Files
oh-my-pi/packages/coding-agent/test
Mathews-Tom 7d3a3a23a3 fix(coding-agent): reject unresolvable regex fallback and sanitize friendly-name collision check
Two Codex P2 findings on commit 732f725:

- A default (no custom replacement) mode: "replace" regex that cannot
  escape a 1-2 char match (e.g. ".", "[\\s\\S]", "[\\s\\S]{2}") had its
  key-derived same-length fallback marker returned without checking it
  against the matched value. Since that marker is drawn from an alphabet
  the regex has already proven to match exhaustively, a real 1-2 byte
  secret coinciding with it would ship unredacted. Such entries are now
  rejected: dropped with a warning when loaded from secrets.yml, dropped
  silently as a construction-time backstop otherwise.
- #friendlyNameCollidesWithSecret compared the sanitized (uppercased,
  alnum-only) friendly name against each secret's raw value, so a
  friendlyName that was a lowercase or punctuated variant of its own
  secret slipped through and stamped most of the secret into the
  placeholder. The secret value is now sanitized the same way before
  comparing.
2026-07-06 05:05:26 +05:30
..
2026-07-02 08:43:40 +00:00
2026-07-05 16:53:07 +02:00
2026-07-05 16:53:07 +02:00
2026-07-05 16:53:07 +02:00
2026-06-26 18:43:32 +02:00
2026-07-01 00:07:30 +00:00
2026-07-02 21:02:46 +00:00
2026-05-30 18:08:51 +02:00
2026-05-30 18:08:51 +02:00
2026-06-24 13:44:47 +00:00