Skip to content

fix: Ensure shared file previews use truncated content - #607

Merged
thdxr merged 1 commit into
devfrom
unknown repository
Jul 2, 2025
Merged

fix: Ensure shared file previews use truncated content#607
thdxr merged 1 commit into
devfrom
unknown repository

Conversation

@ghost

@ghost ghost commented Jul 2, 2025

Copy link
Copy Markdown

The read tool's display in the share view was unintentionally falling back to rendering the full tool output if the specific metadata.preview (max 20 lines) was an empty string. This could lead to more data being embedded in the page source than implied by the UI.

This commit modifies the Share.tsx component to ensure that the CodeBlock for the read tool prioritizes metadata.preview even if it's an empty string. The fallback to showing the full tool result via TextPart is now more restrictive and less likely to be triggered for the read tool, thus preventing excessive data exposure in the preview.

The read tool's display in the share view was unintentionally falling
back to rendering the full tool output if the specific metadata.preview
(max 20 lines) was an empty string. This could lead to more data
being embedded in the page source than implied by the UI.

This commit modifies the Share.tsx component to ensure that the
CodeBlock for the read tool prioritizes metadata.preview even if it's
an empty string. The fallback to showing the full tool result via
TextPart is now more restrictive and less likely to be triggered for
the read tool, thus preventing excessive data exposure in the preview.
@thdxr
thdxr merged commit 2799a96 into anomalyco:dev Jul 2, 2025
@ghost
ghost deleted the fix/share-data-exposure branch July 3, 2025 04:42
xywsxp pushed a commit to xywsxp/opencode that referenced this pull request Apr 24, 2026
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
AIALRA-0 pushed a commit to AIALRA-0/opencode-turn-engine that referenced this pull request Jun 10, 2026
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
avion23 pushed a commit to avion23/opencode that referenced this pull request Jun 10, 2026
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
mayoalexander added a commit to FREELABEL/iris-opencode that referenced this pull request Sep 3, 2026
…aybooks

PAGES WERE UNSCOPED (#183541). Scoped to 'Branded Champions anomalyco#607', the Pages tab listed
X-ART's pages and IRIS internals. Every other sidebar tab passes bloq_id; pages passed only
user_id — AND it sat in the load-once block that runs before any project is selected, so it
could never change when you switched projects.

Moved into fetchBloqData with owner_type=bloq&owner_id={bloqId}. That filter already existed:
fl-api's PageController::index supports owner_type+owner_id and its own comment calls it 'a
NARROWING filter applied on top of the scope above, never a widening one'; iris-api's
/v1/pages is a pass-through proxy forwarding the query verbatim.

VERIFIED against production data, because the filter is worthless if pages are not owned that
way: xart-board is owner_type=bloq owner_id=570, and branded-champions is owner_id=607. Note
branded-champions was NOT in the reported screenshot — so other projects' pages were pushing
this project's OWN page off the per_page=50 list. The bug was hiding what you came to see, not
just adding noise.

FLOWS -> PLAYBOOKS. The tab labelled 'Flows' rendered workflows. It now renders playbooks,
fetched per-bloq from /api/v1/bloqs/{bloqId}/playbooks and relabelled 'Playbooks'.

Bloq anomalyco#607 has NO attached playbooks, so a purely-attached list would render an empty tab. It
falls back to the available set (97) — but flagged attached:false and headed 'Available — none
attached to this project'. Silently listing 97 global playbooks under a project header would
have repeated the exact bug being fixed one tab over. The label is the difference between a
scoped panel and one pretending to be scoped.

Removed the workflow detail view's now-dead state (activeWorkflow, workflowLoading,
workflowImported) and the status icon/colour helpers rather than leaving signals nothing can
set — dead state in a reset handler reads as if a detail view still exists.

Typecheck clean (the one remaining error, session/llm.ts TS2589, is pre-existing and
unrelated). NOT render-verified in a running TUI — the API contracts and types are checked,
the pixels are not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0195GD9U29DkMpcjbMUdsuMV
meSingh pushed a commit to meSingh/opencode that referenced this pull request Sep 6, 2026
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant