Skip to content

fix(remote): fail closed for a remote repository with no endpoint - #657

Merged
Ziinc merged 1 commit into
claude/prd-gaps-remote-path-guardsfrom
claude/prd-gaps-remote-path-guards-2
Oct 1, 2026
Merged

Ziinc merged 1 commit into
claude/prd-gaps-remote-path-guardsfrom
claude/prd-gaps-remote-path-guards-2

Conversation

@Ziinc

@Ziinc Ziinc commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #649.

Problem

When a remote repository had no endpoint, activeRepositoryFromRemote fell back to transport: {type: "local"}. activeForPath and remoteRepositoryContaining then returned null, so every operation ran as a local Tauri command against the remote path string. remoteDispatch with a null endpoint also fell through to remote_dispatch_local. The endpoint-less legacy last_opened_remote_repo blob was restored on launch without the trust sequence, which contradicts remote-repository.ts:17.

Changes

Call site Before After
activeRepositoryFromRemote, no endpoint transport: local transport: unresolved
activeForPath on an unresolved remote null, so it ran locally throws endpoint_unresolved:
remoteDispatch / remoteMutation, no SSH transport ran through remote_dispatch_local throws endpoint_unresolved:
assertLocalOperation on an unresolved remote passed throws unsupported:
Launch restore with no saved descriptor id restored the endpoint-less blob does nothing; reopening goes through the descriptor and trust sequence
The remote-workspace-ui screenshot spec now opens through the loopback descriptor helper from #649.

Checks

  • unit: src/lib, src/components, src/hooks (750 passed), including a new unresolved-remote fail-closed test
  • integration: remote-workspace-ui and remote-ssh (16 passed), including a new "no descriptor id: blob not restored" case
  • screenshot spec remote-workspace-ui passes; I checked the capture by eye
  • npm run check, lint, check:format, knip
    🤖 Generated with Claude Code
    https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
    Generated by Claude Code

activeRepositoryFromRemote fell back to a local transport when a remote
repository had no endpoint, so every transport helper ran the operation as a
local Tauri command against the remote path. It is now an explicit
"unresolved" transport: routed reads and mutations throw
endpoint_unresolved, and assertLocalOperation keeps rejecting local-only
calls. The launch-time restore of the endpoint-less legacy blob is removed;
a repository reopens only through the saved descriptor and trust sequence.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t

Ziinc commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Consolidated into #649 (remote repo identity and trust). Closing.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants