fix(kanban): redact secrets in kanban_create body - #94088
Closed
salch-cred wants to merge 1 commit into
Closed
salch-cred wants to merge 1 commit into
salch-cred wants to merge 1 commit into
Conversation
kanban_create was the only one of five kanban write paths that persisted body without redact_sensitive_text, allowing API keys to be stored in plaintext in kanban.db. Mirror _handle_comment by redacting body with force=True before create_task. Fixes NousResearch#92354
Contributor
Contributor
Author
|
Happy to consolidate — #92366's broader coverage (title redaction + integration tests) is the stronger PR. Mine was the minimal one-line mirror of _handle_comment. Either way the security gap gets closed. |
Contributor
Author
|
Deferring to #92366 which has broader coverage (title redaction + integration tests). Closing to keep the queue clean. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(kanban): redact secrets in kanban_create body
kanban_create was the only one of five kanban write paths that
persisted body without redact_sensitive_text, allowing API keys
to be stored in plaintext in kanban.db. Mirror _handle_comment
by redacting body with force=True before create_task.
Fixes #92354