fix(routing): seal explicit workspace media workflows

This commit is contained in:
pewdiepie-archdaemon
2026-09-18 13:55:02 +00:00
parent cb03070690
commit e80b85fcab
2 changed files with 83 additions and 0 deletions
+50
View File
@@ -4150,6 +4150,56 @@ def requested_capabilities(message: str, history: Iterable = (), *, active_docum
text = lead["request"].strip()
history = tuple(history)
concrete_urls = re.findall(r"\bhttps?://[^\s<>\"']+", raw_text, re.I)
workspace_media = re.search(
r"(?:file://)?/workspace/[^\s`\"']+\."
r"(?:avif|bmp|gif|jpe?g|png|svg|tiff?|webp|mp3|m4a|ogg|wav|flac|"
r"aac|mp4|m4v|mov|mkv|avi|webm)\b",
raw_text,
re.I,
)
media_action = re.search(
r"\b(?:inspect|view|study|look\s+at|analy[sz]e|read|transcribe|caption|"
r"recreate|reproduce|identify|describe|extract)\b",
raw_text,
re.I,
)
if workspace_media and media_action:
# A concrete media asset owns score "notes", timestamp ranges, and
# other content nouns. Those details must not authorize unrelated
# personal Notes or Calendar products. Preserve only explicit
# downstream artifact/browser work and deliberate personal-note
# mutations.
if re.search(r"\bOCR\b|\bextract\b[^.\n]{0,80}\b(?:exact\s+)?(?:visible\s+)?text\b", raw_text, re.I):
primary_media_family = "ocr"
elif re.search(r"\b(?:transcribe|transcription|captions?|subtitles?)\b", raw_text, re.I):
primary_media_family = "transcription"
else:
primary_media_family = "media_inspection"
families = {primary_media_family}
if (
re.search(r"\b(?:create|write|save|build|implement|produce|recreate|reproduce)\b", raw_text, re.I)
and re.search(
r"(?:file://)?/workspace/[^\s`\"']+\.(?:csv|html?|json|md|svg|txt)\b",
raw_text,
re.I,
)
):
families.add("shell_files")
if re.search(
r"\b(?:preview|render|open|inspect|verify)\b[^.\n]{0,120}"
r"\b(?:page|html|browser|rendered\s+result)\b",
raw_text,
re.I,
):
families.add("search_browser")
if re.search(
r"\b(?:create|add|write|save)\b[^.;\n]{0,80}\b(?:a\s+)?note\b"
r"[^.;\n]{0,80}\b(?:my\s+)?notes\b",
raw_text,
re.I,
):
families.add("notes")
return frozenset(families)
if (
broad_web_briefing_request(text)
and not re.search(r"\b(?:research|investigate|deep[ -]?dive)\b", text, re.I)
+33
View File
@@ -4253,3 +4253,36 @@ def test_recurring_calendar_event_remains_calendar():
assert requested_capabilities(
"Create a recurring calendar event every Monday morning for the team meeting."
) == {"calendar"}
@pytest.mark.parametrize(
("message", "expected"),
[
(
"Inspect /workspace/input/reference.png, recreate all musical notes in "
"/workspace/output.html, then preview the page in a browser.",
{"media_inspection", "shell_files", "search_browser"},
),
(
"First view /workspace/input/reference.png, recreate the piano score with "
"correct noteheads in /workspace/output.html, and inspect the rendered result.",
{"media_inspection", "shell_files", "search_browser"},
),
(
"Transcribe every distinct caption in /workspace/input/video.mp4 from "
"00:04 through 00:12 and return only the words.",
{"transcription"},
),
],
)
def test_explicit_workspace_media_workflow_owns_content_nouns_and_timestamps(
message, expected
):
assert requested_capabilities(message) == expected
def test_explicit_personal_note_action_survives_media_workflow_sealing():
assert requested_capabilities(
"Inspect /workspace/input/score.png, then save a note in my notes called "
"Practice Review with the musical details."
) == {"media_inspection", "notes"}