| adapters/http |
34 |
Re-resolution at call time, redirects refused, headers never returned |
| policy/evaluate |
33 |
Rule order, inclusive limits, null versus zero, every decision path |
| policy/evaluateHttp |
32 |
Host allowlist, per-method decisions, and that deny beats classify |
| routes/dashboard |
26 |
Session gate, tenant isolation, key issue and rotation |
| routes/policyEdit |
26 |
Editing a policy from the dashboard, and what may not be edited |
| approvals/routes |
25 |
The approve and deny endpoints, replay, expiry, wrong tokens |
| actions/service |
24 |
Request to decision to execution, and every terminal path |
| db/repo |
24 |
Every query, idempotency, the daily spend calculation |
| audit/log |
23 |
Event vocabulary, redaction, the size cap, ordering |
| routes/actions |
20 |
The HTTP surface, auth, validation, error bodies |
| sdk/client |
20 |
All three methods, timeouts, polling, error shapes |
| actions/classified |
18 |
The classifier inside the action path, and every failure meaning ask |
| approvals/token |
17 |
Minting, hashing, single use, expiry |
| policy/classify |
17 |
Timeouts, malformed answers, the body cap, unrecognised verdicts |
| routes/auth |
16 |
GitHub OAuth, single-use state, the cookie it is matched against |
| env |
15 |
The boot refusals, including half-configured SMTP |
| routes/decide |
15 |
Approving and denying from the dashboard, behind three gates |
| routes/audit |
14 |
Reading a trail back, pagination, scoping to a project |
| demo/agent |
13 |
A real LLM agent driving the tool, end to end |
| docs/generated |
13 |
That the published schema matches the runtime behaviour |
| auth/session |
12 |
Session tokens: hashed at rest, compared in constant time, absolute expiry |
| notify/email |
12 |
Message construction, the approval link, escaping |
| shared/actions |
11 |
The wire schema, strict mode, integer cents |
| notify/smtp |
10 |
Transport construction and credential verification |
| policy/seedPolicy |
8 |
The policy the seed script writes |
| adapters/ledger |
6 |
That it records and does not settle |
| auth/apiKey |
5 |
Generation, hashing, constant-time comparison |