Repository navigation
Safe literal secret references: x-kody-secret-resolution opt-out header and inert placeholder convention - #676
Conversation
β¦ convention for literal placeholder text
|
No actionable comments were generated in the recent review. π βΉοΈ Recent review infoβοΈ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: π Files selected for processing (5)
π WalkthroughWalkthroughAdds an ChangesSecret resolution opt-out feature
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant Client
participant expandSecretPlaceholders
participant readSecretResolutionMode
participant SecretService
Client->>expandSecretPlaceholders: fetch request with x-kody-secret-resolution header
expandSecretPlaceholders->>readSecretResolutionMode: readSecretResolutionMode(headers)
readSecretResolutionMode-->>expandSecretPlaceholders: 'off' or 'on'
alt mode is off
expandSecretPlaceholders-->>Client: forwarded Request (placeholders literal)
else mode is on
expandSecretPlaceholders->>SecretService: resolveSecret(placeholder)
SecretService-->>expandSecretPlaceholders: resolved secret value
expandSecretPlaceholders-->>Client: forwarded Request (resolved)
end
Possibly related PRs
π₯ Pre-merge checks | β 5β Passed checks (5 passed)
β¨ Finishing Touchesπ Generate docstrings
π§ͺ Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
π Preview deployed: https://kody-pr-676.kody-a99.workers.dev Worker: Mocks:
|
Why
The fetch gateway resolves
{{secret:...}}placeholders on the final serialized request β URL, headers, and body β with no escape mechanism. Any prose that mentions the placeholder syntax (a Discord message, an issue body, docs written via API) either fails closed ("Secret β¦ was not found") or, worse, resolves a real secret into third-party-visible content. Discovered while shipping #674: a summary message about the placeholder syntax could not be sent through the gateway.What
x-kody-secret-resolution: offdisables placeholder resolution for one gateway fetch. The gateway strips the header before the request leaves, placeholders pass through literally, and no secret is resolved. Valueon(or omitting the header) keeps normal behavior; unknown values fail loudly so a typo cannot silently re-enable resolution. Out-of-band by design: only calling code can set a header, so attacker-controlled data in a URL or body can never disable resolution.{{secret:<name>}}as the way to mention placeholder syntax in prose β angle brackets are outside the placeholder name charset ([a-zA-Z0-9._-]), so the form can never resolve, in this request or any later one.docs/use/secrets-and-values.md(new "Mentioning placeholders without resolving them" section),docs/use/execute.md, anddocs/guides/secret-backed-integration.md, replacing the vague "obfuscate it" guidance with both concrete options and when to use each.System recap β extends existing primitives (medium risk)
Mode: recap Β· Base:
main@f456bebfΒ· Head:30be6328Classification: extends β the fetch gateway's secret-resolution contract gains an explicit, header-scoped opt-out; no primitives added.
Primitives touched
secretsx-kody-secret-resolution: offopt-outSystem map
Before / after
Invariants
Secret isolation is preserved: the opt-out can only prevent resolution, never widen it. The header cannot be injected via data (headers are code-controlled), and unknown header values throw instead of silently resolving.
Testing
fetch-gateway.node.test.ts: opt-out sends placeholders literally with the header stripped andresolveSecretnever called;onresolves normally and strips the header; unknown values throw.npm run validategreen (format, lint, typecheck, 688 unit tests, Playwright E2E, MCP E2E).Summary by CodeRabbit
New Features
Bug Fixes