/GIT/ URL anatomy — one segment is doing no work isAllowedRepo() already enforces a single tenant. The owner segment is checked, rejected if anything else, and never read again. It's policy overhead, not data. BEFORE https://tdd.md/GIT/syntaxai/tdd.md/blob/main/src/b32_sama_v2_verify.ts ↑ redundant — always "syntaxai", validated then ignored // src/d21_handlers_repo_browse.ts:26 const isAllowedRepo = (owner: string, repo: string): boolean => owner === LIVE_REPO_OWNER && // "syntaxai" — checked but never user-supplied in practice repo === LIVE_REPO_NAME && // "tdd.md" SAFE_OWNER_REPO.test(owner) && SAFE_OWNER_REPO.test(repo); AFTER https://tdd.md/GIT/tdd.md/blob/main/src/b32_sama_v2_verify.ts 49 references touched · 10 source files · 7 content files · 1 regex 301-redirect https://tdd.md