feat(video): redact transcript in the in-memory pending-request snapshot (#12430 item 6) - #12596
Conversation
…t snapshot (#12430 item 6) trackPendingRequest (open-sse/handlers/chatCore.ts) stored the raw client body (with video transcript/audioTranscript cues) under `clientRequest`, live-exposed via /api/usage/call-logs (pendingDetails), /api/logs/[id] and /api/conversations while a request is in-flight. P2a redacted the persisted detailed-log snapshot but not this in-memory copy. Add redactPendingBody() to videoBridgeSnapshotRedaction.ts (sibling to logClientRawRequestRedacted from P2a): when videoBridgeObserved, returns the redacted clone from redactVideoTranscriptFieldsForLog; otherwise returns the exact same reference. Wire it into the trackPendingRequest call site (chatCore.ts:934), keeping the file within its frozen 5976-line budget (5971 -> 5974).
/sweep-reds round 6 — FQG diagnosis (no code change)
Reproduced on a clean tip checkout ( Cause: Own complexity / file-size / mutation: green (complexity new-code 0, file-size OK, tap.testFiles no drift). Not merging origin/release into this PR (base-red #12581 OPEN). Holding until a base-reds PR retargets the allowlist line-key (302 → 313). |
…ogs (#12430 item 4) Extend applyVideoBridgeLogRedaction with a string-content branch: pipeline-strategy stages, smart-auto-pipeline, and context-handoff summaries embed the transcript as a substring of a rendered prompt string rather than an exact array part, so the existing exact part-array match silently skipped them. Adds a mutually-exclusive string branch (Array.isArray vs typeof === "string") that does a replaceAll of the trusted fullText literal against a lazily cloned message, reusing the existing rootClone/clonedContainers/clonedMessages clone-on-write pattern so siblings keep original references and the input is never mutated.
|
Merging (item 6 + P2c). The only red — "Fast Quality Gates" — fails on |
…hot (diegosouzapw#12430 item 6) (diegosouzapw#12596) * feat(video): redact transcript fields in the in-memory pending-request snapshot (diegosouzapw#12430 item 6) trackPendingRequest (open-sse/handlers/chatCore.ts) stored the raw client body (with video transcript/audioTranscript cues) under `clientRequest`, live-exposed via /api/usage/call-logs (pendingDetails), /api/logs/[id] and /api/conversations while a request is in-flight. P2a redacted the persisted detailed-log snapshot but not this in-memory copy. Add redactPendingBody() to videoBridgeSnapshotRedaction.ts (sibling to logClientRawRequestRedacted from P2a): when videoBridgeObserved, returns the redacted clone from redactVideoTranscriptFieldsForLog; otherwise returns the exact same reference. Wire it into the trackPendingRequest call site (chatCore.ts:934), keeping the file within its frozen 5976-line budget (5971 -> 5974). * feat(video): substring-redact transcript in derived-prompt dispatch logs (diegosouzapw#12430 item 4) Extend applyVideoBridgeLogRedaction with a string-content branch: pipeline-strategy stages, smart-auto-pipeline, and context-handoff summaries embed the transcript as a substring of a rendered prompt string rather than an exact array part, so the existing exact part-array match silently skipped them. Adds a mutually-exclusive string branch (Array.isArray vs typeof === "string") that does a replaceAll of the trusted fullText literal against a lazily cloned message, reusing the existing rootClone/clonedContainers/clonedMessages clone-on-write pattern so siblings keep original references and the input is never mutated.
What
Closes retention surface #6 from #12430 (surfaced by the P2a review):
trackPendingRequest(open-sse/handlers/chatCore.ts:931) stored the RAW client body — withtranscript/audioTranscript— in the in-memory pending-requests structure, live-exposed via/api/usage/call-logs(pendingDetails),/api/logs/[id]and/api/conversationswhile a request is in-flight. P2a (#12528) redacted the persisted detailed-log snapshot but not this in-memory sibling.When
videoBridgeObserved, the storedclientRequestis now run throughredactPendingBody→ the same P2aredactVideoTranscriptFieldsForLoghelper (structured field redaction, parse-free, un-bypassable). Non-observed path passes the exact same reference (no clone); the model-bound body is untouched.Validation
TDD (RED→GREEN);
videoBridgeSnapshotRedaction10/10, siblings green;typecheck:core+prettier --checkclean. File-size: chatCore.ts 5974 ≤ 5976 (frozen), baseline untouched — the helper name was chosen to stay within the budget.Refs #12150, #12430 (P2 surface 6). No DB migration.⚠️ base-red inherited: #12581.