Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

🤖 refactor: VS Code webview hardening follow-ups (unscoped agent toggle, stream redaction)

クローズ 初心者向け
#4,820 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
半日
初心者へのやさしさ
78/100
issue の種類
リファクタリング
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript

調査の方向性

vscode/src/webview/ChatComposer.tsx の SimpleAgentToggle から始め、vscode/src/extension.ts の handleOrpcCall と pumpOrpcStream も確認してください。stream の経路を既存の value-response の redaction と比較し、provider scope が composer にどのように到達するかを調べてください。workspace scope がない場合に toggle が無効になり、stream items が同じ redactor を通過すれば完了です。

索引モデルが issue の本文から書いたものです。

説明

backlog refactor

Problem

Two small VS Code webview hardening items deferred from the final checks of #4810 and #4813. Neither is a user-facing bug today.

  1. Agent toggle while unscoped. Since #4810, AgentProvider gets no workspace ID in file mode (and, since #4792, before the workspace list arrives). The composer is disabled then, but SimpleAgentToggle in vscode/src/webview/ChatComposer.tsx stays clickable and writes the webview's global agent key (agentId:__global__). Workspace scopes do not read that key, so nothing leaks into a workspace; the click is just misleading. Fix: also disable the toggle while the provider has no workspace scope.
  2. Stream chunks bypass redaction. redactWebviewOrpcResult runs on value responses in handleOrpcCall (vscode/src/extension.ts), but pumpOrpcStream forwards stream items unchanged. The allowed streams (providers.onConfigChanged, config.onConfigChanged, policy.onChanged) emit only void change signals, so nothing leaks today. Fix (defense in depth): run stream items through the same redactor, so a future structured stream on a redacted path cannot bypass it.

Refs #4797, #4766


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $4.48

主要言語
TypeScript
スター
2k
フォーク
136
平均マージ
7時間 27分
マージ済み PR(30日)
710

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

coder/xum のほかの issue

coder/xum の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。