test(relay): look for origin fragments long enough to mean something - #665
Merged
Merged
Conversation
localURLCarriesNoOriginText checked that the relay URL does not contain "jf",
but the reference in that URL is random base64 of about 190 characters, which
contains any given two-letter pair on roughly one run in twenty. It failed the
7.22.0 release run on main that way ("...BjyjfBTh..."), with the code
unchanged since its green PR run. The fragments are now the ones that would
actually give the origin away (jf.example, master.m3u8, api_key); 40 runs in a
row are green.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mf4MXgM9bqugHoe5TW4BYf
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
HLSOriginRelayTests.localURLCarriesNoOriginTextchecked that the relay URL does not contain"jf". The reference in that URL is random base64 of about 190 characters, so it contains any given two-letter pair on roughly one run in twenty. That is how it failed the 7.22.0 release run onmain(…BjyjfBTh…), with the code unchanged since the PR run that passed.The test now checks for fragments that would actually give the origin away:
jf.example,master.m3u8andapi_key. The check still covers what it was written for, since a leaked host, path or token contains those fragments. Test-only change, no release needed. 40 runs in a row pass locally.🤖 Generated with Claude Code
https://claude.ai/code/session_01Mf4MXgM9bqugHoe5TW4BYf