Dashboard › cli › Distillation
14a14a26-6ee7-43b1-bbdd-6821f5b81da4["lore_tm_v1_JsVn8B5BGX8HHhZ1kHC13BxlDfEQxbqK8QkKP0LZnGg","lore_tm_v1_Y-4H7hIC-4h6WOexItbV46m--Z-pA-Om8H_e_EH1mgU"]
Date: Sep 10, 2026
sntrys_ claim versus request-host mismatch, the token must never hit the wire.packages/cli/test/lib/security/refresh-token-poison.test.ts contains CVE defense-in-depth coverage for sntrys_ claim/request mismatches, including: direct request to sentry.secondhost.com that matches environment scope but not token claim; invalid claim URL fallback to SaaS; region-URL extension trust behavior; and sntryu_ user-auth tokens having no claim and therefore taking a distinct claim-check path.setOrgRegion()/setOrgRegions(), showing broad existing test dependence on the region-cache APIs across packages/cli/test/lib/, packages/cli/test/lib/api/, packages/cli/test/commands/, and packages/cli/test/lib/db/model-based.test.ts; results were truncated after 100 matches.packages/cli/test/lib/api-client.coverage.test.ts, api-client.test.ts, api-client.seer.test.ts, api-client.seer-trial.test.ts, api-client.multiregion.test.ts, api/replays.test.ts, api/releases.test.ts, api/projects.test.ts, api/events-overshoot.test.ts, api/alerts.test.ts, resolve-target.test.ts, resolve-target-listing.test.ts, resolve-effective-org.test.ts, region.test.ts, db/model-based.test.ts, hex-id-recovery.adapters.test.ts, complete.test.ts, commands/issue/utils.test.ts, commands/trace/view.func.test.ts, commands/trace/list.test.ts, commands/team/list.test.ts, commands/span/view.test.ts, and commands/issue/list.test.ts.