fix(ai): redact sensitive credentials in system prompt instructions

This commit is contained in:
usr_bin_roygbiv
2026-07-16 00:24:00 -05:00
committed by can1357
parent c55196eb30
commit fab31a2bae
2 changed files with 14 additions and 1 deletions
+4 -1
View File
@@ -1,5 +1,6 @@
import { $env } from "@oh-my-pi/pi-utils";
import type { ResponseInput, ResponseInputItem } from "./providers/openai-responses-wire";
import { redactSensitiveCredentials } from "./providers/transform-messages";
import type { CacheRetention, OpenAIResponsesHistoryPayload, ProviderPayload } from "./types";
type OpenAIResponsesReplayItem = ResponseInput[number];
@@ -9,7 +10,9 @@ export { isRecord } from "@oh-my-pi/pi-utils";
export function normalizeSystemPrompts(systemPrompt: readonly string[] | string | undefined | null): string[] {
if (systemPrompt === undefined || systemPrompt === null) return [];
const prompts = Array.isArray(systemPrompt) ? systemPrompt : typeof systemPrompt === "string" ? [systemPrompt] : [];
return prompts.map(prompt => prompt.toWellFormed()).filter(prompt => prompt.trim().length > 0);
return prompts
.map(prompt => redactSensitiveCredentials(prompt.toWellFormed()))
.filter(prompt => prompt.trim().length > 0);
}
export function normalizeToolCallId(id: string): string {
@@ -86,6 +86,16 @@ describe("openai-responses system prompt routing", () => {
expect(input.every(m => m.role !== "system")).toBe(true);
});
it("redacts sensitive credentials in instructions", async () => {
const context: Context = {
systemPrompt: ["Token: gho_************************************"],
messages: [{ role: "user", content: "hi", timestamp: Date.now() }],
};
const body = await captureRequestBody(gpt4oMiniModel, context);
expect(body.instructions).toBe("Token: [github_token_redacted]");
});
it("omits instructions field when there is no system prompt", async () => {
const context: Context = {
systemPrompt: undefined,