Fixes a hole in the Windows smoke test (#19): the "microphone refused to a foreign page" check navigated to https://example.com and ignored navigation failures. If the runner couldn't reach the internet, the request came from the app's own page and "passed" vacuously. That's what happened on the #27 build (run 2274).
Now it:
serves the foreign page locally on http://localhost:9333, a different origin that is still a secure context;
confirms the navigation happened before asking for the microphone;
Fixes a hole in the Windows smoke test (#19): the "microphone refused to a foreign page" check navigated to `https://example.com` and ignored navigation failures. If the runner couldn't reach the internet, the request came from the app's own page and "passed" vacuously. That's what happened on the #27 build (run 2274).
Now it:
- serves the foreign page locally on `http://localhost:9333`, a different origin that is still a secure context;
- confirms the navigation happened before asking for the microphone;
- **fails** on builds that should refuse it.
Script-only change.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
The example.com check could pass vacuously if the runner can't reach the
internet (goto failed silently, the mic request then came from the app's
own page). Serve a page on http://localhost:9333 instead, confirm the
navigation happened, and fail on builds that should refuse it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
jared
merged commit 06fe43c3cd into main2026-09-30 12:46:31 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes a hole in the Windows smoke test (#19): the "microphone refused to a foreign page" check navigated to
https://example.comand ignored navigation failures. If the runner couldn't reach the internet, the request came from the app's own page and "passed" vacuously. That's what happened on the #27 build (run 2274).Now it:
http://localhost:9333, a different origin that is still a secure context;Script-only change.
🤖 Generated with Claude Code
https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA