fix(logging): redact browser debug endpoint (#1622)

* fix(logging): redact browser debug endpoint

* fix(logging): redact prompt argv values
This commit is contained in:
Kai (Tam Nhu) Tran authored and GitHub committed 2026-06-30 13:07:46 -04:00
1 parent a77096ed7c
commit 138ead0e1e
3 files changed
+38 -3

No files matched your search

+1 -1
View File
@@ -548,7 +548,7 @@ export async function execClaudeWithCLIProxy(
keys: Object.keys(env)
.filter((key) => key.startsWith('CCS_BROWSER_'))
.sort(),
ws: env.CCS_BROWSER_DEVTOOLS_WS_URL || '',
hasDevtoolsWsUrl: Boolean(env.CCS_BROWSER_DEVTOOLS_WS_URL),
});
}
logEnvironment(env, webSearchEnv, verbose);
+17 -2
View File
@@ -12,7 +12,14 @@ const SENSITIVE_KEY_PATTERN =
/** CLI flags whose following argument should be redacted in argv arrays. */
const SENSITIVE_ARGV_FLAG_PATTERN =
/^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token)$/i;
/^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token|prompt)$/i;
/** Short CLI flags whose following argument should be redacted in argv arrays. */
const SENSITIVE_SHORT_ARGV_FLAG_PATTERN = /^-p$/;
/** CLI flags whose inline `--flag=value` payload should be redacted in argv arrays. */
const SENSITIVE_ARGV_ASSIGNMENT_PATTERN =
/^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token|prompt)=/i;
/** Bearer/Basic/Token auth-scheme prefix in raw string values. */
const AUTH_SCHEME_VALUE_PATTERN = /^(Bearer|Basic|Token)\s+\S+/;
@@ -126,8 +133,16 @@ export function redactArgv(argv: readonly string[]): string[] {
const out: string[] = [];
for (let i = 0; i < argv.length; i++) {
const arg = argv[i];
if (SENSITIVE_ARGV_ASSIGNMENT_PATTERN.test(arg)) {
const separatorIndex = arg.indexOf('=');
out.push(`${arg.slice(0, separatorIndex + 1)}[redacted]`);
continue;
}
out.push(arg);
if (SENSITIVE_ARGV_FLAG_PATTERN.test(arg) && i + 1 < argv.length) {
if (
(SENSITIVE_ARGV_FLAG_PATTERN.test(arg) || SENSITIVE_SHORT_ARGV_FLAG_PATTERN.test(arg)) &&
i + 1 < argv.length
) {
out.push('[redacted]');
i++;
}
@@ -136,4 +136,24 @@ describe('redactArgv', () => {
'[redacted]',
]);
});
it('redacts prompt values passed with -p and --prompt', () => {
expect(redactArgv(['glm', '-p', 'summarize secret account notes'])).toEqual([
'glm',
'-p',
'[redacted]',
]);
expect(redactArgv(['glm', '--prompt', 'summarize secret account notes'])).toEqual([
'glm',
'--prompt',
'[redacted]',
]);
});
it('redacts inline prompt and sensitive flag assignments', () => {
expect(
redactArgv(['glm', '--prompt=summarize secret account notes', '--api-key=plainsecret'])
).toEqual(['glm', '--prompt=[redacted]', '--api-key=[redacted]']);
});
});