Repository navigation
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
| ): Uint8Array => { | ||
| if (hash.length > maxSnapshotHashLength) throw new SnapshotError("too-large"); | ||
| if (!hash.startsWith(prefix)) { | ||
| throw new SnapshotError(/^v\d+\./u.test(hash) ? "unsupported" : "invalid"); |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
Ensure that the regex used to compare with user supplied input is safe from regular expression denial of service.
To resolve this comment:
🔧 No guidance has been designated for this issue. Fix according to your organization's approved methods.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by regex_dos.
You can view more details about this finding in the Semgrep AppSec Platform.
| ): Uint8Array => { | ||
| if (hash.length > maxSnapshotHashLength) throw new SnapshotError("too-large"); | ||
| if (!hash.startsWith(prefix)) { | ||
| throw new SnapshotError(/^v\d+\./u.test(hash) ? "unsupported" : "invalid"); |
PR SummaryLow Risk Overview A Share control on editable local documents opens a popover to copy the link (optional current view in query params), download YAML when the net exceeds link size limits, and freeze the net at open time. A new Reviewed by Cursor Bugbot for commit 2f14564. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
🟡 Changes recommended
Clipboard completion can report a stale URL as copied, and the critical oversized-snapshot download fallback is not exercised.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds self-contained, read-only Petrinaut snapshot sharing with optional editor-view restoration, local copying, and file fallback.
Changes:
- Adds versioned Brotli snapshot encoding through cancellable workers.
- Adds sharing UI,
/sharerouting, local-copy behavior, and Sentry redaction. - Adds comprehensive documentation, tests, dependency updates, and changesets.
File summaries
| File | Description |
|---|---|
yarn.lock |
Locks the Brotli dependency. |
libs/@hashintel/petrinaut/src/ui/views/Editor/panels/ai-assistant-panel/petrinaut-docs-content.ts |
Registers sharing documentation. |
libs/@hashintel/petrinaut/docs/sharing.md |
Documents snapshot sharing. |
libs/@hashintel/petrinaut/docs/README.md |
Links the sharing guide. |
libs/@hashintel/petrinaut-core/src/ai.ts |
Exposes sharing documentation to AI. |
apps/petrinaut-website/src/sharing/snapshot.ts |
Serializes and validates snapshots. |
apps/petrinaut-website/src/sharing/snapshot.test.ts |
Tests snapshot codec behavior. |
apps/petrinaut-website/src/sharing/snapshot-worker.ts |
Runs Brotli operations in a worker. |
apps/petrinaut-website/src/sharing/snapshot-worker-protocol.ts |
Defines worker messages. |
apps/petrinaut-website/src/sharing/snapshot-codec.ts |
Implements bounded Brotli encoding. |
apps/petrinaut-website/src/sharing/snapshot-client.ts |
Manages worker lifecycle and URLs. |
apps/petrinaut-website/src/sharing/snapshot-client.test.ts |
Tests cancellation and failures. |
apps/petrinaut-website/src/sharing/share-snapshot-button.tsx |
Adds the sharing dialog. |
apps/petrinaut-website/src/sharing/share-snapshot-button.test.tsx |
Tests sharing interactions. |
apps/petrinaut-website/src/sentry/strip-snapshot-links.ts |
Redacts snapshot payloads. |
apps/petrinaut-website/src/sentry/strip-snapshot-links.test.ts |
Tests telemetry redaction. |
apps/petrinaut-website/src/sentry/instrument.ts |
Applies redaction to Sentry hooks. |
apps/petrinaut-website/src/routes/share.tsx |
Adds the snapshot route. |
apps/petrinaut-website/src/routes/-share.test.tsx |
Tests snapshot navigation and copying. |
apps/petrinaut-website/src/main/app/readonly-document-page.tsx |
Extracts shared read-only document UI. |
apps/petrinaut-website/src/main/app/local-storage-demo/local-storage-demo-app.tsx |
Adds sharing to local documents. |
apps/petrinaut-website/src/examples/full-example-page.tsx |
Reuses the read-only document page. |
apps/petrinaut-website/README.md |
Documents snapshot architecture. |
apps/petrinaut-website/package.json |
Adds brotli-wasm. |
.changeset/snapshot-sharing-guide.md |
Records the Petrinaut documentation change. |
.changeset/snapshot-sharing-doc-catalog.md |
Records the core catalog change. |
Review details
- Files reviewed: 25/26 changed files
- Comments generated: 2
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| const copy = async () => { | ||
| if (url === null) return; | ||
| try { | ||
| await navigator.clipboard.writeText(url); | ||
| setCopyState("copied"); | ||
| } catch { | ||
| setCopyState("failed"); | ||
| } |
| expect(screen.getByRole("button", { name: "Download file" })).toHaveProperty( | ||
| "disabled", | ||
| false, | ||
| ); |
a47a5f7 to
dff1ad1
Compare
| SnapshotResponse, | ||
| } from "./snapshot-worker-protocol"; | ||
|
|
||
| self.onmessage = async (event: MessageEvent<SnapshotRequest>) => { |
dff1ad1 to
65eeb68
Compare
bb2a502 to
05755ea
Compare
05755ea to
c188a7e
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit c188a7e. Configure here.
| let position = 0; | ||
| for (const chunk of chunks) { | ||
| output.set(chunk, position); | ||
| position += chunk.length; |
There was a problem hiding this comment.
Decompress reuses freed chunk buffers
Medium Severity
decompressSnapshot stores each result.buf and then calls result.free() before the next stream.decompress. Those buffers are only copied into output after the loop, so a later WASM allocation can overwrite earlier chunks. Nets that expand past the 32 KiB output step can open as a corrupted document instead of the shared snapshot.
Reviewed by Cursor Bugbot for commit c188a7e. Configure here.
c188a7e to
8f2f386
Compare
Share in a local document's top bar builds a /share#v1.br.<payload> link that carries the whole net, Brotli-compressed in a worker, so nothing is uploaded. /share opens the snapshot read-only and saves nothing until Make a local copy. Sentry strips the fragment before sending. Examples and snapshots now share one read-only page and offer no Share button, since their own URL is already the link. The Share dialog is one link row and one options row, with a message only when something fails.
Snapshot links are a demo-website feature, so their guide does not belong in the @hashintel/petrinaut user guide, the assistant's documentation catalog in @hashintel/petrinaut-core, or either package's patch notes. The website README carries what a snapshot holds.
Share is a ghost icon button in the top bar's trailing section, beside version history, and opens a dropdown in place of the dialog: a short hint, the link with an inline Copy, then Include current view and Download on one row. The popover animates in and out, and the button stays pressed while it is open.
8f2f386 to
2f14564
Compare


Summary
Saved nets live in one browser, so their local URLs only work there. This PR adds Share, which builds a link that carries a copy of the whole net, with the current view if wanted.
Recipients open the snapshot read-only at
/shareand can save an editable local copy. Nothing is uploaded, and later edits to the sender's net do not change the link.9680.mp4
Links
Changes
Snapshot format
/share#v1.br.<payload>link carries the netWebsite
/shareopens the snapshot read-only and saves nothingReview fixes
Test coverage
snapshot.test.ts:snapshot-client.test.ts:-share.test.tsx:share-snapshot-button.test.tsx:strip-snapshot-links.test.ts:How to test