{"slug":"agentabrams-viewer","total":14,"limit":100,"offset":0,"since":null,"commits":[{"hash":"ea8bb3a","date":"2026-07-25 10:55:27 -0700","author":"Steve","subject":"chore: lint (loadDomains try/catch),  (session close)","body":""},{"hash":"814faa8","date":"2026-07-25 10:18:06 -0700","author":"Steve Abrams","subject":"viewer UI: 3-way status dots (Basic/login/open) + per-dot tooltip","body":"Front-end now reads authType from /api/status: amber=Basic un/pw, blue=login/SSO,\ngreen=open(no auth), red=down/pw-rejected. Legend + hover tooltip updated so 'is this\nprotected, and how' is answerable at a glance."},{"hash":"a983e0c","date":"2026-07-25 10:14:07 -0700","author":"Steve Abrams","subject":"Fix self-XSS in domain search filter: escape filter + labels before innerHTML","body":""},{"hash":"1eb9bf1","date":"2026-07-25 10:04:56 -0700","author":"Steve Abrams","subject":"viewer: follow redirects + detect login-form/SSO gating, not just HTTP 401","body":"probe() now walks the redirect chain and classifies authType as\nbasic (401 wall) | login (redirect-to-auth or password field) | open | down,\nso a 302->/login and a 200 login page are correctly counted as protected\ninstead of 'open'. Adds authType + finalStatus to /api/status."},{"hash":"d7674a9","date":"2026-07-22 21:00:27 -0700","author":"Steve Abrams","subject":"proxy: strip upstream Referrer-Policy — no-referrer (from the 7/22 fleet CSP sweep) blinded the referer-based asset escape hatch, previews rendered unstyled","body":"Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>"},{"hash":"12882d2","date":"2026-07-22 20:35:45 -0700","author":"Steve Abrams","subject":"5x fleet: 5-sweep report — 47/47 clean, CSP/schema/asset fixes, harness --location-trusted","body":""},{"hash":"a0a5729","date":"2026-07-22 20:13:51 -0700","author":"Steve Abrams","subject":"domains: livesiteaudit.aa renamed to barber.aa","body":""},{"hash":"2dbe2c3","date":"2026-07-22 19:36:04 -0700","author":"Steve Abrams","subject":"5x sweeps 3-4 clean: REPORT — 7/7 stable, stop on clean-twice","body":""},{"hash":"15161bc","date":"2026-07-22 19:33:46 -0700","author":"Steve Abrams","subject":"5x sweep 2: add data-URI favicon (Chrome's auto /favicon.ico request 404'd -> console error in E2E)","body":""},{"hash":"b807e6b","date":"2026-07-22 19:31:44 -0700","author":"Steve Abrams","subject":"5x sweep 1: handle aborted/failed api fetches in boot IIFE (unhandled rejection -> page error in E2E)","body":""},{"hash":"4175e4a","date":"2026-07-22 19:20:43 -0700","author":"Steve Abrams","subject":"chore: lint, refactor (dedup loadDomains, proxy-error writableEnded guard), version bump (session close)","body":"Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>"},{"hash":"8ef170b","date":"2026-07-22 19:15:59 -0700","author":"Steve Abrams","subject":"fix SSO cookie rewrite in site proxy: fleet-wide (Domain=) cookies scope to /site/, strip Secure for http loopback","body":""},{"hash":"02f58ea","date":"2026-07-22 19:03:30 -0700","author":"Steve Abrams","subject":"viewer: credential-injecting reverse proxy so unified admin pw auto-applies to in-panel sites","body":"- /site/<domain>/ proxies upstream with admin/DW2024! injected (browsers won't basic-auth cross-origin iframes)\n- strips X-Frame-Options/CSP so authed sites render in the panel; TLS verify stays ON\n- status probe now does a 2nd authed HEAD to flag a rejected pw (authFail) vs a healthy gate\n- allowlisted to domains.json; localhost-only, still behind admin/DW2024!\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>"},{"hash":"21d5179","date":"2026-07-22 17:39:59 -0700","author":"Steve Abrams","subject":"agentabrams domain viewer: left-rail list of all 47 *.agentabrams.com vhosts, right-panel live iframe, health dots, frame-block fallback","body":"Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n"}]}