
copied verbatim. Other providers keep their existing recursive watch
options.

Validation: the 20-test filesystem/watcher/indexing group, type checks,
and lint pass. Tests cover an existing or initially absent database,
changes, deletion and recreation, excluded nested caches, and unchanged
non-OpenCode options.

`docs/evidence/issue131/review.md` records a disposition for all
thirteen preserved commits and all six review groups, including
already-shipped work, corrections in #133/#134/#135, and proposals
intentionally not carried forward under the current Fleet contract.
Merge after #134 and #135, with required checks rerun on that latest
main. The preserved historical branch remains available.

Closes #131.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant