## Sharing is a separate disclosure decision

Noor has reviewed a local packet\.&#32;That does not automatically authorize uploading it\.

This chapter is a decision and evidence exercise\.&#32;**Do not execute&#32;`/share`&#32;as part of the workbook\.**&#32;No live upload is needed to learn the boundaries\.

### Milestone\:&#32;Identify the route before authorizing disclosure

**Need\.**&#32;Noor may eventually need a link for an authorized reviewer\.

**Obstacle\.**&#32;The same human command can use a default encrypted snapshot or a custom executable handler with a different data contract\.

**Exact action\:**&#32;review the effective sharing settings and whether the active agent directory contains a custom share script\.&#32;Then identify what data that route would receive\.&#32;Do not invoke sharing to discover its policy\.

The supplied settings schema places sharing controls under Interaction&#32;\/&#32;Collab\:

| Setting | Current default or source | Meaning |
| --- | --- | --- |
| `share.store` | `blob` | Upload the encrypted snapshot to the share server\. |
| `share.serverUrl` | `DEFAULT_SHARE_URL` | Upload\/viewer base\.&#32;The accompanying operation document names&#32;`https://my.omp.sh/s`\. |
| `share.redactSecrets` | `true` | Pass the session’s secret obfuscator to default sharing when available\. |
| `secrets.enabled` | `false` | SDK creation only builds the normal secret obfuscator when enabled\. |

The defining body of the imported&#32;`DEFAULT_SHARE_URL`&#32;constant is not included in the source bundle\.&#32;Treat the effective installed&#32;`share.serverUrl`&#32;as authoritative rather than assuming a documented endpoint\.

Global settings\,&#32;project settings\,&#32;explicit overlays\,&#32;and runtime overrides can affect effective values\.&#32;A value in one config file is not necessarily the current effective value\,&#32;especially after a project\-scope change\.

**Current default correction\:**&#32;GitHub gist is not the default or preferred route in the supplied schema\.&#32;`share.store`&#32;defaults to&#32;`blob`\.&#32;There is no supplied&#32;`--gist`&#32;flag\.

### Default sharing and custom sharing are different contracts

| Route | Data contract |
| --- | --- |
| Default encrypted sharing | Builds a JSON snapshot directly from the manager and optional current agent state\;&#32;optionally applies the typed secret\-redaction pass\;&#32;compresses and encrypts it\. |
| TUI custom handler | Receives the path to an ordinary temporary HTML export\.&#32;It is not handed the default encrypted\/redacted snapshot\. |
| Shared non\-TUI builtin | Calls default&#32;`shareSession`&#32;directly\;&#32;it does not load the custom TUI share script\. |

Default&#32;`buildShareSnapshot`&#32;calls&#32;`buildSessionData`\.&#32;**It does not collect adjacent subagent JSONL files\.**&#32;The supplied interception check confirmed that omission\.

Ordinary HTML export\,&#32;including the TUI custom\-handler input\,&#32;does collect adjacent nested transcripts by default\.

This does not mean default sharing contains no subagent\-derived information\.&#32;Parent journal entries can already contain task inputs\,&#32;results\,&#32;and quoted output\.

Default sharing can work for an in\-memory session because it builds the snapshot from the manager’s entries without requiring a session file\.&#32;A custom TUI handler still depends on HTML export\,&#32;so a manager without a session file can fail before the handler runs\.&#32;There is no automatic fallback from that custom path\.

**What changes\?**&#32;An approved share would create a separate disclosure artifact or handler effect\,&#32;not a new conversation identity\.

**What does not change\?**&#32;The default snapshot does not append sharing entries to the source journal\.&#32;Encryption and redaction operate on the outgoing representation\,&#32;not as an erasure operation on the original\.

**Recorded check\.**&#32;Intercepted default sharing encrypted a fictional snapshot\,&#32;removed a configured synthetic secret\,&#32;retained an unmatched fictional string\,&#32;left source entries unchanged\,&#32;and did not collect adjacent nested sessions\.

**Self\-check\.**&#32;Can Noor assume that a custom handler receives the same sanitized data as default sharing\?

**Answer\:**&#32;No\.&#32;It receives ordinary HTML under a separate contract\.

### Redaction is conditional and field\-specific

`share.redactSecrets: true`&#32;is not a universal privacy guarantee\.

