Commit Graph

5 Commits

Author SHA1 Message Date
Teknium 5aa9e7f033 fix(vault): independent-review findings — vendor contracts, profile scope, transport, target binding
Bitwarden unlock now uses the CLI's documented non-interactive channel:
`bw unlock --raw --nointeraction --passwordenv VAR`, VAR set on the child
environment only (bw 2026.x rejects a piped password with "Master password
is required"). Verified against the real published binary.

Manager session tokens are keyed by (profile home, backend): a Desktop
gateway hosting several profiles can no longer reuse or lock another
profile's session. Status probes (`vault.sources`, is_unlocked) no longer
refresh the idle TTL; only real manager calls do. Gateway session teardown
locks the profile's managers (a per-session unlock ends with the session).

1Password service-account token comes from the profile-scoped secret store
(get_secret), not ambient os.environ.

`vault.source.set` no longer references a module constant (bind_module
rebinding dropped it → NameError on every Settings toggle).

Fill target binding: inspection stamps each input with a per-inspection
slot attribute; the fill resolves by stamp and requires type=password, then
strips every stamp. A DOM reflow between inspect and fill can no longer
redirect the password into a text field (reproduced in real Chrome before,
0 filled after).

Redaction boundary: no 4-char floor, CR/LF-normalized form registered
(what a text input actually stores), JSON object KEYS scrubbed in both
browser redactors; longest value first. Docs now state the real trust
model: accidental-disclosure protection, not an execution sandbox.

Desktop: the mid-turn card sends the master password through the owning
session's socket (requestForOwnedSession), never the ambient foreground
gateway; `vault.unlock.expire` clears a stale card; Settings keeps the
master password out of react-query mutation variables (ref consumed by the
mutationFn). One renderer invariant test for the routing.
2026-09-10 10:35:07 -07:00
JonthanaHanh d78cdd7119 fix(tools): truncation footers name the path the SANDBOX sees, not the host path (#72389, #81984, #77015)
web_extract / browser_snapshot / delegate_task spill their full text under HERMES_HOME/cache,
which is mounted read-only into docker/modal (at /root/.hermes) and synced under ~/.hermes for
ssh/daytona/vercel — but the footer told the agent the HOST path, so read_file inside the
sandbox got 'File not found'. Translate through the existing
credential_files.to_agent_visible_cache_path (what tool_result_storage already does); local and
singularity are unchanged.

Salvaged from #72429 by @JonthanaHanh (the web_extract sites), widened to every footer.
2026-09-05 18:46:16 +05:30
Teknium de60f789a7 simplify(compat): tools/browser_tool + browser_supervisor — drop 114 re-exports + 6 legacy aliases + PEP 562 requests/call_llm hook, repoint 21 non-test callers; siblings read sibling names directly 2026-09-03 14:16:54 -07:00
Teknium d3523096fa refactor(tools): browser_tool — origin proxy replaces per-call _bt lookups, unified JSON/error builders, cached-config helper, dead shim removal 2026-09-02 22:39:28 -07:00
Teknium 9f6335bc44 refactor(tools/browser): extract eval-policy/lightpanda-fallback/real-profile/snapshot modules from browser_tool; split supervisor dialogs/frames; dedupe camofox/cli 2026-09-02 14:44:15 -07:00