activeloopai / activeloopai/hivemind
Redact secrets on the Cowork transcript ingest path (+ tests)
- Lenguaje dominante
- TypeScript
- Estrellas
- 1.6k
- Forks
- 107
- Merge medio
- 17 h 30 min
- PR fusionados (30 d)
- 6
Descripción
Follow-up to #307 (secret redaction on capture).
#307 masks secrets before persist/embed on the four agent capturers + `uploadSummary`. The **Cowork transcript ingest** path (`src/mcp/cowork-ingest.ts`, `entriesForLine` → queued session rows) is NOT yet redacted — deferred because that file is ~35% covered and wiring redaction into #307 dragged the PR's coverage comment down.
**Scope:**
- Apply `redactSecrets(...)` to the serialized entry in `cowork-ingest.ts` (the `const serialized = JSON.stringify(entry)` site), matching the pattern in the agent capturers.
- Add a real test suite for `cowork-ingest.ts` (currently ~35%): cover `entriesForLine` (pure transcript→entries mapping) and assert a secret in a Cowork transcript entry is masked before it's queued/embedded.
Until this lands, secrets echoed in Cowork transcripts are captured verbatim.
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.