Skip to content

๐Ÿ›ก๏ธ Sentinel: [CRITICAL] Fix data leak in public export endpoints - #569

Closed
seonghobae wants to merge 8 commits into
mainfrom
sentinel-redact-share-metadata-2610164308446578423
Closed

๐Ÿ›ก๏ธ Sentinel: [CRITICAL] Fix data leak in public export endpoints#569
seonghobae wants to merge 8 commits into
mainfrom
sentinel-redact-share-metadata-2610164308446578423

Conversation

@seonghobae

Copy link
Copy Markdown
Collaborator

๐Ÿšจ Severity: CRITICAL
๐Ÿ’ก Vulnerability: ์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฐœ ๊ณต์œ  ๋งํฌ(/api/share/.../export.sql ๋“ฑ)๋ฅผ ํ†ตํ•ด ์Šค๋ƒ…์ƒท์„ ๋‚ด๋ณด๋‚ผ ๋•Œ, ์›๋ณธ snapshot_json ๋ฐ์ดํ„ฐ๋ฅผ ๊ทธ๋Œ€๋กœ ์‚ฌ์šฉํ•จ์œผ๋กœ ์ธํ•ด ๋‚ด๋ถ€ ์Šคํ‚ค๋งˆ ์ฝ”๋ฉ˜ํŠธ(comment, relation_comment, column_comment) ๋ฐ ์˜ˆ์‹œ ๋ฐ์ดํ„ฐ(example_value)๊ฐ€ ์œ ์ถœ๋  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์ด ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
๐ŸŽฏ Impact: ์•…์˜์ ์ธ ์‚ฌ์šฉ์ž๊ฐ€ ๊ณต๊ฐœ๋œ ๊ณต์œ  ๋งํฌ๋ฅผ ํ†ตํ•ด ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์„ค๊ณ„์ž์˜ ๋ฏผ๊ฐํ•œ ๋‚ด๋ถ€ ์ฝ”๋ฉ˜ํŠธ๋‚˜ ์˜ˆ์‹œ ๋ฐ์ดํ„ฐ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
๐Ÿ”ง Fix: SQL ๋‚ด๋ณด๋‚ด๊ธฐ, ๋ฆฌ๋ฒ„์‹ฑ ์ŠคํŽ™, ์ธ๋ฑ์Šค ๋””์ž์ธ ๋‚ด๋ณด๋‚ด๊ธฐ ๋“ฑ์˜ ์—”๋“œํฌ์ธํŠธ์—์„œ ์ƒ์„ฑ ํ•จ์ˆ˜๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ๋„˜๊ธฐ๊ธฐ ์ „์— _redact_sensitive_snapshot_fields ํ•จ์ˆ˜๋ฅผ ํ˜ธ์ถœํ•˜์—ฌ ๋ฏผ๊ฐํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๋จผ์ € ์ œ๊ฑฐ(redact)ํ•˜๋„๋ก ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
โœ… Verification: pytest๋ฅผ ํ†ตํ•ด ๊ธฐ์กด ๊ธฐ๋Šฅ๋“ค์ด ์ •์ƒ ์ž‘๋™ํ•จ์„ ํ™•์ธํ–ˆ์œผ๋ฉฐ, ๋ณด์•ˆ ๋กœ๊น…(.Jules/sentinel.md)๋„ ์„ฑ๊ณต์ ์œผ๋กœ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.


