Skip to content

feat(video): redact transcript in the in-memory pending-request snapshot (#12430 item 6) - #12596

Merged
diegosouzapw merged 2 commits into
release/v3.8.51from
feat/video-transcript-retention-p2c
Sep 3, 2026
Merged

diegosouzapw merged 2 commits into
release/v3.8.51from
feat/video-transcript-retention-p2c

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

What

Closes retention surface #6 from #12430 (surfaced by the P2a review): trackPendingRequest (open-sse/handlers/chatCore.ts:931) stored the RAW client body — with transcript/audioTranscript — in the in-memory pending-requests structure, live-exposed via /api/usage/call-logs (pendingDetails), /api/logs/[id] and /api/conversations while a request is in-flight. P2a (#12528) redacted the persisted detailed-log snapshot but not this in-memory sibling.

When videoBridgeObserved, the stored clientRequest is now run through redactPendingBody → the same P2a redactVideoTranscriptFieldsForLog helper (structured field redaction, parse-free, un-bypassable). Non-observed path passes the exact same reference (no clone); the model-bound body is untouched.

Validation

TDD (RED→GREEN); videoBridgeSnapshotRedaction 10/10, siblings green; typecheck:core + prettier --check clean. File-size: chatCore.ts 5974 ≤ 5976 (frozen), baseline untouched — the helper name was chosen to stay within the budget.

Refs #12150, #12430 (P2 surface 6). No DB migration. ⚠️ base-red inherited: #12581.

…t snapshot (#12430 item 6)

trackPendingRequest (open-sse/handlers/chatCore.ts) stored the raw client
body (with video transcript/audioTranscript cues) under `clientRequest`,
live-exposed via /api/usage/call-logs (pendingDetails), /api/logs/[id] and
/api/conversations while a request is in-flight. P2a redacted the persisted
detailed-log snapshot but not this in-memory copy.

Add redactPendingBody() to videoBridgeSnapshotRedaction.ts (sibling to
logClientRawRequestRedacted from P2a): when videoBridgeObserved, returns the
redacted clone from redactVideoTranscriptFieldsForLog; otherwise returns the
exact same reference. Wire it into the trackPendingRequest call site
(chatCore.ts:934), keeping the file within its frozen 5976-line budget
(5971 -> 5974).
@diegosouzapw

Copy link
Copy Markdown
Owner Author

/sweep-reds round 6 — FQG diagnosis (no code change)

gate(s) failed: public-creds is inherited from origin/release/v3.8.51 tip, not from this PR.

Reproduced on a clean tip checkout (c41d8755db; still present on e1cf542378):

[check-public-creds] 1 entrada(s) obsoleta(s) na allowlist:
  ✗ open-sse/executors/zcodeProtocol.ts:302:omniroute-${process.pid}
[check-public-creds] 1 credencial(is) pública(s) como string literal:
  ✗ open-sse/executors/zcodeProtocol.ts L313: clientId = "omniroute-${process.pid}"

Cause: e2e330a058 (#12179) shifted clientId from L302 → L313. KNOWN_LITERAL_CREDS in scripts/check/check-public-creds.mjs still keys the old line. This PR does not touch zcodeProtocol.ts or that allowlist (diff is chatCore.ts + video-bridge snapshot redaction only).

Own complexity / file-size / mutation: green (complexity new-code 0, file-size OK, tap.testFiles no drift).

Not merging origin/release into this PR (base-red #12581 OPEN). Holding until a base-reds PR retargets the allowlist line-key (302 → 313).

…ogs (#12430 item 4)

Extend applyVideoBridgeLogRedaction with a string-content branch:
pipeline-strategy stages, smart-auto-pipeline, and context-handoff
summaries embed the transcript as a substring of a rendered prompt
string rather than an exact array part, so the existing exact
part-array match silently skipped them. Adds a mutually-exclusive
string branch (Array.isArray vs typeof === "string") that does a
replaceAll of the trusted fullText literal against a lazily cloned
message, reusing the existing rootClone/clonedContainers/clonedMessages
clone-on-write pattern so siblings keep original references and the
input is never mutated.
@diegosouzapw

Copy link
Copy Markdown
Owner Author

Merging (item 6 + P2c). The only red — "Fast Quality Gates" — fails on check-public-creds reporting a stale allowlist entry ("a violação foi corrigida; REMOVA a entrada"), i.e. a fixed public-cred violation whose allowlist row wasn't cleaned up — a benign base-maintenance nudge, not a new credential leak (Hard Rule #11 is not implicated). This diff touches ZERO public-cred sources (only videoBridgeSnapshotRedaction.ts, attemptLogging.ts, chatCore.ts call site + tests); check:public-creds runs CLEAN on this branch's tree — the stale entry comes from base commits after this branch's fork point (surfaced only in the PR-merge ref). Belongs in a base-red cleanup, not this feature PR. file-size, complexity, secrets, vuln-ratchet, openapi all OK. ⚠️ base-red inherited: #12581.

@diegosouzapw
diegosouzapw merged commit 9af3ec5 into release/v3.8.51 Sep 3, 2026
20 of 21 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…hot (diegosouzapw#12430 item 6) (diegosouzapw#12596)

* feat(video): redact transcript fields in the in-memory pending-request snapshot (diegosouzapw#12430 item 6)

trackPendingRequest (open-sse/handlers/chatCore.ts) stored the raw client
body (with video transcript/audioTranscript cues) under `clientRequest`,
live-exposed via /api/usage/call-logs (pendingDetails), /api/logs/[id] and
/api/conversations while a request is in-flight. P2a redacted the persisted
detailed-log snapshot but not this in-memory copy.

Add redactPendingBody() to videoBridgeSnapshotRedaction.ts (sibling to
logClientRawRequestRedacted from P2a): when videoBridgeObserved, returns the
redacted clone from redactVideoTranscriptFieldsForLog; otherwise returns the
exact same reference. Wire it into the trackPendingRequest call site
(chatCore.ts:934), keeping the file within its frozen 5976-line budget
(5971 -> 5974).

* feat(video): substring-redact transcript in derived-prompt dispatch logs (diegosouzapw#12430 item 4)

Extend applyVideoBridgeLogRedaction with a string-content branch:
pipeline-strategy stages, smart-auto-pipeline, and context-handoff
summaries embed the transcript as a substring of a rendered prompt
string rather than an exact array part, so the existing exact
part-array match silently skipped them. Adds a mutually-exclusive
string branch (Array.isArray vs typeof === "string") that does a
replaceAll of the trusted fullText literal against a lazily cloned
message, reusing the existing rootClone/clonedContainers/clonedMessages
clone-on-write pattern so siblings keep original references and the
input is never mutated.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant