Commit Graph

12 Commits

Author SHA1 Message Date
roboomp 7dadeab331 fix(coding-agent): hid secrets from advisor prompts
Stopped restoring placeholders inside opaque assistant thinking blocks and threaded the configured secret obfuscator into advisor session-update prompts.

Added regression coverage for thinking preservation and advisor prompt redaction.

Fixes #3237
2026-06-22 07:05:23 +00:00
can1357 7302a7ae96 feat(coding-agent): improved secret obfuscation and data protection
- Refined obfuscation logic to use granular, typed transformations instead of generic object traversal.
- Enforced an 8-character minimum for secret patterns and restricted redaction to user-authored content to prevent false positives.
- Preserved system prompts, tool schemas, and opaque remote replay data to maintain provider context and data integrity.
- Integrated protected snapshot exports with targeted redaction to safeguard sensitive information in shared sessions.
2026-06-22 01:13:52 +02:00
can1357 24c8bb24c6 feat(session): added modular session APIs and rebuilt listing/persistence behavior
- Added session-domain modules and exports for session-entries, context, listing, loader, and migrations.
- Changed persistence to async append writes plus writeTextAtomic, removing sync line APIs.
- Added compaction-aware session context rebuild with dangling tool-call cleanup.
- Added resumable session resolution with status inference, id/stem/suffix matching, and backup recovery.
2026-06-14 02:02:53 +02:00
roboomp aa4cd0ab2d fix(coding-agent): preserved tool schemas while redacting
Converted provider-facing tool parameters to wire JSON Schema before redaction so live Zod instances are not deep-cloned into plain objects.

Fixes #2146
2026-06-10 08:26:02 +02:00
roboomp 2a90108893 fix(coding-agent): hid secrets in provider requests
Redacted configured secrets across provider-facing system prompts, tool definitions, developer reminders, and assistant tool-call payloads before LLM requests.

Fixes #2146
2026-06-10 08:26:01 +02:00
can1357 7f88a0c24c refactor: restructured logger.time() API to accept function references with wall-clock markers
- Refactored logger.time() API to accept function references and arguments separately instead of wrapped callbacks.
- Replaced RingBuffer-based timing with wall-clock markers and async span tracking for improved timing accuracy.
- Updated 20+ call sites across executor, kernel, main, and tools modules to use new logger.time() signature.
- Removed parsePath() helper function and inlined path.split() calls in settings module.
- Added test case verifying model selection without auth validation during startup.
2026-04-08 08:47:32 +02:00
can1357 3d29a48e7a fix(coding-agent): fixed memory leak by cancelling idle compaction
- Fixed memory leak by cancelling idle compaction timer on event controller disposal.
- Fixed session resumption to preserve last non-empty session when starting fresh.
- Fixed stash detection to use git ref resolution instead of output parsing for reliability.
- Fixed secret obfuscation to deobfuscate restored session messages locally while keeping LLM messages obfuscated.
- Fixed stash pop operation to preserve staged changes with --index flag after task branch merges.
- Changed idle compaction settings from enum to numeric type for flexible configuration.
2026-04-05 03:50:52 +02:00
DeprecatedLuke 8023872f43 feat(coding-agent): switch secret placeholders to hash tokens 2026-04-04 11:54:34 +01:00
can1357 c0912708c1 refactor(coding-agent): centralized builtin slash command registry 2026-02-16 19:36:56 +01:00
can1357 fee42ed7f0 refactor(coding-agent): switch secrets config from JSON to YAML 2026-02-16 19:26:35 +01:00
can1357 f399b8e323 fix(coding-agent): fixes for PRs 80, 82, 85
- Parse --full as exact token in /changelog command
- Scope MCP disabled list to discovered servers only
- Guard malformed disabledServers config field
- Parse regex literal /pattern/flags syntax in secret entries
- Prevent infinite loop on zero-length regex matches
- Replace longer plain secrets before shorter prefixes
- Default secrets.enabled to false
2026-02-16 19:23:37 +01:00
luk 2924495bfd feat(secrets): add secret obfuscation with regex flags support 2026-02-15 17:02:33 +00:00