@ChomboSoup@JustJake@Railway It's definitely a problem you can't deploy the dodgy code you put into prod in the first place. I'm just saying, if you hadn't have shipped a vulnerability in the first place it wouldn't be too much of a big deal.
@ChomboSoup@JustJake@Railway 1. You shipped vulnerable code, that's on you then.
2. This is obviously a massive infra challenge that literally nobody could have seen coming. And now they'll get stronger and adjust their threat model to include such a ridiculous case like this.
@JustSteveKing@taylorotwell I _assume_ Taylor means directly in replacement of AI, but I'm not sure. Or he's saying those devs were shit, either way, it's not a great tweet.
@tobias_petry@MurmeltierS@tomhacks@GoogleCloudTech Exactly, only the client side visits this URL in this OAuth flow. It doesn't need to be a public url, just a URL that the client can visit (in this case, the local machine can)
@marcelpociot@getpolyscope Hey @marcelpociot quick win - would be really nice when opening a modal (such as clicking "From branch" when adding a workspace) focuses the input instead of having to make a second click. Thanks!