You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: authorize a pruned key like the message it replaces
Greptile found a real disclosure. The pruned answer ran
`authorize_query` against the synthetic `__snapshot__` operation, while a
lookup whose row survives runs the hook for the stored operation. A
caller allowed to read state but denied the operation could therefore
tell `MessagePruned` from nil and learn that the operation had run.
`snapshot` does not expose the remembered keys, so the gate granted more
than the thing it borrowed.
An actor now remembers the operation beside each key, and the pruned
answer runs the same hook against the same operation a surviving row
would. Without that the new test raises
`SolidObjects::MessagePruned` where it expects nil.
`authorized_to_invoke?` carries the check both paths share, and
`authorized_to_read?` passes a message to it.
Validation: bundle exec rake (795 runs, 0 failures).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
0 commit comments