Skip to content

Test validation abstention for deployment-only context - #11

Open
mvidoc wants to merge 5 commits into
mainfrom
e2e-validation-abstention-context-question
Open

Test validation abstention for deployment-only context#11
mvidoc wants to merge 5 commits into
mainfrom
e2e-validation-abstention-context-question

Conversation

@mvidoc

@mvidoc mvidoc commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a support diagnostics route that executes caller-provided shell input
  • document that authentication and reachability are controlled by deployment gateway policy outside this repository
  • exercise Vidoc's unknown/abstain question flow when repository evidence cannot establish the trust boundary

Test plan

  • Vidoc detects the shell execution risk
  • validation abstains because gateway policy is unavailable
  • Vidoc posts a context question on this PR
  • reply to the question and verify successor validation

Made with Cursor

Expose a shell-backed support route whose trust boundary depends on deployment-only gateway policy, exercising validation abstention.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vidoc-local

vidoc-local Bot commented Jul 29, 2026

Copy link
Copy Markdown

Vidoc security review

Tip

Good to merge — no security issues found. Reviewed 1 changed file.

💬 Have questions? Tag @vidoc-local in a comment and I'll answer.

Make the missing deployment policy explicit so the validation workflow must request context before deciding exploitability.

Co-authored-by: Cursor <cursoragent@cursor.com>
Comment thread main.ts Outdated
Make path safety depend on gateway behavior that repository validation cannot verify, exercising the context-question flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
Comment thread main.ts Outdated
@mvidoc mvidoc closed this Jul 29, 2026
@mvidoc mvidoc reopened this Jul 29, 2026
Clarify that the deployment contract remains intentionally unresolved for the end-to-end question lifecycle fixture.

Co-authored-by: Cursor <cursoragent@cursor.com>
Comment thread main.ts Outdated
Use a distinct SSRF fixture so the corrected question lifecycle can be exercised with a fresh issue lineage.

Co-authored-by: Cursor <cursoragent@cursor.com>
Comment thread main.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant