fix: redact authorization evidence variants - #1544
Conversation
Performance BenchmarksCompared
|
mldangelo-oai
left a comment
There was a problem hiding this comment.
I found and fixed two boundary issues on the current head:
SENSITIVE_AUTH_SCHEME_ASSIGNMENT_REaccepted only a narrow credential alphabet. Unquoted scheme-bearing API/custom tokens containing valid real-world punctuation such as:,!, or%caused the scheme to be redacted while the credential remained visible. Example:apiKey = ApiKey COLON:SECRET123456becameapiKey = <redacted> COLON:SECRET123456.- The camel-case control guard used a word boundary after
Cache|Count|Enabled|Status|Timeout, so obvious benign extensions such asxApiKeyCounter,xApiKeyCount2,myApiKeyTimeoutMs, andsessionTokenEnabledFlagwere still falsely redacted.
Local commit 27de41aa reuses the existing bounded unquoted-value grammar for scheme credentials and treats the control terms as suffix prefixes. It adds positive punctuation regressions and expanded near-match negatives.
Focused validation:
tests/scanners/test_evidence_redaction.py: 254 passed- targeted auth/camel-case slice: 12 passed
- Ruff check/format: clean
- scoped mypy: clean
- changed regex scales linearly: ~0.006s for a one-million-character credential probe
git diff --check: clean
I could not push the commit because the available shell GitHub token is invalid, and the source/test files are too large for the connector's whole-file update endpoint. These findings remain on remote head c90c78e1.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c90c78e1e2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed all four review threads and synced current Security/quality fixes:
Focused validation:
Published tested tree |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b6bb267bf9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed the three latest review threads and completed another adversarial false-positive/false-negative pass. Key follow-up fixes:
Validation: 273 associated tests passed; scoped Ruff, format, mypy, and |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 630fbd7a52
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Final review pass published through Additional adversarial QA closed three live-head edge cases:
Validation on the published tree: 278 associated tests passed; scoped Ruff, format, mypy, and |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c341dc0110
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
The three post-merge authorization-redaction findings are addressed in follow-up PR #1596 ( |
|
The three post-merge findings are addressed in follow-up PR #1596 ( |
Summary
False-positive / false-negative review
SignedHeadersresponse=leakage across quoted delimiters, truncated values, and indented or unindented multiline literalsToken or eval(...), f-string executable expressions, spaced and unspaced shell commands, and source orderingAll inline review threads are resolved. Synced with
mainat6e6ba57bfe0d9fbbef5ab7b8116432353daca8b2.Validation
tests/scanners/test_evidence_redaction.py: 278 passedgit diff --check: cleanPublished tested tree:
83b1e562f775ff1eb95a25310067264df1aeae47Published head:
c341dc0110d988ad7c963c1ba8133aa3eb946c18