[eric] browser: reddit clears its composer without posting, so treat it as a ghost-drop host

This commit is contained in:
ciregenz
2026-07-31 02:37:07 -07:00
parent b4074c3665
commit a1c6c710eb
2 changed files with 14 additions and 4 deletions
@@ -21,7 +21,11 @@ from backend.apps.agents.browser import browser_submit_click
ToolRunner = Callable[[str, dict, str, str], Awaitable[dict]]
# Hosts known to accept-then-silently-drop an automated post. A newly-found one is a one-line add.
GHOST_DROP_HOSTS = ("youtube.com",)
# reddit joined 2026-07-31 on live evidence, twice: the r/test submit form clears the composer and
# the post never appears in r/test/new (markers canary5ef128b9 and canary99b063a2, both audited
# absent). Without this the cleared composer is trusted as delivery and the user gets told
# 'Done, I sent "canary..." for you' about a post that does not exist.
GHOST_DROP_HOSTS = ("youtube.com", "reddit.com")
# What a site says when it REFUSED the write. Only ever consulted inside a live announcement
# region, never against the whole page, so an unrelated "failed" in an article body can't match.
+9 -3
View File
@@ -6,18 +6,24 @@ import pytest
from backend.apps.agents.browser import browser_delivery_check as dc
def test_ghost_drop_host_matches_youtube_only():
def test_ghost_drop_hosts_are_the_ones_that_eat_a_post():
assert dc.is_ghost_drop_host("https://www.youtube.com/watch?v=abc")
assert dc.is_ghost_drop_host("https://youtube.com/watch")
assert dc.is_ghost_drop_host("https://m.youtube.com/watch")
# every proven-good write host stays OFF the ghost path (zero added latency there)
# reddit joined 2026-07-31 on live evidence, twice: the r/test submit form clears the composer
# and the post never lands in r/test/new (markers canary5ef128b9 and canary99b063a2, both
# audited absent) while the run announced 'Done, I sent "canary..." for you'. This assertion
# used to say the opposite, on the assumption reddit was a proven-good write host.
assert dc.is_ghost_drop_host("https://www.reddit.com/r/test/submit")
assert dc.is_ghost_drop_host("https://old.reddit.com/r/test")
# every still-proven write host stays OFF the ghost path (zero added latency there)
assert not dc.is_ghost_drop_host("https://x.com/home")
assert not dc.is_ghost_drop_host("https://www.reddit.com/r/test")
assert not dc.is_ghost_drop_host("https://mail.google.com/mail")
assert not dc.is_ghost_drop_host("https://www.linkedin.com/feed/")
assert not dc.is_ghost_drop_host("")
# a lookalike domain must not match the bare-endswith by accident
assert not dc.is_ghost_drop_host("https://notyoutube.com.evil.test/")
assert not dc.is_ghost_drop_host("https://notreddit.com/r/test")
def test_probe_expression_escapes_and_truncates():