mirror of
https://github.com/tiennm99/ccs.git
synced 2026-10-06 08:13:49 +00:00
fix(logging): redact browser debug endpoint (#1622)
* fix(logging): redact browser debug endpoint * fix(logging): redact prompt argv values
This commit is contained in:
1 parent
a77096ed7c
commit
138ead0e1e
3 files changed
+38
-3
No files matched your search
@@ -548,7 +548,7 @@ export async function execClaudeWithCLIProxy(
|
||||
keys: Object.keys(env)
|
||||
.filter((key) => key.startsWith('CCS_BROWSER_'))
|
||||
.sort(),
|
||||
ws: env.CCS_BROWSER_DEVTOOLS_WS_URL || '',
|
||||
hasDevtoolsWsUrl: Boolean(env.CCS_BROWSER_DEVTOOLS_WS_URL),
|
||||
});
|
||||
}
|
||||
logEnvironment(env, webSearchEnv, verbose);
|
||||
|
||||
@@ -12,7 +12,14 @@ const SENSITIVE_KEY_PATTERN =
|
||||
|
||||
/** CLI flags whose following argument should be redacted in argv arrays. */
|
||||
const SENSITIVE_ARGV_FLAG_PATTERN =
|
||||
/^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token)$/i;
|
||||
/^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token|prompt)$/i;
|
||||
|
||||
/** Short CLI flags whose following argument should be redacted in argv arrays. */
|
||||
const SENSITIVE_SHORT_ARGV_FLAG_PATTERN = /^-p$/;
|
||||
|
||||
/** CLI flags whose inline `--flag=value` payload should be redacted in argv arrays. */
|
||||
const SENSITIVE_ARGV_ASSIGNMENT_PATTERN =
|
||||
/^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token|prompt)=/i;
|
||||
|
||||
/** Bearer/Basic/Token auth-scheme prefix in raw string values. */
|
||||
const AUTH_SCHEME_VALUE_PATTERN = /^(Bearer|Basic|Token)\s+\S+/;
|
||||
@@ -126,8 +133,16 @@ export function redactArgv(argv: readonly string[]): string[] {
|
||||
const out: string[] = [];
|
||||
for (let i = 0; i < argv.length; i++) {
|
||||
const arg = argv[i];
|
||||
if (SENSITIVE_ARGV_ASSIGNMENT_PATTERN.test(arg)) {
|
||||
const separatorIndex = arg.indexOf('=');
|
||||
out.push(`${arg.slice(0, separatorIndex + 1)}[redacted]`);
|
||||
continue;
|
||||
}
|
||||
out.push(arg);
|
||||
if (SENSITIVE_ARGV_FLAG_PATTERN.test(arg) && i + 1 < argv.length) {
|
||||
if (
|
||||
(SENSITIVE_ARGV_FLAG_PATTERN.test(arg) || SENSITIVE_SHORT_ARGV_FLAG_PATTERN.test(arg)) &&
|
||||
i + 1 < argv.length
|
||||
) {
|
||||
out.push('[redacted]');
|
||||
i++;
|
||||
}
|
||||
|
||||
@@ -136,4 +136,24 @@ describe('redactArgv', () => {
|
||||
'[redacted]',
|
||||
]);
|
||||
});
|
||||
|
||||
it('redacts prompt values passed with -p and --prompt', () => {
|
||||
expect(redactArgv(['glm', '-p', 'summarize secret account notes'])).toEqual([
|
||||
'glm',
|
||||
'-p',
|
||||
'[redacted]',
|
||||
]);
|
||||
|
||||
expect(redactArgv(['glm', '--prompt', 'summarize secret account notes'])).toEqual([
|
||||
'glm',
|
||||
'--prompt',
|
||||
'[redacted]',
|
||||
]);
|
||||
});
|
||||
|
||||
it('redacts inline prompt and sensitive flag assignments', () => {
|
||||
expect(
|
||||
redactArgv(['glm', '--prompt=summarize secret account notes', '--api-key=plainsecret'])
|
||||
).toEqual(['glm', '--prompt=[redacted]', '--api-key=[redacted]']);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user