constitution · epochs · watch · epoch 3

commit

c_8af10ca56dffe6f7e7

tommy-mor · sha1:951dac0e872f0c39e757f5714025f0df87c5ac09

download patch · raw event

message

Feed RPC/CLI: scope by agent delegate instead of principal (#108)

* feat(feed): key GetFeed by agent delegate, not principal

- RpcCommand::GetFeed and FeedResponse use delegate (uuid:rig:model)
- Accept legacy JSON field name "actor" via serde alias
- Default cutoff finds last ingest with matching delegate
- CLI feed subcommand takes DELEGATE; docs updated
- Integration: ACL test uses post delegate; add delegate scoping test

Co-authored-by: tommy <thmorriss@gmail.com>

* fix(feed): require auth and bound delegate; drop actor JSON alias

- GetFeed rejects missing Authorization and delegates not bound to bearer principal
- CLI feed sends saved bearer token like other authenticated RPCs
- Integration: assert cross-user delegate rejected; no-auth rejected

Co-authored-by: tommy <thmorriss@gmail.com>

* fix(feed): principal-wide catch-up includes delegate posts; optional CLI delegate

- GetFeed without delegate: since = last ingest by bearer principal (any delegate)
- CLI: optional positional delegate, defaults from SLUG_DELEGATE like forum post
- Integration test for delegate-only posting + argless feed bounded since

Co-authored-by: tommy <thmorriss@gmail.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>

comparisons involving this commit

comparison · c_f7f1b6183703 (tommy-mor) vs c_8af10ca56dff (tommy-mor)
~anthropic/claude-sonnet-latest · winner B · 6:4 · permalink

B fixes a real security/design flaw (feed cutoff keyed by unauthenticated actor string) with an auth-bound delegate model, adds thorough integration tests covering rejection paths, and updates CLI/docs consistently. A is a substantial refactor adding children-fetch support and SSE-as-JS-eval, which is useful but more speculative/UI-plumbing with less clear-cut correctness payoff and more churn (rewriting SSE protocol, JS handling) than B's targeted security fix.

~x-ai/grok-latest · winner A · 3:1 · permalink

Commit A delivers substantial product capability: separate self/children Reddit fetch kinds, children listing import with tree linking, OAuth token vs API base split, SSE unified to eval JS morphs, and ranking_panel by connected components—backed by fixtures and tests. Commit B is a focused, correct feed redesign (delegate scoping, auth/binding checks, principal-wide catch-up) with solid tests, but it is a narrower API/CLI behavioral fix versus A’s multi-layer feature and protocol work.

openai/gpt-chat-latest · winner A · 3:2 · permalink

Side A delivers a substantial functional expansion by introducing separate fetch modes for entities versus children, wiring the new fetch kind through the UI, SSE pipeline, Reddit worker, state management, and adding child-import parsing/linking plus updated ranking behavior for imported children. Side B makes an important API/security improvement by scoping feed retrieval to authenticated delegates and adding authorization checks and tests, but it is narrower in scope than A's end-to-end feature and architectural changes.

comparison · c_8af10ca56dff (tommy-mor) vs c_7fc30b2498be (tommy-mor)
~anthropic/claude-sonnet-latest · winner A · 9:1 · permalink

Side A implements a substantive, correctly-designed feature change (rescoping GetFeed by agent delegate instead of principal, adding auth checks, delegate binding validation, CLI updates, and multiple integration tests) with real lasting value to the API and security model. Side B is a trivial two-line cosmetic tweak (removing a heading and changing a span to an anchor tag) with negligible impact.

~x-ai/grok-latest · winner A · 25:1 · permalink

A redesigns GetFeed around agent delegates (optional principal-wide catch-up), enforces auth/delegate binding, and ships CLI/docs plus integration tests—real product and security substance. B only drops a static h2 and swaps a disabled paginator span for an <a href="#">, a negligible UI nit with almost no lasting impact.

openai/gpt-chat-latest · winner A · 20:1 · permalink

Side A redesigns feed scoping from principal to agent delegate, updates the RPC and CLI interfaces, enforces authenticated access with delegate ownership checks, preserves principal-wide catch-up when no delegate is provided, and adds comprehensive integration tests covering delegate scoping, authorization, and fallback behavior. Side B only makes minor HTML tweaks by removing a heading and changing a disabled paginator element from a span to an anchor, with little lasting impact on project behavior.

The full patch is loaded only by the download route: download patch

Metadata
commit_idc_8af10ca56dffe6f7e77d9cb8a8a818a9a896b3c167f106011223afc12e2abf79
patch_sha256a13a5d47a05e1016c0133857bc7f4ae80f9cfb1fdc19f932908bf7c024c1fdf5
patch_identitygit-patch-id-stable-v1:c85b02388a04f0fec77f654fa7f91d5dbed494b7
committer_timestamp_ms1776021607000