mirror of
https://github.com/andrewyng/openworker.git
synced 2026-09-10 22:20:27 +00:00
web_search reclassified EGRESS (spec 2.2, decided 2026-08-12): the destination is fixed (the configured provider) but the query is model-chosen free text - the same outbound channel web_fetch's URL is. It ran completely ungated in every mode until now; it gates like any egress from here on, which also puts it in front of the Auto-Approve reviewer. The egress approval cards (spec 1.9): - web_fetch offers "Always allow <host> this session" -> ALWAYS_DOMAIN. Tool-wide "always" is gone from the card AND server-refused (_grant_offered): it would cover every future destination, and the live A/B showed exactly that (one click on a bbc.com card ran promptless fetches to hosts no card ever named). - www. stripped at grant minting (allow_domain_for_session) - pure spelling only, never eTLD+1. The card button shows the exact spelling the grant mints. - web_search offers "Always allow searches this session" -> ALWAYS_TOOL (tool-wide IS provider-wide for a fixed destination), with the card naming the LIVE destination: "Queries go to your configured search provider (currently: <name>)". Provider resolved when the card is raised (engine.approval_extras hook), not at session start. - Provider-change invalidation: set_web_search clears the web_search session grant in every live engine when the provider actually changes - the grant was consent to a named destination. - Auto-Approve fall-through cards hide every session "always" button: grants don't skip the reviewer there (1.5), and a button that lies is worse than none. - scopeNote tells the truth for egress: "leaves this computer -> <host>" replaces "stays on this computer" on fetch/search cards. Corpora gain web_search cases (benign 22 / dangerous 17 / injection 14), including query-borne secret exfiltration and a planted search-the-credentials injection. Tests: test_egress_and_overrides (EGRESS class, gating, www-strip, 1.5 in Auto-Approve), test_approval_integrity (tool-wide refused for URL-carrying egress, kept for web_search; provider-change invalidation), ApprovalCard.test.tsx (domain button + www-strip, provider line, Auto-Approve hides always). Full suites pass; the 22 pre-existing failures (Slack fake-gateway timeouts, a Windows file-lock rename) fail identically on the pre-change tree.
30 lines
680 B
Python
30 lines
680 B
Python
"""Web search — a keyless DuckDuckGo default + configurable third-party providers."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from .providers import (
|
|
BraveProvider,
|
|
DuckDuckGoProvider,
|
|
SearchResult,
|
|
TavilyProvider,
|
|
WebSearchProvider,
|
|
build_provider,
|
|
provider_names,
|
|
)
|
|
from .fetch import make_web_fetch_tool
|
|
from .tool import make_web_search_tool, provider_name, resolve_provider
|
|
|
|
__all__ = [
|
|
"SearchResult",
|
|
"WebSearchProvider",
|
|
"DuckDuckGoProvider",
|
|
"TavilyProvider",
|
|
"BraveProvider",
|
|
"build_provider",
|
|
"provider_names",
|
|
"make_web_search_tool",
|
|
"make_web_fetch_tool",
|
|
"provider_name",
|
|
"resolve_provider",
|
|
]
|