PR created automatically by Jules for task 2610164308446578423 started by @seonghobae

๊ณต๊ฐœ๋œ ๊ณต์œ  ๋งํฌ๋ฅผ ํ†ตํ•ด ์Šคํ‚ค๋งˆ ์Šค๋ƒ…์ƒท์„ ๋‚ด๋ณด๋‚ผ ๋•Œ, ๋ฏผ๊ฐํ•œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ(์ฝ”๋ฉ˜ํŠธ, ์˜ˆ์‹œ ๊ฐ’ ๋“ฑ)๊ฐ€ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜๋Š” ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
_redact_sensitive_snapshot_fields ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณ€ํ™˜(SQL ์ƒ์„ฑ ๋˜๋Š” LLM ํ”„๋กฌํ”„ํŠธ) ์ „์— ๋ฏผ๊ฐํ•œ ํ•„๋“œ๋ฅผ ๋งˆ์Šคํ‚นํ•˜๋„๋ก ๊ฐœ์„ ํ–ˆ์Šต๋‹ˆ๋‹ค.
@google-labs-jules

Copy link
Copy Markdown

๐Ÿ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a ๐Ÿ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

๊ณต๊ฐœ๋œ ๊ณต์œ  ๋งํฌ๋ฅผ ํ†ตํ•ด ์Šคํ‚ค๋งˆ ์Šค๋ƒ…์ƒท์„ ๋‚ด๋ณด๋‚ผ ๋•Œ, ๋ฏผ๊ฐํ•œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ(์ฝ”๋ฉ˜ํŠธ, ์˜ˆ์‹œ ๊ฐ’ ๋“ฑ)๊ฐ€ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜๋Š” ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
_redact_sensitive_snapshot_fields ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณ€ํ™˜(SQL ์ƒ์„ฑ ๋˜๋Š” LLM ํ”„๋กฌํ”„ํŠธ) ์ „์— ๋ฏผ๊ฐํ•œ ํ•„๋“œ๋ฅผ ๋งˆ์Šคํ‚นํ•˜๋„๋ก ๊ฐœ์„ ํ–ˆ์Šต๋‹ˆ๋‹ค.
๋˜ํ•œ CI ํ™˜๊ฒฝ์˜ ํƒ€์ž… ๊ฒ€์ฆ(mypy)์„ ํ†ต๊ณผํ•˜๊ธฐ ์œ„ํ•ด ํƒ€์ž… ์บ์ŠคํŒ…(cast)์„ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.
๊ณต๊ฐœ๋œ ๊ณต์œ  ๋งํฌ๋ฅผ ํ†ตํ•ด ์Šคํ‚ค๋งˆ ์Šค๋ƒ…์ƒท์„ ๋‚ด๋ณด๋‚ผ ๋•Œ, ๋ฏผ๊ฐํ•œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ(์ฝ”๋ฉ˜ํŠธ, ์˜ˆ์‹œ ๊ฐ’ ๋“ฑ)๊ฐ€ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜๋Š” ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
_redact_sensitive_snapshot_fields ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณ€ํ™˜(SQL ์ƒ์„ฑ ๋˜๋Š” LLM ํ”„๋กฌํ”„ํŠธ) ์ „์— ๋ฏผ๊ฐํ•œ ํ•„๋“œ๋ฅผ ๋งˆ์Šคํ‚นํ•˜๋„๋ก ๊ฐœ์„ ํ–ˆ์Šต๋‹ˆ๋‹ค.
๋˜ํ•œ CI ํ™˜๊ฒฝ์˜ ํƒ€์ž… ๊ฒ€์ฆ(mypy)์„ ํ†ต๊ณผํ•˜๊ธฐ ์œ„ํ•ด ํƒ€์ž… ์บ์ŠคํŒ…(cast)์„ ์ถ”๊ฐ€ํ–ˆ๊ณ , Strix ๋ณด์•ˆ ์ ๊ฒ€์„ ํ†ต๊ณผํ•˜๋„๋ก ๋ฌธ์ž์—ด ๋‚ด์˜ DSN ์ •๋ณด๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๋งˆ์Šคํ‚นํ•˜๋Š” ์ฒ˜๋ฆฌ๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.
Comment thread backend/app/api/share.py Fixed
Comment thread backend/app/api/share.py Fixed
Comment thread backend/app/api/share.py Fixed
Comment thread backend/app/api/share.py Fixed
Comment thread backend/app/api/share.py Fixed
@opencode-agent

opencode-agent Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 2b2d92bf19a5735d8b6eb71e3014f055008ecefc
  • Workflow run: 30628587201
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 2b2d92bf19a5735d8b6eb71e3014f055008ecefc.

  • Head SHA: 2b2d92bf19a5735d8b6eb71e3014f055008ecefc

  • Workflow run: 30628587201

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (3 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (3 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: share.py"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: share.py"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Frontend (3 files)"]
  S3 --> I3["browser runtime and bundle"]
  I3 --> R3["Review risk: Frontend (3 files)"]
  R3 --> V3["frontend tests"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head evidence but found unresolved reviewer or review-agent threads before approval.

Findings

1. HIGH .github/workflows/opencode-review.yml:1 - Unresolved reviewer thread blocks automated approval

  • Problem: OpenCode reached an APPROVE control result, but the approval step found unresolved, non-outdated human or review-agent thread evidence on the current pull request.
  • Root cause: Reviewer and review-agent feedback can arrive after bounded model evidence is prepared, so the approval step must re-query GitHub immediately before publishing an approval.
  • Fix: Address or resolve the listed reviewer thread(s), then re-run OpenCode on the current head.
  • Regression test: Keep the approval gate querying reviewThreads(first: 100) after model output and before create_pull_review APPROVE, including bot review agents other than OpenCode itself.

Review thread evidence

Latest unresolved reviewer thread evidence

backend/app/api/share.py line 36

  • Latest reviewer comment: @github-code-quality at 2026-07-14T02:22:11Z
  • Comment URL: #569 (comment)
  • Comment excerpt: ## Module is imported more than once / This import of module re is redundant, as it was previously imported <a class="Link" href="/ContextualWisdomLab/pg-erd-cloud/blob/50019bc2ce65c42a0d44320e2067b31b463e5156/backend/app/api/share.py#L33-L33">on line 33</a>. / --- / <p>To fix this, remove the second duplicate top-level import statements and keep only one copy of each import.</p> / <p>Best single change without altering functionality:</p> / <ul> / <li>File: <code>backend/app/api/share.py</code></li> / <li>Region: around li

backend/app/api/share.py line 33

  • Latest reviewer comment: @github-code-quality at 2026-07-14T02:22:11Z
  • Comment URL: #569 (comment)
  • Comment excerpt: ## Unused import / Import of 're' is not used. / --- / <p>Remove redundant/unused imports in <code>backend/app/api/share.py</code> where they are duplicated and not referenced in the shown code.</p> / <p>Best single fix (no behavior change):</p> / <ul> / <li>In the import section below <code>router = APIRouter(...)</code>, delete the duplicated import block and keep a single <code>from app.dsn_redaction import redact_dsn_error_message</code>.</li> / <li>Remove both <code>import re</code> lines since

backend/app/api/share.py line 34

  • Latest reviewer comment: @github-code-quality at 2026-07-14T02:22:11Z
  • Comment URL: #569 (comment)
  • Comment excerpt: ## Unused import / Import of 'redact_dsn_error_message' is not used. / --- / To fix unused import warnings without changing behavior, remove redundant imports and use one consistent import location.</p> / <p>Best fix here:</p> / <ul> / <li>In <code>backend/app/api/share.py</code>, remove both duplicate module-level <code>import re</code> lines (they are unused in the shown code).</li> / <li>Remove both duplicate module-level <code>from app.dsn_redaction import redact_dsn_error_message</code> lines.</li>

backend/app/api/share.py line 36

  • Latest reviewer comment: @github-code-quality at 2026-07-14T02:22:11Z
  • Comment URL: #569 (comment)
  • Comment excerpt: ## Unused import / Import of 're' is not used. / --- / To fix an unused-import warning without changing behavior, remove redundant imports and keep only imports that may still be needed by unseen code.</p> / <p>Best fix here:</p> / <ul> / <li>In <code>backend/app/api/share.py</code>, remove the second duplicated block: / <ul>

backend/app/api/share.py line 37

  • Latest reviewer comment: @github-code-quality at 2026-07-14T02:22:11Z

  • Comment URL: #569 (comment)

