Skip to content

fix(session-bridge): harden the view-bridge watcher, token and local-user defences #6109

Description

@kyle-sexton

Context

Found in the review of #6094 (feat(session-bridge): claude-interactive triage board and plan view). Found while delivering spec container #5835. All items are hardening; none is exploitable beyond the stated limits.

Problem

  1. An orphaned watch.sh after a session crash loops on timeouts and keeps the view-bridge server and its token alive.
  2. The page and the watcher share one token, so page script could call /api/wait or release the lease (denial of service only).
  3. Sec-Fetch-Site is a browser-only defence; it does not stop other local OS users.
  4. json.dumps(ensure_ascii=False) passes U+2028 raw into the watcher line (cosmetic).

Suggested fix

  1. Add a parent-liveness check to watch.sh so it exits when the owning session is gone, which lets the server and token expire.
  2. Use separate tokens (or scopes) for the page and the watcher.
  3. Document the local-user limit, or bind the listener with a per-user credential.
  4. Escape U+2028 and U+2029 in the watcher line.

Related: #5835

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: lowNice-to-have, cosmetic, or speculative; opportunistic.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions