github / github/copilot-cli

Password masking feature fails to mask passwords from agents and makes them use extra tokens

Offen
#4,241 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

area:tools
Vorherrschende Sprache
Shell
Sterne
11.2k
Forks
1.9k
Ø Merge
14 Std. 16 Min.
Gemergte PRs (30 T.)
6

Beschreibung

Describe the bug

Every time I have an agent read a file with a password in, (most often it is a dummy password) the password gets masked from the agent. The agent then every single time, uses python to read the underlying bytes in the file, and gets stuck on thinking the password is an issue, when the password is not an issue, it just picks up as a false positive due to not being able to read the password. From that point, all file edits by the agent are done via python instead of the view tool.

Affected version

GitHub Copilot CLI 1.0.74.

Steps to reproduce the behavior

Here is a little snippet from my conversation, with paths to my files redacted:
"""
The file uses `` which is masking the password in the DB_URL default. The view tool is showing this. Let me check the raw content to be safe. The old_str I'm trying to match includes "localhost:5432/password_dummy" but with what the view shows, the match should work. Let me check more carefully... Ah wait, looking at the view output again - it shows "localhost:5432/password_dummy" but when I tried to match this in old_str with the exact same text, it didn't match. This is strange. The view tool might be masking actual content (the postgres:// prefix is being masked as ``). Let me use bash to check the actual content. Shell Read raw install.sh content 21 lines… head -20 {REDACTED} | cat Shell Check raw DB_URL line bytes 6 lines… python3 - << 'EOF' with open('{REDACTED}', 'rb') as f: content = f.read() # Show hex of the DB_URL line for line in cont… Thought for 3s OK the view tool is masking postgres:// with ``. The raw content actually has postgres:// replaced with `` which is the view tool masking. Wait no - let me look more carefully. The bash output also shows localhost:5432/password_dummy. So the actual file content has localhost:5432/password_dummy as the default URL. This is probably postgres:// being masked. Actually looking at this again, the file literally contains the string "postgres://localhost:5432/password_dummy" and the view tool is masking the postgres:// prefix. Let me verify by showing more bytes:
"""

Expected behavior

No response

Additional context

No response

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Reproduziere das Problem im view tool mit einer Datei, die die angezeigte DB_URL enthält, und vergleiche ihren angezeigten Inhalt mit den rohen Lesevorgängen in bash und Python. Verfolge, wie die Passwortmaskierung mit dem Wert postgres:// umgeht und wie der Agent das Ergebnis erhält. Erledigt ist es, wenn nicht passwortbezogener URL-Text konsistent angezeigt wird und der Agent für gewöhnliche Dateibearbeitungen keine alternativen Lesevorgänge mehr benötigt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python, shell
Bereich
cli, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
38/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.