Repository navigation
fix: accept query token on dashboard settle POST (rebased, supersedes #27) - #45
Merged
Merged
Conversation
POST /api/approvals/:id discarded ?token= by authorizing against a placeholder URL with allowQuery false, so scripted clients got a 401 that looked like a wrong secret. Pass the real request URL and allow query tokens the same way GET routes do; header auth and sameOrigin still apply.
7 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Supersedes #27, which has been
CONFLICTINGagainstmainsince 2026-09-30.#27's branch (
dsh/dashboard-settle-query-token) is 1 commit ahead / 32 behindmain, and the conflict is a real one:maingrewgrantOwnAsk(run-scoped approval, #43) directly above theapprovedefinition the fix rewrites. Merging the stale branch as-is would need that resolved by hand anyway, so this branch is the same commit rebased onto3534097(v0.4.2) with the conflict resolved — nothing else changed.The change (unchanged from #27)
POST /api/approvals/:idnow receives the real request URL and passesallowQuery: true, so?token=works the same way the GET dashboard routes do.x-dashboard-tokenheader still wins when present.sameOriginstill rejects cross-origin browser POSTs — the state-changing route keeps both gates.CHANGELOG.mdgets the entry under[Unreleased] → Fixed, appended after the existing entries rather than opening a second### Fixedblock.The conflict resolution
Only
src/dashboard.tsandCHANGELOG.mdconflicted.src/dashboard.ts: keptmain'sgrantOwnAskverbatim, and replaced only the old one-lineapprovesignature plus itsauthorized(req, new URL('/', 'http://x'), false)body line with the fix's four-parameter signature andauthorized(req, url, true).CHANGELOG.md: keptmain's whole### Addedsection and appended the one newFixedbullet.Test plan
Run in this worktree on
3534097 + c82d674:node --experimental-strip-types --test test/*.test.ts— 819 pass, 0 fail, 1 skipped (820 tests)node --experimental-strip-types --test test/dashboard.test.ts— 40/40, includingPOST settle accepts ?token= without the header (KNOWN-ISSUES §5)npx tsc --noEmit— cleanbash .githooks/pre-commit --all—security scan ok (all)The live-model evidence from #27 (
docs/evidence/settle-query-token-live/) is carried over unchanged — it was measured against this same code, and the rebase did not touchapprove's behaviour.Once this lands, #27 and its branch can be closed and deleted.