fix(secrets): key placeholder base on exact secret value to block case-hint sibling synthesis

This commit is contained in:
Mathews-Tom
2026-06-19 21:40:54 +05:30
parent 6a91ca5bc1
commit 645a91f182
4 changed files with 52 additions and 18 deletions
+1 -1
View File
@@ -80,7 +80,7 @@ Each entry in the array has these fields:
This produces placeholders shaped like `#GITHUBTOKEN_AB12:L#`. The friendly name is sanitized to uppercase letters and digits, capped at 32 characters, and omitted if it sanitizes to an empty value. Invalid optional `friendlyName` metadata does not disable the secret entry; the secret still obfuscates with an unlabeled placeholder.
The hash base is an HMAC of the secret under a private per-install key (stored at `~/.omp/secret-placeholder.key`, never sent to a model), so a transcript reader cannot dictionary the placeholder back to the secret. For non-mixed casing the key is the case-folded value, so casing variants share a base distinguished by a case hint suffix:
The hash base is an HMAC of the secret under a private per-install key (stored at `~/.omp/secret-placeholder.key`, never sent to a model), so a transcript reader cannot dictionary the placeholder back to the secret. The base is keyed on the exact secret value, so two secrets that differ only by case get independent bases and a provider that sees one placeholder cannot synthesize another secret's token by swapping the hint. A case hint suffix labels the casing of the redacted value for the model:
| Hint | Meaning |
| ---- | -------------------------------------------- |