From the security sweep (#149).
The threat model states private-repo invisibility as one cross-cutting
rule, but it was tested per feature — so a surface added later leaks and
nothing fails. TestPrivateRepoIsInvisible makes the list of surfaces
the thing under test: every web route, thirteen control commands, and the
listings a stranger legitimately reaches, as both anonymous and
logged-in.
Two things worth knowing about the test itself:
- It distinguishes a leak from an echo. A search page renders the query into its form and filter links, so a term present because the prober typed it proves nothing. My first version didn't make that distinction and reported four false positives; I confirmed they were false by checking whether the page linked the repo or showed the issue title, and it did neither.
- It's load-bearing. Removing the visibility predicate from the search query fails it on both the web and CLI paths.
The sweep also confirmed the headers, parser fuzzing, #+INCLUDE:
refusal, LFS/asset path handling and org/team authorization are all
sound, and found two things that are not — #147 and #148.
Ref #149