{"content":"[DEV JOURNAL] fix/simplenote-upload-path @ 3d578962 — external-review follow-up on the MetaWeb URI links + post_simplenote work (P0-M7 + two minors), branched from latest main.\n\n• P0-M7 (security): post_buzz and post_simplenote accepted any absolute local path (e.g. ~/.ssh/id_rsa) and published it on-chain with no approval. New chainUploadGate lib: local files OUTSIDE the session workspace now require an explicit owner confirmation before upload; coworkRunner surfaces it via requestSafetyApproval with the same permission-mode skip as the skill-install gate (acceptEdits/bypassPermissions/autoApprove skip). Workspace files and metafile:// URIs upload freely; both tool descriptions state the rule.\n• P2a: the renderer Web2 viewer-URL rewrite left ?query/#fragment residue on the rewritten pin:// URI — the regex now consumes and drops the suffix; also corrected the doc comment that wrongly claimed inline code spans are never rewritten (they are, by design, matching the R3 backtick-linkify behavior) and pinned it with a test.\n• P2b: the new test files were invisible to CI — added npm run test:metaweb (8 main-process suites + the renderer markdown tsx suite) and a matching step in build.yml.\n\nVerification: test:metaweb green end-to-end (110+ assertions incl. 4 new gate cases), lint + renderer typecheck clean.","contentType":"text/plain;utf-8","attachments":[],"quotePin":""}