Compare commits

..

1 Commits

Author SHA1 Message Date
hongjr03 63c86322de fix: preserve run provider capability 2026-07-11 15:00:34 +08:00
5 changed files with 8 additions and 17 deletions
+2 -2
View File
@@ -1,12 +1,12 @@
{
"name": "@paradigm/hub",
"version": "0.0.17",
"version": "0.0.18",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "@paradigm/hub",
"version": "0.0.17",
"version": "0.0.18",
"dependencies": {
"@anthropic-ai/claude-agent-sdk": "^0.3.202",
"@fastify/cookie": "^11.0.2",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@paradigm/hub",
"version": "0.0.17",
"version": "0.0.18",
"private": true,
"type": "module",
"engines": {
+3 -6
View File
@@ -23,11 +23,6 @@ const SAFE_HOST_ENV_KEYS = [
"CPH_BIN",
] as const;
const SANDBOX_HIDDEN_ENV_KEYS = [
"ANTHROPIC_AUTH_TOKEN",
"ANTHROPIC_API_KEY",
] as const;
// Linux sockaddr_un.sun_path is 108 bytes including the terminator. Claude's
// sandbox appends its own user directory and randomized bridge socket names,
// so keep our prefix well below that hard limit.
@@ -156,7 +151,9 @@ export async function createAgentSecurityPolicy(input: AgentSecurityInput): Prom
},
credentials: {
files: sensitiveReadPaths.map((path) => ({ path, mode: "deny" as const })),
envVars: SANDBOX_HIDDEN_ENV_KEYS.map((name) => ({ name, mode: "deny" as const })),
// These values are short-lived loopback capabilities, not Organization
// provider secrets. Denying them also strips Claude's own request auth.
envVars: [],
},
},
};
+1 -4
View File
@@ -66,10 +66,7 @@ describe("agent subprocess security policy", () => {
allowRead: expect.arrayContaining([canonicalWorkspace, "/usr/bin"]),
},
credentials: {
envVars: expect.arrayContaining([
{ name: "ANTHROPIC_AUTH_TOKEN", mode: "deny" },
{ name: "ANTHROPIC_API_KEY", mode: "deny" },
]),
envVars: [],
},
});
});
+1 -4
View File
@@ -288,10 +288,7 @@ describe("runAgent", () => {
},
sandbox: {
credentials: {
envVars: expect.arrayContaining([
{ name: "ANTHROPIC_AUTH_TOKEN", mode: "deny" },
{ name: "ANTHROPIC_API_KEY", mode: "deny" },
]),
envVars: [],
},
},
},