Skip to content

Redact secret-bearing artifact string representations #22

Description

@BenWestgate

Medium security finding. _Artifact.__str__ returns the complete Codex32 secret/share text, and dataclass reprs retain secret-bearing fields; CorrectionCandidate recursively embeds the artifact. Generic logging, REPL/notebook display, or exception context can persist recovery material.

Remediation: make str/repr redacted by default and require an explicit reveal/export operation; add nested-rendering tests.

Parent: #20

Activity

  1. self-assigned this
    on Sep 22, 2026
  2. BenWestgate commented on Sep 24, 2026

    @BenWestgate
    OwnerAuthor

    PR # 25 should have closed this issue, but it's likely waiting to reach master.

  3. BenWestgate commented on Sep 25, 2026

    @BenWestgate
    OwnerAuthor

    Resolved on reviewability-v1 by merged PR #25 (bip93: Redact artifact string rendering). Default str()/repr() are redacted, nested CorrectionCandidate rendering is covered, and .text remains the explicit export path. Closing this finding as completed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workinggate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.help wantedExtra attention is needed

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions