diff --git a/src/cliproxy/executor/index.ts b/src/cliproxy/executor/index.ts index cb389095..d2fc4c76 100644 --- a/src/cliproxy/executor/index.ts +++ b/src/cliproxy/executor/index.ts @@ -548,7 +548,7 @@ export async function execClaudeWithCLIProxy( keys: Object.keys(env) .filter((key) => key.startsWith('CCS_BROWSER_')) .sort(), - ws: env.CCS_BROWSER_DEVTOOLS_WS_URL || '', + hasDevtoolsWsUrl: Boolean(env.CCS_BROWSER_DEVTOOLS_WS_URL), }); } logEnvironment(env, webSearchEnv, verbose); diff --git a/src/services/logging/log-redaction.ts b/src/services/logging/log-redaction.ts index 79a65dd7..8218e4e4 100644 --- a/src/services/logging/log-redaction.ts +++ b/src/services/logging/log-redaction.ts @@ -12,7 +12,14 @@ const SENSITIVE_KEY_PATTERN = /** CLI flags whose following argument should be redacted in argv arrays. */ const SENSITIVE_ARGV_FLAG_PATTERN = - /^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token)$/i; + /^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token|prompt)$/i; + +/** Short CLI flags whose following argument should be redacted in argv arrays. */ +const SENSITIVE_SHORT_ARGV_FLAG_PATTERN = /^-p$/; + +/** CLI flags whose inline `--flag=value` payload should be redacted in argv arrays. */ +const SENSITIVE_ARGV_ASSIGNMENT_PATTERN = + /^--(token|api[_-]?key|auth|auth[_-]?token|secret|bearer|password|client[_-]?secret|refresh[_-]?token|access[_-]?token|id[_-]?token|prompt)=/i; /** Bearer/Basic/Token auth-scheme prefix in raw string values. */ const AUTH_SCHEME_VALUE_PATTERN = /^(Bearer|Basic|Token)\s+\S+/; @@ -126,8 +133,16 @@ export function redactArgv(argv: readonly string[]): string[] { const out: string[] = []; for (let i = 0; i < argv.length; i++) { const arg = argv[i]; + if (SENSITIVE_ARGV_ASSIGNMENT_PATTERN.test(arg)) { + const separatorIndex = arg.indexOf('='); + out.push(`${arg.slice(0, separatorIndex + 1)}[redacted]`); + continue; + } out.push(arg); - if (SENSITIVE_ARGV_FLAG_PATTERN.test(arg) && i + 1 < argv.length) { + if ( + (SENSITIVE_ARGV_FLAG_PATTERN.test(arg) || SENSITIVE_SHORT_ARGV_FLAG_PATTERN.test(arg)) && + i + 1 < argv.length + ) { out.push('[redacted]'); i++; } diff --git a/tests/unit/services/logging/log-redaction-extended.test.ts b/tests/unit/services/logging/log-redaction-extended.test.ts index 44b87849..7b5b2402 100644 --- a/tests/unit/services/logging/log-redaction-extended.test.ts +++ b/tests/unit/services/logging/log-redaction-extended.test.ts @@ -136,4 +136,24 @@ describe('redactArgv', () => { '[redacted]', ]); }); + + it('redacts prompt values passed with -p and --prompt', () => { + expect(redactArgv(['glm', '-p', 'summarize secret account notes'])).toEqual([ + 'glm', + '-p', + '[redacted]', + ]); + + expect(redactArgv(['glm', '--prompt', 'summarize secret account notes'])).toEqual([ + 'glm', + '--prompt', + '[redacted]', + ]); + }); + + it('redacts inline prompt and sensitive flag assignments', () => { + expect( + redactArgv(['glm', '--prompt=summarize secret account notes', '--api-key=plainsecret']) + ).toEqual(['glm', '--prompt=[redacted]', '--api-key=[redacted]']); + }); });