The current default\-share path skips its typed redaction pass when there is no obfuscator or the obfuscator reports no configured\/recognized secret handling\.&#32;With&#32;`secrets.enabled`&#32;at its schema default of false\,&#32;the normal SDK path does not create that obfuscator\.

When active\,&#32;the typed pass rewrites selected text\-bearing fields\,&#32;including relevant\:

- Header title and cwd\.
- Current system prompt and tool descriptions\.
- Message text\,&#32;stored thinking text\,&#32;tool\-call arguments\,&#32;and error text\.
- Tool\-result content and execution output\.
- File\-mention paths and contents\.
- Summaries\,&#32;labels\,&#32;and title\-change text\.

It drops specified opaque provider replay material and untyped payloads\,&#32;such as certain&#32;`details`\,&#32;`data`\,&#32;output schemas\,&#32;and compaction preserve data\,&#32;rather than attempting a universal recursive scrub\.

Important limits remain\:

- Unknown or unconfigured strings can survive\.
- Image bytes remain intact before the later size\-trimming pass\.
- The typed header walk does not rewrite every possible path\-bearing field\.&#32;For example\,&#32;`additionalDirectories`&#32;is not rewritten by&#32;`redactShareHeader`\.
- IDs\,&#32;parent references\,&#32;and pseudonymous account\-related metadata can still be identifying or linkable\.
- Dropping a metadata field can also remove context a reviewer would otherwise need\.

The recorded check confirmed configured\-secret removal\,&#32;opaque tool\-result\-details omission\,&#32;small\-image preservation\,&#32;and complete skipping of redaction with an absent or empty obfuscator\.

Local HTML export does not run this share\-redaction pass\.&#32;A transcript may already contain some obfuscated content\,&#32;but that is not the same as auditing the output artifact\.

### Encryption protects a different boundary

Default sharing\:

1. Builds the snapshot\.
2. Applies the configured redaction pass when available\.
3. Gzips the JSON\.
4. Seals it using a fresh AES\-256\-GCM key and a 12\-byte IV\.
5. Uploads the sealed blob\.
6. Returns a viewer URL containing the key in its fragment after&#32;`#`\.

The recorded intercepted POST URL did not contain the fragment key\.&#32;Ordinary HTTP requests do not carry URL fragments automatically\.

But&#32;**possession of the complete link grants decryption access**\.&#32;A recipient can forward it\.&#32;Messages\,&#32;screenshots\,&#32;browser history\,&#32;and other places where the complete link is stored can become access\-bearing copies\.

Do not turn “the key is in the fragment” into “no client\-side code or recipient can disclose it\.” The viewer is part of the trust boundary\.

Encryption is not redaction\,&#32;anonymity\,&#32;access approval\,&#32;or secure deletion\.

### Size trimming is loss\,&#32;not privacy review

The production sealed\-byte budgets are\:

- Share server\:&#32;**1\,000\,000 bytes**\.
- Gist route\:&#32;**5\,000\,000 bytes**\,&#32;before base64 expansion\.

When a snapshot is too large\,&#32;the implementation progressively\:

1. Replaces large inline image payloads and large data URLs\.
2. Caps long strings at lengths of 32\,768\,&#32;8\,192\,&#32;2\,048\,&#32;then 512\.
3. Removes oldest entries by repeatedly halving the retained entry list while more than four entries remain\.
4. Throws if the result still cannot fit\.

The string caps are implementation string\-length caps\,&#32;distinct from the final sealed\-byte budget\.

The result reports truncation\,&#32;and the command can display a note that large content was trimmed\.&#32;Trimming can remove evidence or qualifiers\.&#32;It is not a secret detector and does not make surviving content safe\.

The recorded trimming tests used a smaller explicit 4\,000\-byte budget\,&#32;confirmed image\/text trimming and unchanged originals\,&#32;and checked an impossible\-budget error\.&#32;They did not upload a production\-size packet\.

### Gist fallback is not custom\-handler fallback

Optional&#32;`share.store: gist`&#32;tries the gist route when&#32;`gh`&#32;is installed and authenticated\.&#32;It stores the sealed blob base64\-encoded as&#32;`session.ompshare.txt`&#32;in a secret gist\.

If&#32;`gh`&#32;is unusable or gist creation fails\,&#32;default sharing can fall back to the share server\.

That fallback matters for disclosure policy\:&#32;approving one destination is not automatically approving the fallback destination\.

