[Browser Run] Document session guardrails - #32876
Open
meddulla wants to merge 7 commits into
Open
Conversation
meddulla
requested review from
a team,
Refaerds,
celso,
jonnyparris,
kathayl,
mchenco,
omarmosid and
ruifigueira
as code owners
August 19, 2026 23:45
meddulla
marked this pull request as draft
August 19, 2026 23:46
Contributor
Review
👉 Fix in your agent 👈Fix the following review findings in PR #32876 (https://github.com/cloudflare/cloudflare-docs/pull/32876).
Before making changes, review each finding and present a brief summary table:
- For each finding, state whether you agree, disagree, or need clarification
- If you disagree (e.g. the fix requires disproportionate effort for minimal benefit,
or the finding is factually incorrect), explain why
- If you need clarification before deciding, ask those questions
- Then share your plan for which issues to tackle and in what order
After triaging, follow this order:
1. Post a comment on this PR for any findings you are skipping, with the finding ID and your reasoning.
2. Then commit the fixes for the legitimate findings.
The comment must come before the commit — the bot reads PR comments when a new
push triggers a review, so skip comments posted after the push will be missed.
---
## Code Review
### Warnings (1)
#### CR-4d3413f8ce1b · API conflation: session guardrails vs. Live View readonly
- **File:** `src/content/changelog/browser-run/2026-08-20-guardrails.mdx` line 24
- **Issue:** The post defines guardrails as a per-session, immutable host allowlist, then tells readers to 'Set `guardrails` when generating a link' for a view-only Live View URL. But the existing Live View docs use `guardrails: { mode: 'readonly' }` only to restrict interactivity; that parameter does not accept `allowedDomains` or `allowedDomainSets`. This contradicts the earlier claim that guardrails cannot be changed after session acquisition.
- **Fix:** Clarify that the session's host-allowlist guardrails automatically apply to anything the session does, including a Live View stream. If you want to mention view-only sharing, describe it as a separate `guardrails: { mode: 'readonly' }` option on the Live View link, not as setting the same guardrails object again.
### Suggestions (1)
#### CR-f14326dcfe2c · Frontmatter conflates two features
- **File:** `src/content/changelog/browser-run/2026-08-20-guardrails.mdx` line 3
- **Issue:** The `description` says guardrails let you 'restrict which hosts a browser session can reach and share read-only views of a running session.' Sharing a read-only view is a Live View feature controlled by `guardrails: { mode: 'readonly' }`, not the new host-restriction guardrails.
- **Fix:** Keep the description focused on the host-allowlist capability only, and address read-only Live View separately in the body if needed.
Code ReviewThis code review is in beta and may not always be helpful — use your judgment. Warnings (1)
Suggestions (1)
ConventionsNo convention issues found. Style Guide ReviewNo style-guide issues found. CommandsOnly codeowners can run commands. Post a comment with the command to trigger it.
|
meddulla
force-pushed
the
feat/browser-run-guardrails
branch
from
August 20, 2026 00:00
ef40862 to
29b564e
Compare
meddulla
marked this pull request as ready for review
August 20, 2026 00:00
Co-authored-by: Simona Badoiu <simonaandreea.badoiu@gmail.com>
Contributor
|
Missing a "Verify guardrails are working" mini-section (make a request to a blocked host, expect 403 with the two headers) would help self-service debugging. Maybe? |
simonabadoiu
suggested changes
Aug 20, 2026
Co-authored-by: Simona Badoiu <simonaandreea.badoiu@gmail.com>
Co-authored-by: Simona Badoiu <simonaandreea.badoiu@gmail.com>
…udflare-docs into feat/browser-run-guardrails
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Document session guardrails for Browser Run
Documentation checklist