hub v0.126.0: fresh connect link from the old one (R-719); day-one mails (R-723); bind-page wording (R-725); volunteer guide current (R-722); ep0 cleanup and release evidence
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Red-proofs RP40-RP42. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -83,6 +83,11 @@ func TestBindExpiredIsAlwaysDefaultLanguage(t *testing.T) {
|
||||
// A token that was never real.
|
||||
unknown := getBind(t, s, "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa")
|
||||
|
||||
// v0.126.0 (R-719): the expired page echoes the visitor's OWN token into its „Új linket kérek" form. The
|
||||
// visitor already holds that token (it is the URL they opened), so it discloses nothing; every OTHER
|
||||
// byte must still be identical, which is what the comparison below keeps asserting.
|
||||
realExpired = strings.ReplaceAll(realExpired, expiredTok, "<token>")
|
||||
unknown = strings.ReplaceAll(unknown, "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa", "<token>")
|
||||
if realExpired != unknown {
|
||||
t.Errorf("an expired REAL token and an unknown token render differently — the page is an "+
|
||||
"oracle for whether a link existed.\n--- real ---\n%s\n--- unknown ---\n%s", realExpired, unknown)
|
||||
|
||||
Reference in New Issue
Block a user