Commit 2ff0e02
committed
fix: apply tool policy before PTC bridge creation
The sandbox bridge was built from allTools before applyToolPolicy ran,
so the mux.* API inside code_execution ignored allow/deny filters.
Now the policy is applied first, and policyFilteredTools is passed to
ToolBridge, ensuring the sandbox only exposes policy-allowed tools.1 parent 6edb774 commit 2ff0e02
File tree
2 files changed
+18
-11
lines changed- src
- browser/utils/messages
- node/services
2 files changed
+18
-11
lines changedLines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
653 | 653 | | |
654 | 654 | | |
655 | 655 | | |
| 656 | + | |
656 | 657 | | |
657 | 658 | | |
658 | 659 | | |
| |||
707 | 708 | | |
708 | 709 | | |
709 | 710 | | |
| 711 | + | |
710 | 712 | | |
711 | 713 | | |
712 | 714 | | |
| |||
766 | 768 | | |
767 | 769 | | |
768 | 770 | | |
| 771 | + | |
769 | 772 | | |
770 | 773 | | |
771 | 774 | | |
| |||
853 | 856 | | |
854 | 857 | | |
855 | 858 | | |
| 859 | + | |
856 | 860 | | |
857 | 861 | | |
858 | 862 | | |
| |||
884 | 888 | | |
885 | 889 | | |
886 | 890 | | |
| 891 | + | |
887 | 892 | | |
888 | 893 | | |
889 | 894 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1279 | 1279 | | |
1280 | 1280 | | |
1281 | 1281 | | |
| 1282 | + | |
| 1283 | + | |
| 1284 | + | |
| 1285 | + | |
| 1286 | + | |
1282 | 1287 | | |
1283 | | - | |
| 1288 | + | |
1284 | 1289 | | |
1285 | 1290 | | |
1286 | 1291 | | |
| |||
1295 | 1300 | | |
1296 | 1301 | | |
1297 | 1302 | | |
1298 | | - | |
1299 | | - | |
| 1303 | + | |
| 1304 | + | |
1300 | 1305 | | |
1301 | 1306 | | |
1302 | 1307 | | |
| |||
1310 | 1315 | | |
1311 | 1316 | | |
1312 | 1317 | | |
1313 | | - | |
| 1318 | + | |
1314 | 1319 | | |
1315 | | - | |
| 1320 | + | |
1316 | 1321 | | |
1317 | | - | |
1318 | | - | |
| 1322 | + | |
| 1323 | + | |
1319 | 1324 | | |
1320 | 1325 | | |
1321 | | - | |
| 1326 | + | |
1322 | 1327 | | |
1323 | 1328 | | |
1324 | 1329 | | |
1325 | 1330 | | |
1326 | | - | |
1327 | | - | |
1328 | | - | |
1329 | 1331 | | |
1330 | 1332 | | |
1331 | 1333 | | |
| |||
0 commit comments