Skip to content

fix(bets): GET /api/bets was readable with no session (v0.453.1) - #852

Merged
vikasprogrammer merged 1 commit into
mainfrom
feat/bets-board
Oct 5, 2026
Merged

vikasprogrammer merged 1 commit into
mainfrom
feat/bets-board

Conversation

@vikasprogrammer

Copy link
Copy Markdown
Owner

The bug

GET /api/bets shipped in v0.453.0 above the /api/* auth gate — it was added beside the agent loopback routes (/api/agent/bets/*), which are deliberately pre-auth because they carry their own session-secret check. So the board route inherited no gate at all:

$ curl -s -o /dev/null -w '%{http_code}' localhost:3010/api/bets   # live instapods, no cookie
200

Every bet on the tenant — titles, hypotheses, baselines, asset URLs — to anyone who could reach the port. On the Mac Mini that is the tailnet rather than the internet, which is why this is a 🔴 rather than a 🚨, but it is the same class of mistake as a missing auth_request.

The handler was correct. Its position in the file was the bug.

Fix

  • Moved below the gate, beside the other goal routes, with a comment stating that it must stay there and why.
  • scripts/bets-test.cjs now asserts an un-cookied GET /api/bets and an un-cookied PATCH /api/bets/:id both return 401. A position bug needs a reachability test; a handler test would have passed throughout.

Also

The human write side the board needs, owner/admin gated:

  • PATCH /api/bets/:id — state + lesson (and hypothesis/baseline/expected/window). A terminal state requires a lesson, exactly as the agent lane does.
  • POST /api/bets/:id/judge — run the arithmetic early on a window a human has already seen enough of; audited with early: true.

The measured columns stay unwritable from both lanes: the test pins that an owner PATCHing observedLift: 99 changes nothing.

🤖 Generated with Claude Code

The route landed beside the agent loopback routes, which sit above the /api/*
auth gate, so every bet on the tenant — titles, hypotheses, baselines, asset
URLs — was served to anyone who could reach the port. The handler was fine; its
POSITION was the bug, so the test is about reachability without a cookie rather
than about the handler.

Also adds the human write side the board needs (PATCH /api/bets/:id and
POST /api/bets/:id/judge, owner/admin): decide + record the lesson, or force the
arithmetic early. The measured columns stay unwritable — not even an owner can
type a number over a measurement.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vikasprogrammer
vikasprogrammer merged commit 8f81efb into main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant