Validate a clone URL's authority as it was typed

main

Commit

gtrrz-victor1w ago

entire://real-cluster.entire.io@evil.com/gh/a/b resolved to evil.com and would be dialled — the CLI fetching /.well-known/entire-cluster.json from a host the URL never appeared to name, out of a string a user pasted because it looked like their cluster.

validateClusterHost was never wrong: it refuses userinfo explicitly. It just never saw any, because the check ran on url.Parse's Host, which has the userinfo stripped off by then. Cutting the authority out of the literal text is what puts it back in front of the check. The cut splits on "//" rather than the scheme constant, so a differently-cased scheme — which url.Parse accepts — cannot slip past.

The doc comment claimed this boundary held while the code did not enforce it. I had measured that gap earlier, deleted the failing test case as out of scope, and left the claim standing, which is worse than never having looked.

Two texts the ULID removal left behind: badRepoRefErr still offered "a repo ULID" among the forms to pass, and the conventions still documented repo view as taking one. Neither is reachable now.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com Entire-Checkpoint: 01M3PV5SSC6BN0W4ARHWCVPWSP

Checkpoints

Fix repo view CLI output and validation

Claude CodeOpus 5
View session
Checkpoint 1