Skip to content

Fix credential guard gaps and clarify private-note storage - #168

Merged
suboss87 merged 2 commits into
Mainfrom
fix/credential-guard
Oct 5, 2026
Merged

suboss87 merged 2 commits into
Mainfrom
fix/credential-guard

Conversation

@suboss87

@suboss87 suboss87 commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Fix

The write guard accepted hyphenated AI-provider keys and secret assignments shorter than eight characters, allowing accidental credentials into Git-backed engagement records. Extend supported key characters and reject nonempty assignments regardless of length. Output masking covers the same assignment forms, including punctuation and escaped quotes.

Private-note confirmation now explains that hidden content remains plaintext in local files and Git history. Credential refusal explains that undo/redact does not erase history and exposed credentials need rotation. The deliberate --force override remains available with a warning.

Includes version 5.1.24 and synthetic regression tests for write refusal, unchanged history, debrief/ingest, whole-value masking, and ordinary nonsecret text. No real credentials or customer records were used.

Validation

  • 18 credential regressions passed; focused masking and ingestion coverage passed.
  • Independent review found no remaining concrete regressions after correction.
  • npm run check: 509 tests passed, zero failures or skips on the final revision.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@suboss87
suboss87 merged commit 303af32 into Main Oct 5, 2026
2 checks passed
@suboss87
suboss87 deleted the fix/credential-guard branch October 5, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant