A command-line interface for tangled, the decentralized Git collaboration platform built on the AT Protocol. eric-wien.tngl.io/tng-cli
cli git atproto tangled

fix: address extensive dual-reviewer code review findings master

Security/correctness: - GetRecord/GetBlob fall back to the record owner's PDS for cross-PDS reads - Escape error text in the OAuth callback HTML page (reflected XSS) - Cap and magic-byte-check gzip decompression of untrusted patch blobs - Map AuthError/CancelError to documented exit codes 4/2 - Surface failed PDS-record restore in DeleteRepo rollback - Keep the OAuth callback listener bound for the whole flow (port TOCTOU) - Error on unresolvable explicit --repo filter in pr/issue list - Guard empty knot in pr merge and set AuthorEmail from git config - Guard flag-like git args in Clone/FormatPatch ('--' separator, ref check) - Bail out of pagination loops on repeated cursors Cleanup: - Remove dead code: unused config fields, TokenFromEnv, FormatHandle, Remotes.FindByName/FindByRepo, Factory.Remotes, git SetConfig/Fetch, ReopenPull/ReopenIssue - Make TNG_FORCE_TTY/CLICOLOR_FORCE actually force color - Whole-line prompt reads (cmdutil.ReadLine) for login and repo delete - ssh:// clone URL form for knot hosts with ports - Sync docs/index.html and README with the real flag/config surface - Route SessionFilePath through sanitizeFilename; fix stale doc comments Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>