**Recorded check\.**&#32;A deliberately unauthenticated fake&#32;`gh`&#32;received only&#32;`auth status`\.&#32;No gist was created\.&#32;The code fell back to one intercepted server POST\.

By contrast\,&#32;a TUI custom handler is discovered in the active&#32;`getAgentDir()`&#32;in this order\:

1. `share.ts`
2. `share.js`
3. `share.mjs`

The first existing candidate must default\-export the expected function\.&#32;The ordinary default location is under&#32;`~/.omp/agent`\,&#32;but profile\/agent\-directory resolution can change that location\.

If loading fails\,&#32;the command errors and returns\.&#32;If execution throws\,&#32;it errors and returns\.&#32;**Neither failure falls back to default sharing\.**

A custom handler is executable code\,&#32;not a declarative upload destination\.&#32;Have its policy reviewed by its maintainer rather than assuming the default encryption or redaction settings constrain it\.

Its result can be\:

- A URL string\.
- An object with optional&#32;`url`&#32;and\/or&#32;`message`\.
- `undefined`\,&#32;which produces a generic shared status\.

A generic status is not independent proof that a handler uploaded anything\.

### Milestone\:&#32;Interpret cancellation without assuming revocation

**Need\.**&#32;Noor wants to stop a sharing action\.

**Obstacle\.**&#32;Restoring the editor and cancelling transport work are different events\.

This is a recorded\-boundary exercise\,&#32;not an instruction to start an upload and press Escape\.

The TUI loader has an abort signal\,&#32;but&#32;`handleShareCommand`&#32;does not pass that signal into default&#32;`shareSession`&#32;or the custom callback\.

The recorded default sequence was\:

1. An intercepted POST began and was held pending\.
2. The real loader handled Escape\.
3. The UI reported&#32;`Share cancelled`\.
4. No transport abort signal had been supplied\.
5. The held operation completed afterward\.
6. The late URL was not displayed or opened\.

The recorded custom sequence likewise completed a callback effect after Escape\.&#32;Its temporary HTML remained while the handler was pending and was removed after settlement\.

**What changes on Escape\?**&#32;The editor is restored\,&#32;the loader is cancelled\,&#32;and later result display\/opening is suppressed\.

**What does not follow\?**&#32;A started upload or custom effect is not necessarily stopped\,&#32;undone\,&#32;or revoked\.

Temporary custom HTML is removed in&#32;`finally`&#32;after settlement\,&#32;with cleanup errors ignored\.&#32;A crash or failed cleanup can leave it behind\.&#32;“Temporary” is not an erasure guarantee\.

**Failure and recovery\.**&#32;Treat a cancelled or ambiguous share as possibly completed until the destination is checked through an approved process\.&#32;Do not repeat the share merely to recover a missing URL\.&#32;Do not use&#32;`/clear`\,&#32;`/new`\,&#32;or&#32;`/drop`&#32;as upload revocation\.

A server error also does not establish that nothing reached the remote system\.&#32;The supplied HTTP\-error check observed one intercepted POST and error propagation\,&#32;not a universal remote non\-delivery guarantee\.

No generic revoke\/delete\-link workflow is established by this evidence\.

**Self\-check\.**&#32;Noor sees&#32;`Share cancelled`\.&#32;Is that enough to tell an owner that nothing was uploaded\?

**Answer\:**&#32;No\.

**Source anchors\:**&#32;`packages/coding-agent/src/export/share.ts`&#32;—&#32;`buildShareSnapshot`\,&#32;`redactShareHeader`\,&#32;`redactShareEntry`\,&#32;`redactShareMessage`\,&#32;`shareSession`\,&#32;`sealToFit`\,&#32;`tryCreateGist`\,&#32;`uploadToServer`\;&#32;`packages/coding-agent/src/export/custom-share.ts`&#32;—&#32;`getCustomSharePath`\,&#32;`loadCustomShare`\;&#32;`packages/coding-agent/src/config/settings-schema.ts`&#32;— sharing and secrets settings\;&#32;`packages/coding-agent/src/sdk.ts`&#32;— obfuscator construction\;&#32;`packages/coding-agent/src/modes/controllers/command-controller.ts`&#32;—&#32;`handleShareCommand`\;&#32;`packages/tui/src/components/cancellable-loader.ts`&#32;—&#32;`handleInput`\.
