mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-05 16:13:51 +00:00
Adds a v2 credential envelope next to the v1 tool-secret helpers: AES-256-GCM, a master key derived once per process from ENCRYPTION_SECRET_KEY, and a per-record key from HKDF over the owner's id, which is also the associated data, so a blob moved onto another user's row does not decrypt. The envelope names its key, so ENCRYPTION_SECRET_KEY_PREVIOUS keeps old rows readable during a rotation. Log redaction now also covers token_info, tokens and client_info, and the API warns at startup when the public default key is in use.
69 lines
2.0 KiB
Python
69 lines
2.0 KiB
Python
"""Secret redaction for reflected ``stack_logs`` data.
|
|
|
|
``stacks`` is built by reflecting every public attribute of runtime
|
|
objects (the ``llm`` component carries the deployment provider
|
|
``api_key`` and the caller's ``user_api_key``). The unified-logs endpoint
|
|
returns ``stacks`` to the client, so credentials must be scrubbed — at
|
|
write time for new rows, and at read time for rows written before
|
|
redaction existed.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
REDACTED = "[REDACTED]"
|
|
|
|
# Substrings marking a key as a credential. Compound token-count fields
|
|
# (``prompt_tokens`` / ``generated_tokens`` / ``token_budget`` / ...) are
|
|
# intentionally not matched: secret token forms are spelled out
|
|
# (``access_token`` etc.) and a bare ``token`` is handled separately.
|
|
_SECRET_SUBSTRINGS = (
|
|
"api_key",
|
|
"apikey",
|
|
"api_token",
|
|
"access_token",
|
|
"refresh_token",
|
|
"auth_token",
|
|
"id_token",
|
|
"session_token",
|
|
"secret",
|
|
"password",
|
|
"passwd",
|
|
"passphrase",
|
|
"private_key",
|
|
"credential",
|
|
"authorization",
|
|
"bearer",
|
|
# Connection secrets: an OAuth token_info blob, MCP token and client
|
|
# registration dicts (``client_secret`` is covered by ``secret``).
|
|
"token_info",
|
|
"client_info",
|
|
)
|
|
|
|
|
|
def is_secret_key(key: str) -> bool:
|
|
"""True when ``key`` names a credential that must not be persisted/returned."""
|
|
k = key.lower()
|
|
if k in ("token", "tokens"):
|
|
return True
|
|
return any(s in k for s in _SECRET_SUBSTRINGS)
|
|
|
|
|
|
def redact_secrets(obj):
|
|
"""Recursively replace secret-keyed values with ``[REDACTED]``.
|
|
|
|
Walks dicts and lists; leaf scalars pass through unchanged. ``None``
|
|
returns ``None`` so callers can redact an optional payload directly.
|
|
"""
|
|
if isinstance(obj, dict):
|
|
return {
|
|
k: (
|
|
REDACTED
|
|
if isinstance(k, str) and is_secret_key(k)
|
|
else redact_secrets(v)
|
|
)
|
|
for k, v in obj.items()
|
|
}
|
|
if isinstance(obj, list):
|
|
return [redact_secrets(v) for v in obj]
|
|
return obj
|