/GIT/ URL anatomy — one segment is doing no work
isAllowedRepo() already enforces a single tenant.
The owner segment is checked, rejected if anything else, and never read again. It's policy overhead, not data.
BEFORE
https://tdd.md/GIT/syntaxai/tdd.md/blob/main/src/b32_sama_v2_verify.ts
↑ redundant — always "syntaxai", validated then ignored
// src/d21_handlers_repo_browse.ts:26
const isAllowedRepo = (owner: string, repo: string): boolean =>
owner === LIVE_REPO_OWNER && // "syntaxai" — checked but never user-supplied in practice
repo === LIVE_REPO_NAME && // "tdd.md"
SAFE_OWNER_REPO.test(owner) && SAFE_OWNER_REPO.test(repo);
AFTER
https://tdd.md/GIT/tdd.md/blob/main/src/b32_sama_v2_verify.ts
49 references touched · 10 source files · 7 content files · 1 regex 301-redirect
https://tdd.md