Harden maintainer-preview harness and review fixes

Unify conversational domain routing, preserve artifact completion evidence, replace provisional tool-round prose with terminal synthesis, and resolve verified maintainer review findings across search, frontend module identity, path policy, configuration, and built-in skill startup.
This commit is contained in:
pewdiepie-archdaemon
2026-09-21 06:54:03 +00:00
parent d7cad0621f
commit 297ad19248
54 changed files with 1223 additions and 110 deletions
+5
View File
@@ -338,3 +338,8 @@ async def test_write_file_dispatch_blocks_cron(monkeypatch):
)
assert "outside the allowed roots" in (result.get("error") or "")
assert result.get("exit_code") == 1
@pytest.mark.parametrize("filename", ["auth.json", "app.db", "settings.json"])
def test_application_secrets_are_sensitive_paths(filename):
from src.tool_execution import _is_sensitive_path
assert _is_sensitive_path(f"/tmp/odysseus-data/{filename}")