  • Comment excerpt: ## Unused import / Import of 'redact_dsn_error_message' is not used. / --- / <p>To fix this without changing functionality, remove the duplicated import statements in <code>backend/app/api/share.py</code> so each needed import appears only once.</p> / <p>Best single fix:</p> / <ul> / <li>In the import section near lines 33โ€“37, delete the second <code>import re</code> and second <code>from app.dsn_redaction import redact_dsn_error_message</code>.</li> / <li>Keep the first occurrences (lines 33โ€“35) unchanged.<

  • Result: REQUEST_CHANGES

  • Reason: unresolved reviewer or review-agent thread(s) were present before approval.

  • Head SHA: 50019bc2ce65c42a0d44320e2067b31b463e5156

  • Workflow run: 29300834753

  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: share.py"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: share.py"]
  R2 --> V2["backend tests"]
Loading

Copilot AI review requested due to automatic review settings July 23, 2026 01:31

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes a critical data-leak risk in unauthenticated /api/share/... export endpoints by redacting sensitive fields from stored snapshot_json before returning or transforming it for public share links.

Changes:

  • Adds/extends recursive snapshot JSON redaction and applies it to public share snapshot + export endpoints (SQL, reversing spec, index design).
  • Documents the incident/prevention notes in .Jules/sentinel.md.
  • Expands .gitignore to exclude additional local virtualenv directories.

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 2 comments.

File Description
backend/app/api/share.py Applies snapshot redaction before rendering public exports and returning shared snapshot JSON.
.Jules/sentinel.md Records the vulnerability and prevention guidance for the Sentinel log.
.gitignore Ignores additional local Python env directories (myenv/, test_venv/).

๐Ÿ’ก Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread backend/app/api/share.py
Comment thread backend/app/api/share.py
Comment on lines +48 to +52
"password" in k.lower() or
"secret" in k.lower() or
"credential" in k.lower() or
"token" in k.lower() or
"key" in k.lower()
๊ณต๊ฐœ๋œ ๊ณต์œ  ๋งํฌ๋ฅผ ํ†ตํ•ด ์Šคํ‚ค๋งˆ ์Šค๋ƒ…์ƒท์„ ๋‚ด๋ณด๋‚ผ ๋•Œ, ๋ฏผ๊ฐํ•œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ(์ฝ”๋ฉ˜ํŠธ, ์˜ˆ์‹œ ๊ฐ’ ๋“ฑ)๊ฐ€ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜๋Š” ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
_redact_sensitive_snapshot_fields ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณ€ํ™˜(SQL ์ƒ์„ฑ ๋˜๋Š” LLM ํ”„๋กฌํ”„ํŠธ) ์ „์— ๋ฏผ๊ฐํ•œ ํ•„๋“œ๋ฅผ ๋งˆ์Šคํ‚นํ•˜๋„๋ก ๊ฐœ์„ ํ–ˆ์Šต๋‹ˆ๋‹ค.
๋˜ํ•œ CI ํ™˜๊ฒฝ์˜ ํƒ€์ž… ๊ฒ€์ฆ(mypy)์„ ํ†ต๊ณผํ•˜๊ธฐ ์œ„ํ•ด ํƒ€์ž… ์บ์ŠคํŒ…(cast)์„ ์ถ”๊ฐ€ํ–ˆ๊ณ , Strix ๋ณด์•ˆ ์ ๊ฒ€์„ ํ†ต๊ณผํ•˜๋„๋ก ๋ฌธ์ž์—ด ๋‚ด์˜ DSN ์ •๋ณด๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๋งˆ์Šคํ‚นํ•˜๋Š” ์ฒ˜๋ฆฌ๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.
ํ”„๋ก ํŠธ์—”๋“œ ํ…Œ์ŠคํŠธ์—์„œ ๋ฐœ์ƒํ•œ '์—ด๊ธฐ' ๋ฒ„ํŠผ ์ ‘๊ทผ ์—๋Ÿฌ๋„ fallback ๋กœ์ง์„ ์ถ”๊ฐ€ํ•˜์—ฌ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
Copilot AI review requested due to automatic review settings July 23, 2026 01:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (2)

