The config API can no longer undo the protections set for an agent, and
with LibreOffice's KDE interface a call right after opening a document no
longer lands on the previous one.
Fixed
- With LibreOffice's KDE interface, the call right after
doc_openor
doc_createcould land on the previous document. The window manager can
hand focus back to the previous window for about 100 ms after the switch,
and the next call arrives within milliseconds. Nelson now keeps the
document a tool just made active as the active one for two seconds, unless
it is closed. Measured with the new KDE smoke mode: the opening checks
failed about one run in three, and now pass 12 of 12
Security
-
The config API could undo the protections set for an agent.
POST /api/configwrote any setting. An agent with access could clear the
access token, change the address, switch off the guard against disabling
change recording, set the command a launcher runs, or widen the folders its
tools reach.GETalso returned the token and providers' API keys in clear.
The settings that decide what is exposed, what runs and what can be reached
are now reserved to Options:http.*,tunnel.*,debug.*,launcher.*;*.instances;core.force_track_changes.
A request that touches one is refused with
403and writes nothing, and
secrets read back as***. Everything else (read limits, exchange format,
the name on tracked changes, MCP endpoints) stays open to the agent
Added
- README: "Let the agent configure Nelson": what the config API is for,
how to switch it on, and what it cannot change.API.mddocuments the
reserved settings, the403and masked secrets, and the current/health
response; the option's help text in Options says what stays reserved