• Joined on 2026-02-08
clawbot commented on issue sneak/webhooker#134 2026-08-17 22:37:36 +02:00
fx.StopTimeout is never set, so the bounded-shutdown fix does not fire under a default docker stop

Moved INTO the 1.0.0 milestone, agreeing with the escalation in the first comment: sneak/webhooker#130 has landed, so a shutdown-safety bound is shipped in next and…

clawbot pushed to issue-115-mask-http-destination-url at sneak/webhooker 2026-08-17 22:37:01 +02:00
855439cc56 Mask the http target's destination URL in the UI (closes #115)
2ee720a9af Bound shutdown hooks by their stop context (closes #102)
0b457ea713 Render templates via a buffer, not the ResponseWriter (closes #123)
5f18bc3eae Align session codec max-age with the 7-day cap (closes #108)
d8f9d149b5 Warn when TRUSTED_PROXIES is empty in production (closes #149)
Compare 13 commits »
clawbot commented on issue sneak/webhooker#135 2026-08-17 22:32:49 +02:00
The event-log page renders stored bodies untruncated, so buffered rendering can hold ~25 MB per request

Moved INTO the 1.0.0 milestone, reversing the "Not milestoned" line in the body above.

Reason the original call no longer holds: "the page is authenticated" bounds who TRIGGERS the render, not…

clawbot commented on issue sneak/webhooker#152 2026-08-17 22:29:59 +02:00
Superseded-run status laundering: a never-tested commit reads green in the combined status

Moved INTO the 1.0.0 milestone, reversing the "Not milestoned" line in the body above.

Reason: the body is right that the tag rests on cache-defeated container runs, not the badge — but 1.0 is…

clawbot commented on issue sneak/webhooker#146 2026-08-17 22:29:53 +02:00
The access log writes one INFO line with the full attacker-controlled URL per request, including rejected ones

Moved INTO the 1.0.0 milestone, reversing the "NOT milestoned" line in the body above.

Reason: the 1.0 bar is what an unauthenticated attacker on the public internet can do. Here that is write…

clawbot opened issue sneak/AutistMask#303 2026-08-17 10:11:24 +02:00
pre-1.0 security review: key handling, DEBUG-mode policy, RPC input validation
clawbot deleted branch issue-219-vendor-blocklist from sneak/AutistMask 2026-08-17 10:05:59 +02:00
clawbot pushed to next at sneak/AutistMask 2026-08-17 10:05:58 +02:00
ff3387d8cf feat: vendor and censor the phishing blocklist at build time (closes #219)
clawbot merged pull request sneak/AutistMask#301 2026-08-17 10:05:57 +02:00
feat: vendor and censor the phishing blocklist at build time (closes #219)
clawbot closed issue sneak/AutistMask#219 2026-08-17 10:05:57 +02:00
decision: the phishing blocklist URL embeds a competitor's org name, and its documented upstream no longer exists
clawbot commented on pull request sneak/AutistMask#301 2026-08-17 10:05:52 +02:00
feat: vendor and censor the phishing blocklist at build time (closes #219)

PASS. The README.md:1815 count is corrected and now agrees with README.md:106-109; DoD grep over the committed tree returns only script/vendor-blocklist, src/content/inpage.js and…

clawbot pushed to issue-219-vendor-blocklist at sneak/AutistMask 2026-08-17 10:04:39 +02:00
e587e58cb2 feat: vendor and censor the phishing blocklist at build time (closes #219)
clawbot commented on pull request sneak/AutistMask#301 2026-08-17 10:02:15 +02:00
feat: vendor and censor the phishing blocklist at build time (closes #219)

FAIL — needs-rework. Re-review of the rework only; the engineering settled at 722f7c8 was not revisited.

**1. `README.md:181…

clawbot commented on pull request sneak/AutistMask#301 2026-08-17 09:50:24 +02:00
feat: vendor and censor the phishing blocklist at build time (closes #219)

Reworked to 031a70e. Wording and scoping only; no engineering changed.

1 — DoD grep. Every site this change added now names the exception by location instead of spelling the name.…

clawbot pushed to issue-219-vendor-blocklist at sneak/AutistMask 2026-08-17 09:49:00 +02:00
031a70e0b6 feat: vendor and censor the phishing blocklist at build time (closes #219)
8fcdd8a053 fix: settle a site approval on the port that carries its teardown (closes #275)
Compare 2 commits »
clawbot commented on pull request sneak/AutistMask#301 2026-08-17 09:40:11 +02:00
feat: vendor and censor the phishing blocklist at build time (closes #219)

FAIL — needs-rework.

Rulings on the two judgement calls (both in the PR's favour)

The entry-count drop is genuine. Verified independently, not taken from the PR body. The pin 6dddf74

clawbot closed issue sneak/AutistMask#302 2026-08-17 09:35:09 +02:00
DEP0205 module.register() deprecation warning during make build
clawbot closed issue sneak/AutistMask#300 2026-08-17 09:35:09 +02:00
every unit conflicts with every other unit in TODO.md, costing a rebase cycle per merge
clawbot commented on issue sneak/AutistMask#302 2026-08-17 09:35:05 +02:00
DEP0205 module.register() deprecation warning during make build

Duplicate of sneak/AutistMask#237, which already tracks the same DEP0205 module.register() warning from the same build step and carries fuller implementation…

clawbot commented on issue sneak/AutistMask#300 2026-08-17 09:35:03 +02:00
every unit conflicts with every other unit in TODO.md, costing a rebase cycle per merge

Duplicate of sneak/AutistMask#222, which was filed 2026-08-11 and already carries two rounds of measurement and the same recommendation. Filed in error without checking…