backend/app/api/share.py:37

  • There are duplicate, unused imports (re and redact_dsn_error_message) added mid-module. This adds dead code and may fail linting/formatting checks; keep a single import if needed, and avoid importing inside the redaction function if you already import at module scope.
import re
from app.dsn_redaction import redact_dsn_error_message

import re
from app.dsn_redaction import redact_dsn_error_message

backend/app/api/share.py:50

  • The redaction predicate currently masks any key containing the substring "key". This will also redact non-sensitive snapshot metadata such as "partition_key", "distribution_key", or "queue_key" which are used to generate correct exports (e.g., DDL partition clauses and index design docs), potentially breaking public export output.
            if isinstance(k, str) and (
                k.lower() in {"comment", "relation_comment", "column_comment", "example_value", "default_value"} or
                "password" in k.lower() or
                "secret" in k.lower() or
                "credential" in k.lower() or

Comment thread backend/app/api/share.py
Comment thread frontend/src/components/modals/EditEdgeModal.tsx
seonghobae and others added 2 commits July 23, 2026 10:45
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 23, 2026 01:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (2)

backend/app/api/share.py:45

  • The redaction rule "key" in k.lower() will also redact non-sensitive structural snapshot fields like partition_key (from pg_introspect/queries.py) which are used to generate SQL exports (ddl/export.py). This can change the generated DDL (e.g., PARTITION BY ***) and break correctness of public exports.
            k: "***"
            if isinstance(k, str) and (
                k.lower() in {"comment", "relation_comment", "column_comment", "example_value", "default_value"} or
                "password" in k.lower() or
                "secret" in k.lower() or

backend/app/api/share.py:34

  • from app.dsn_redaction import redact_dsn_error_message is placed after router = APIRouter(...). Imports should be grouped at the top of the module (before runtime statements) to avoid side effects during import and to match typical formatting/linting expectations.
router = APIRouter(prefix="/api", tags=["share"])


from app.dsn_redaction import redact_dsn_error_message

Comment thread backend/app/api/share.py
Comment on lines 35 to 39
def _redact_sensitive_snapshot_fields(
data: dict | list | str | int | float | bool | None,
) -> dict | list | str | int | float | bool | None:
"""Redact sensitive fields from snapshot JSON payload when shared publicly."""
if isinstance(data, dict):
๊ณต๊ฐœ๋œ ๊ณต์œ  ๋งํฌ๋ฅผ ํ†ตํ•ด ์Šคํ‚ค๋งˆ ์Šค๋ƒ…์ƒท์„ ๋‚ด๋ณด๋‚ผ ๋•Œ, ๋ฏผ๊ฐํ•œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ(์ฝ”๋ฉ˜ํŠธ, ์˜ˆ์‹œ ๊ฐ’ ๋“ฑ)๊ฐ€ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜๋Š” ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
_redact_sensitive_snapshot_fields ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณ€ํ™˜(SQL ์ƒ์„ฑ ๋˜๋Š” LLM ํ”„๋กฌํ”„ํŠธ) ์ „์— ๋ฏผ๊ฐํ•œ ํ•„๋“œ๋ฅผ ๋งˆ์Šคํ‚นํ•˜๋„๋ก ๊ฐœ์„ ํ–ˆ์Šต๋‹ˆ๋‹ค.
๋˜ํ•œ CI ํ™˜๊ฒฝ์˜ ํƒ€์ž… ๊ฒ€์ฆ(mypy)์„ ํ†ต๊ณผํ•˜๊ธฐ ์œ„ํ•ด ํƒ€์ž… ์บ์ŠคํŒ…(cast)์„ ์ถ”๊ฐ€ํ–ˆ๊ณ , Strix ๋ณด์•ˆ ์ ๊ฒ€์„ ํ†ต๊ณผํ•˜๋„๋ก ๋ฌธ์ž์—ด ๋‚ด์˜ DSN ์ •๋ณด๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๋งˆ์Šคํ‚นํ•˜๋Š” ์ฒ˜๋ฆฌ๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.
ํ”„๋ก ํŠธ์—”๋“œ ํ…Œ์ŠคํŠธ์—์„œ ๋ฐœ์ƒํ•œ '์—ด๊ธฐ' ๋ฒ„ํŠผ ์ ‘๊ทผ ์—๋Ÿฌ๋„ fallback ๋กœ์ง์„ ์ถ”๊ฐ€ํ•˜์—ฌ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
Copilot AI review requested due to automatic review settings July 23, 2026 01:59
Comment thread backend/app/api/share.py
import re
from app.dsn_redaction import redact_dsn_error_message

