activeloopai / activeloopai/hivemind
Redact secrets on the Cowork transcript ingest path (+ tests)
- 主要言語
- TypeScript
- スター
- 1.6k
- フォーク
- 107
- 平均マージ
- 17時間 30分
- マージ済み PR(30日)
- 6
説明
Follow-up to #307 (secret redaction on capture).
#307 masks secrets before persist/embed on the four agent capturers + `uploadSummary`. The **Cowork transcript ingest** path (`src/mcp/cowork-ingest.ts`, `entriesForLine` → queued session rows) is NOT yet redacted — deferred because that file is ~35% covered and wiring redaction into #307 dragged the PR's coverage comment down.
**Scope:**
- Apply `redactSecrets(...)` to the serialized entry in `cowork-ingest.ts` (the `const serialized = JSON.stringify(entry)` site), matching the pattern in the agent capturers.
- Add a real test suite for `cowork-ingest.ts` (currently ~35%): cover `entriesForLine` (pure transcript→entries mapping) and assert a secret in a Cowork transcript entry is masked before it's queued/embedded.
Until this lands, secrets echoed in Cowork transcripts are captured verbatim.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。