Skip to content

fix(#8093): align INPUT_SANITIZER_ENABLED default to true across all docs - #8185

Merged
diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.49from
rafaumeu:fix/env-docs-input-sanitizer-8093
Jul 23, 2026
Merged

diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.49from
rafaumeu:fix/env-docs-input-sanitizer-8093

Conversation

@rafaumeu

Copy link
Copy Markdown
Contributor

Summary

The runtime default for INPUT_SANITIZER_ENABLED is enabled (any value that is not exactly "false"), but docs and .env.example incorrectly presented it as opt-in (default false).

Changes

  • .env.example: changed commented example from # INPUT_SANITIZER_ENABLED=true to # INPUT_SANITIZER_ENABLED=false with note "Enabled by default. Set to "false" to disable."
  • 41 i18n translations of ENVIRONMENT.md updated from \false`to`true``
  • tests/unit/env-docs-input-sanitizer-8093.test.ts: consistency tests verifying code/docs/env.example alignment

Fixes #8093

@rafaumeu
rafaumeu requested a review from diegosouzapw as a code owner July 22, 2026 16:15
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks for tracking down the docs/runtime mismatch — verified: INPUT_SANITIZER_ENABLED really does default to enabled at runtime (!== "false" in both src/lib/guardrails/promptInjection.ts and src/shared/utils/inputSanitizer.ts), so aligning .env.example and the 41 ENVIRONMENT.md translations to true is the right call, and tests/unit/env-docs-input-sanitizer-8093.test.ts passes cleanly.

One thing I want to flag before this merges: the branch carries 8 commits, but only the last one (fix(docs): align INPUT_SANITIZER_ENABLED default to true across all docs) matches this PR's title/description. The other 7 are unrelated fixes for #8074, #8072, #8059, #8081, #8056 (x2) and #8141 that aren't mentioned in the summary. A few of those (the #8081 reasoning-placeholder commit especially) are byte-identical to commits already sitting in your other open PRs (#8110, #8179) — and #8081's version here would actually conflict with #7912, which already shipped a different (and currently wired-in) fix for that same leak on the release branch.

To keep things clean I'll cherry-pick just the #8093 commit onto the current tip and merge that in isolation — no action needed from you unless you'd rather rebase this branch down to a single commit yourself. Nothing else to change on the docs fix itself — nice catch.

@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.49 July 22, 2026 18:28
@rafaumeu
rafaumeu force-pushed the fix/env-docs-input-sanitizer-8093 branch 4 times, most recently from e06f2a1 to 7441966 Compare July 22, 2026 22:32
@mergify

mergify Bot commented Jul 22, 2026

Copy link
Copy Markdown

⚠️ The sha of the head commit of this PR conflicts with #8113. Mergify cannot evaluate rules on this PR. Once #8113 is merged or closed, Mergify will resume processing this PR. ⚠️

@rafaumeu
rafaumeu force-pushed the fix/env-docs-input-sanitizer-8093 branch 4 times, most recently from c680293 to 3bdf35c Compare July 23, 2026 02:10
rafaumeu added 2 commits July 22, 2026 23:44
Code defaults INPUT_SANITIZER_ENABLED to enabled (any value that is
not exactly 'false'). Updated .env.example and 41 i18n translations
of ENVIRONMENT.md to match this default instead of showing false.

Fixes diegosouzapw#8093
@rafaumeu
rafaumeu force-pushed the fix/env-docs-input-sanitizer-8093 branch from 3bdf35c to 00e3e3f Compare July 23, 2026 02:47
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks, @rafaumeu! 🙏 Merged — aligns the INPUT_SANITIZER_ENABLED docs to the on-by-default reality across the English ENVIRONMENT.md, all 41 i18n translations, and .env.example (now shows =false as the disable toggle), plus a regression guard test. This complements #8113/#8124 (which covered the English docs) by propagating the correction to every locale. Rebased onto the current release tip. typecheck + i18n key-coverage + glossary gates green.

@diegosouzapw
diegosouzapw merged commit 7c07c9d into diegosouzapw:release/v3.8.49 Jul 23, 2026
2 of 5 checks passed
@diegosouzapw diegosouzapw mentioned this pull request Jul 23, 2026
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
… across all docs (diegosouzapw#8185)

* fix(ci): resolve upstream-inherited check failures

* fix(docs): align INPUT_SANITIZER_ENABLED default to true across all docs

Code defaults INPUT_SANITIZER_ENABLED to enabled (any value that is
not exactly 'false'). Updated .env.example and 41 i18n translations
of ENVIRONMENT.md to match this default instead of showing false.

Fixes diegosouzapw#8093

---------

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
… across all docs (diegosouzapw#8185)

* fix(ci): resolve upstream-inherited check failures

* fix(docs): align INPUT_SANITIZER_ENABLED default to true across all docs

Code defaults INPUT_SANITIZER_ENABLED to enabled (any value that is
not exactly 'false'). Updated .env.example and 41 i18n translations
of ENVIRONMENT.md to match this default instead of showing false.

Fixes diegosouzapw#8093

---------

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: remove stale packaged ENVIRONMENT.md showing INPUT_SANITIZER_ENABLED=false (live docs/code agree: true)

2 participants