Commit Graph

11 Commits

Author SHA1 Message Date
can1357 0697e7f688 refactor(coding-agent): split secret obfuscator into domain modules
- Separated deterministic replacement generation, placeholder derivation,
  placeholder-range scanning and message-tree transforms out of the 2647-line
  module; obfuscator.ts now holds the types and SecretObfuscator.
- ephemeralPlaceholderKey stays a single instance and both global regexes stay
  beside the code that resets their lastIndex, so placeholder stability and
  the security argument in the moved comments are preserved verbatim.
- Repointed every importer at the real modules rather than leaving a re-export
  shim; the public ./secrets barrel exports the same 15 names as before.
2026-08-08 06:32:01 +02:00
Sunil Srivatsa 980ab4fd0a fix(coding-agent): harden archived stats cleanup 2026-08-01 17:17:46 -04:00
roboomp d868519149 fix(coding-agent): dropped Anthropic server-tool blocks from shares
Redacted assistant anthropicServerTool blocks alongside redactedThinking and providerPayload so /share never uploads raw server_tool_use input or web_search_tool_result encrypted_content.
2026-07-24 09:12:53 +00:00
Mathews-Tom d6fe21e079 fix(secrets): redact replay and title metadata 2026-07-12 00:12:01 +05:30
Mathews-Tom 2e4e215da2 fix(secrets): scan typed JSON collision values 2026-07-11 22:31:49 +05:30
Mathews-Tom 2e7c429586 fix(secrets): skip opaque payloads in regex pre-scan 2026-07-11 21:26:50 +05:30
Mathews-Tom 58d420a815 fix(secrets): skip raw image bytes in collision pre-scans
collectShareRegexSecretValues (export/share.ts) and
collectAdvisorRegexSecretValues (advisor/runtime.ts) only skipped
strings already shaped like a "data:image/..." URL, but
ImageContent.data at rest is raw base64 - that URL form only exists
in the rendered viewer. Every image payload was regex-scanned like
any other string, wasting CPU on large screenshots the advisor/share
output never even renders (images render as "[image]"/are left
byte-for-byte intact), and an accidental regex match inside the
base64 bytes could poison the whole-batch collision set used to
decide whether other fields' friendly-name placeholders are safe.
Skip type: "image" blocks entirely in both generic tree walks.
2026-07-09 01:03:29 +05:30
Mathews-Tom 7f3d9427af fix(secrets): share collision values in exports 2026-07-08 23:19:21 +05:30
can1357 26c72689c2 feat(coding-agent): added share.store setting for session uploads
- Added a `share.store` configuration option (`blob` | `gist`) that allows users to choose between the default share server or a GitHub gist for storing exported session data.
- Changed the default upload target from secret GitHub gists to the share server to avoid GitHub API rate limits for shared sessions.
- Enabled fallback to the share server when a gist upload fails or the GitHub CLI is unavailable.
2026-06-22 17:25:05 +02:00
can1357 7302a7ae96 feat(coding-agent): improved secret obfuscation and data protection
- Refined obfuscation logic to use granular, typed transformations instead of generic object traversal.
- Enforced an 8-character minimum for secret patterns and restricted redaction to user-authored content to prevent false positives.
- Preserved system prompts, tool schemas, and opaque remote replay data to maintain provider context and data integrity.
- Integrated protected snapshot exports with targeted redaction to safeguard sensitive information in shared sessions.
2026-06-22 01:13:52 +02:00
can1357 162c9ca422 feat(coding-agent): sealed /share behind encrypted links and embedded subagent transcripts in exports
- Added `src/export/share.ts`: `/share` now snapshots the session JSON, gzips and seals it with a fresh AES-256-GCM key, and pushes the blob to a secret gist or the share server (1 MB cap with image/string/entry truncation via `sealToFit`); links are `<serverUrl>/<id>#<key>` with the key only in the fragment.
- Added `share-loader.js` and `scripts/generate-share-viewer.ts` building the static viewer the relay serves at `GET /s/<id>`: it fetches the sealed blob, decrypts in-browser, and hands the JSON to the export template via `window.__OMP_SESSION_DATA__`.
- Reworked the `/share` command in `command-controller.ts`/`builtin-registry.ts` off the plaintext-gist HTML upload, exported `LoadedCustomShare`, and exposed the session `SecretObfuscator` getter on `AgentSession` for redaction.
- Added `share.serverUrl` and `share.redactSecrets` settings backed by `DEFAULT_SHARE_URL` from pi-wire.
- HTML exports now embed subagent transcripts: `collectSubSessions` walks `<session>/<AgentId>.jsonl` recursively into `SessionData.subSessions`, with `includeSubSessions` opt-out and the exported `buildSessionData` reused by share snapshots.
- Added `share.test.ts` (snapshot/seal/server-url contracts) and `export-subsessions.test.ts`.
2026-06-12 15:00:41 +02:00