Skip to content

Fix credential redaction across exported session data - #49

Merged
peteromallet merged 2 commits into
mainfrom
fix/credential-redaction-coverage
Oct 11, 2026
Merged

peteromallet merged 2 commits into
mainfrom
fix/credential-redaction-coverage

Conversation

@peteromallet

Copy link
Copy Markdown
Owner

Credential redaction could miss provider-specific formats, suffixed secret names, and values outside known message fields. Overlapping detections could also leave part of a credential visible. This change scans the complete session structure, uses secret-named fields to protect opaque values, expands provider coverage, and redacts the union of overlapping matches.

Adds 102 synthetic regressions covering nested metadata, embedded JSON, dictionary-key collisions, authorization headers, punctuation, allowlist bypasses, and binary-heuristic bypasses. No captured credentials are included.

Validation: 660 tests passed with python3.11 -m pytest -q -m 'not pii'; Ruff and diff checks pass. The optional live PII-model test cannot load because the installed Transformers does not support openai_privacy_filter.

Limits remain documented: binary attachments/base64 are not decoded or OCRed, embedded JSON traversal is bounded to eight wrappers, and unknown credential formats may escape heuristic detection. This source change does not rewrite previously published datasets.

@peteromallet
peteromallet merged commit f9eae05 into main Oct 11, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant