hub-safety session: R-135/R-133/R-604/R-530/R-508/R-509/R-880 closed, R-861/R-173/R-518/R-519 narrowed, R-879/R-881 opened (336 → 332); 03 §3.1, 05 §16, golden 0.296.0, the hub-DB off-site plan, STATUS
gates / gates (push) Successful in 32s
gates / gates (push) Successful in 32s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -882,7 +882,7 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
|
||||
// does NOT prove the request is programmatic. A page on another site can make the browser POST a
|
||||
// form with the operator's cached Basic credentials; it cannot add a custom header (that needs a
|
||||
// CORS preflight, which the hub never answers). So the header is the proof the old check assumed.
|
||||
// Decided by CC — operator may reverse (`05` §8.1). Pinned by r135_csrf_test.go.
|
||||
// Decided by CC — operator may reverse (`05` §16.1). Pinned by r135_csrf_test.go.
|
||||
const OperatorCLIHeader = "X-Felhom-Operator"
|
||||
|
||||
// validateCSRF checks a state-changing request (R-135). Two ways pass, nothing else:
|
||||
|
||||
Reference in New Issue
Block a user