Three non-blocking findings from the adversarial re-review of the workstream namespacing PR, addressed as a follow-up: 1. setActiveWorkstream now validates names with the same regex used at CLI entry and cmdWorkstreamSet — defense-in-depth so future callers can't poison the active-workstream file 2. Replaced tautological test assertion (result.success || !result.success was always true) with actual validation that cmdWorkstreamSet returns invalid_name error for path traversal attempts. Added 8 new tests for setActiveWorkstream's own validation. 3. Updated stale comment in copilot-install.test.cjs (said 31, actual 56) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
19 KiB
19 KiB