Revert "fix: preserve run provider capability"

This reverts commit 63c86322de.
This commit is contained in:
2026-07-11 15:06:48 +08:00
parent 2ee84d9543
commit 12a2f3117f
5 changed files with 17 additions and 8 deletions
+2 -2
View File
@@ -1,12 +1,12 @@
{ {
"name": "@paradigm/hub", "name": "@paradigm/hub",
"version": "0.0.18", "version": "0.0.17",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "@paradigm/hub", "name": "@paradigm/hub",
"version": "0.0.18", "version": "0.0.17",
"dependencies": { "dependencies": {
"@anthropic-ai/claude-agent-sdk": "^0.3.202", "@anthropic-ai/claude-agent-sdk": "^0.3.202",
"@fastify/cookie": "^11.0.2", "@fastify/cookie": "^11.0.2",
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "@paradigm/hub", "name": "@paradigm/hub",
"version": "0.0.18", "version": "0.0.17",
"private": true, "private": true,
"type": "module", "type": "module",
"engines": { "engines": {
+6 -3
View File
@@ -23,6 +23,11 @@ const SAFE_HOST_ENV_KEYS = [
"CPH_BIN", "CPH_BIN",
] as const; ] as const;
const SANDBOX_HIDDEN_ENV_KEYS = [
"ANTHROPIC_AUTH_TOKEN",
"ANTHROPIC_API_KEY",
] as const;
// Linux sockaddr_un.sun_path is 108 bytes including the terminator. Claude's // Linux sockaddr_un.sun_path is 108 bytes including the terminator. Claude's
// sandbox appends its own user directory and randomized bridge socket names, // sandbox appends its own user directory and randomized bridge socket names,
// so keep our prefix well below that hard limit. // so keep our prefix well below that hard limit.
@@ -151,9 +156,7 @@ export async function createAgentSecurityPolicy(input: AgentSecurityInput): Prom
}, },
credentials: { credentials: {
files: sensitiveReadPaths.map((path) => ({ path, mode: "deny" as const })), files: sensitiveReadPaths.map((path) => ({ path, mode: "deny" as const })),
// These values are short-lived loopback capabilities, not Organization envVars: SANDBOX_HIDDEN_ENV_KEYS.map((name) => ({ name, mode: "deny" as const })),
// provider secrets. Denying them also strips Claude's own request auth.
envVars: [],
}, },
}, },
}; };
+4 -1
View File
@@ -66,7 +66,10 @@ describe("agent subprocess security policy", () => {
allowRead: expect.arrayContaining([canonicalWorkspace, "/usr/bin"]), allowRead: expect.arrayContaining([canonicalWorkspace, "/usr/bin"]),
}, },
credentials: { credentials: {
envVars: [], envVars: expect.arrayContaining([
{ name: "ANTHROPIC_AUTH_TOKEN", mode: "deny" },
{ name: "ANTHROPIC_API_KEY", mode: "deny" },
]),
}, },
}); });
}); });
+4 -1
View File
@@ -288,7 +288,10 @@ describe("runAgent", () => {
}, },
sandbox: { sandbox: {
credentials: { credentials: {
envVars: [], envVars: expect.arrayContaining([
{ name: "ANTHROPIC_AUTH_TOKEN", mode: "deny" },
{ name: "ANTHROPIC_API_KEY", mode: "deny" },
]),
}, },
}, },
}, },