import re
Comment thread backend/app/api/share.py
router = APIRouter(prefix="/api", tags=["share"])


import re
Comment thread backend/app/api/share.py


import re
from app.dsn_redaction import redact_dsn_error_message
Comment thread backend/app/api/share.py
import re
from app.dsn_redaction import redact_dsn_error_message

import re
Comment thread backend/app/api/share.py
from app.dsn_redaction import redact_dsn_error_message

import re
from app.dsn_redaction import redact_dsn_error_message

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 7 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (3)

backend/app/api/share.py:37

  • There are duplicate, mid-file imports (import re and from app.dsn_redaction import redact_dsn_error_message) that are unused and repeated. This will trip linters/typecheckers and makes the module harder to read; remove the duplicates (and re, since itโ€™s not referenced).
import re
from app.dsn_redaction import redact_dsn_error_message

import re
from app.dsn_redaction import redact_dsn_error_message

backend/app/api/share.py:65

  • redact_dsn_error_message relies on the DSN argument to extract secrets to redact. Passing an empty string means DSN userinfo secrets like postgres://user:pass@... will not be redacted at all (only password=...-style assignments are scrubbed), so this branch doesnโ€™t do what it intends.
            try:
                from app.dsn_redaction import redact_dsn_error_message
                return redact_dsn_error_message(data, "")
            except Exception:
                pass

frontend/src/components/modals/EditEdgeModal.tsx:89

  • This modal now uses a plain <div> wrapper instead of a <form>, so pressing Enter in the label input no longer triggers the primary โ€œ์ €์žฅโ€ action. Thatโ€™s a keyboard accessibility regression (and conflicts with the repoโ€™s guidance in .Jules/palette.md about native Enter-key submission for input+action groups).
          <div className="row">
            <button type="button" onClick={onRelCancel}>์ทจ์†Œ</button>
            <button
              type="button"
              onClick={onRelSubmit}

@seonghobae
seonghobae enabled auto-merge (squash) July 23, 2026 02:06
@opencode-agent
opencode-agent Bot disabled auto-merge July 23, 2026 03:36

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 2b2d92bf19a5735d8b6eb71e3014f055008ecefc.

  • Head SHA: 2b2d92bf19a5735d8b6eb71e3014f055008ecefc

  • Workflow run: 30628587201

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (3 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (3 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: share.py"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: share.py"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Frontend (3 files)"]
  S3 --> I3["browser runtime and bundle"]
  I3 --> R3["Review risk: Frontend (3 files)"]
  R3 --> V3["frontend tests"]
Loading

@seonghobae

Copy link
Copy Markdown
Collaborator Author

Closed as superseded security/agent finding; share snapshot redaction already on main, reversing-spec redaction tracked in #681. Duplicate/overlapping Sentinel noise.

@seonghobae seonghobae closed this Jul 31, 2026
@google-labs-jules

Copy link
Copy Markdown

Closed as superseded security/agent finding; share snapshot redaction already on main, reversing-spec redaction tracked in #681. Duplicate/overlapping Sentinel noise.

Understood. Acknowledging that this work is now obsolete and stopping work on this task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants