The File Fence Lab
A Friday review often begins with a polite subject line. The patch claims to fix a 504 on /invoice . Then the file list arrives: a new Redis helper, a line in requirements.txt , a port in docker-compose.yml , and a comment that the timeout was “probably a cache miss.” Nobody asked for a cache. The timeout lived in one function. The model widened the job because nothing in the repo told it where…
The File Fence Lab revolves around a critique of AI's scope limitations and the importance of file-level controls. The lab features a short story involving an invoice handler with a timeout bug, displayed in a demo. Using AI coding loops, students write a fence.txt file with paths for production modules and tests. They then implement a checker that flags files outside the allowed list. The lab concludes with a replay of the prompt both with and without the checker, demonstrating the necessity of the fence rule.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.