fix(server): isolate Claude capability probe cwd - #8835
Closed
Michel-Liao wants to merge 1 commit into
Closed
Michel-Liao wants to merge 1 commit into
Michel-Liao wants to merge 1 commit into
MacroscopeApp / Macroscope - Correctness Check
succeeded
Aug 31, 2026 in 1m 34s
No issues identified (5 code objects reviewed).
• Merge Base:
352710d
• Head:2b7faf5
Details
| ✅ | File Path | U3 Bytes | Comments Posted | Reason |
|---|---|---|---|---|
| ✅ | apps/server/src/provider/Drivers/ClaudeDriver.ts |
480 | 0 | |
| ✅ | apps/server/src/provider/Drivers/ClaudeHome.ts |
2270 | 0 | |
| ➖ | apps/server/src/provider/Drivers/ClaudeHome.test.ts |
2649 | Excluded by default ignore patterns | |
| ✅ | apps/server/src/provider/Layers/ClaudeProvider.ts |
1854 | 0 | |
| ➖ | apps/server/src/provider/Layers/ClaudeCapabilitiesProbe.test.ts |
3636 | Excluded by default ignore patterns |
Billed Total: 10.00KB of diff | $0.50 (This review was charged at our per-review byte minimum of 10.00KB. Learn more here)
Filtered Issues Details
apps/server/src/provider/Drivers/ClaudeHome.ts
- line 64:
NodeOS.tmpdir()is only a system/user-selected temporary directory, not a guaranteed configuration-free directory. If it (or an overriddenTMPDIR/TEMP) contains.claude/settings.json, the probe still runs withsettingSourcesincludingproject, so it loads that directory's project settings and can again obtain account/capability data affected by unrelated settings. Use a dedicated empty temporary subdirectory (or otherwise exclude project settings) rather than the shared temp root. [ Already posted ] - line 64: Changing the probe
cwdto the temp root also changes the project whose filesystemproject/localsetting sources are consulted. The probe parsesinit.commandsinto the provider's slash commands, so workspace-specific Claude commands previously discovered from the caller'scwdare no longer reported; the unchanged setting-source list does not preserve discovery after its project root has been replaced. [ Already posted ]
Loading