Claude query parameters - #1410
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The rule expansions are narrowly scoped and are validated with new tests covering both allowed and blocked query-parameter cases.
Pull request overview
This PR updates the Claude (Anthropic compliance API) sanitizer rules to allow additional query parameters needed for incremental/paginated discovery, and adds explicit tests to ensure the request allowlist behavior is enforced (allowed vs blocked query params).
Changes:
- Allow
order_byon/v1/compliance/apps/chatsto support org-wide incremental polling by update time. - Allow
updated_at.gteon/v1/compliance/apps/sessions/localto support “changed since last pass” polling. - Allow
limit/pageon/v1/compliance/organizationsand add tests that verify unrecognized params are blocked.
File summaries
| File | Description |
|---|---|
| java/core/src/test/java/co/worklytics/psoxy/rules/anthropic/ClaudeTests.java | Adds new invocation examples plus JUnit tests that assert query-param allowlisting blocks unknown params and permits newly required ones. |
| docs/sources/anthropic/claude/claude.yaml | Extends allowedQueryParams for specific Claude compliance endpoints to include order_by, updated_at.gte, and limit/page. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
aperez-worklytics
requested review from
eschultink
and removed request for
Copilot
September 2, 2026 13:00
eschultink
approved these changes
Sep 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rules updated after https://github.com/Worklytics/evalengin/pull/9028: including more query parameter in rules for Claude Compliance
Fixes
Features
Psoxy update
Logistics
Change implications
CHANGELOG.mdanything that will show up interraform plan/applythat isn'tobviously a no-op? no
alpha, requires major versionchange no