fix(ai): redact sensitive credentials in system prompt instructions
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
import { $env } from "@oh-my-pi/pi-utils";
|
||||
import type { ResponseInput, ResponseInputItem } from "./providers/openai-responses-wire";
|
||||
import { redactSensitiveCredentials } from "./providers/transform-messages";
|
||||
import type { CacheRetention, OpenAIResponsesHistoryPayload, ProviderPayload } from "./types";
|
||||
|
||||
type OpenAIResponsesReplayItem = ResponseInput[number];
|
||||
@@ -9,7 +10,9 @@ export { isRecord } from "@oh-my-pi/pi-utils";
|
||||
export function normalizeSystemPrompts(systemPrompt: readonly string[] | string | undefined | null): string[] {
|
||||
if (systemPrompt === undefined || systemPrompt === null) return [];
|
||||
const prompts = Array.isArray(systemPrompt) ? systemPrompt : typeof systemPrompt === "string" ? [systemPrompt] : [];
|
||||
return prompts.map(prompt => prompt.toWellFormed()).filter(prompt => prompt.trim().length > 0);
|
||||
return prompts
|
||||
.map(prompt => redactSensitiveCredentials(prompt.toWellFormed()))
|
||||
.filter(prompt => prompt.trim().length > 0);
|
||||
}
|
||||
|
||||
export function normalizeToolCallId(id: string): string {
|
||||
|
||||
@@ -86,6 +86,16 @@ describe("openai-responses system prompt routing", () => {
|
||||
expect(input.every(m => m.role !== "system")).toBe(true);
|
||||
});
|
||||
|
||||
it("redacts sensitive credentials in instructions", async () => {
|
||||
const context: Context = {
|
||||
systemPrompt: ["Token: gho_************************************"],
|
||||
messages: [{ role: "user", content: "hi", timestamp: Date.now() }],
|
||||
};
|
||||
const body = await captureRequestBody(gpt4oMiniModel, context);
|
||||
|
||||
expect(body.instructions).toBe("Token: [github_token_redacted]");
|
||||
});
|
||||
|
||||
it("omits instructions field when there is no system prompt", async () => {
|
||||
const context: Context = {
|
||||
systemPrompt: undefined,
|
||||
|
||||
Reference in New Issue
Block a user