github / github/copilot-cli

Password masking feature fails to mask passwords from agents and makes them use extra tokens

Đang mở
#4,241 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
area:tools
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

### Describe the bug

Every time I have an agent read a file with a password in, (most often it is a dummy password) the password gets masked from the agent. The agent then every single time, uses python to read the underlying bytes in the file, and gets stuck on thinking the password is an issue, when the password is not an issue, it just picks up as a false positive due to not being able to read the password. From that point, all file edits by the agent are done via python instead of the view tool.

### Affected version

GitHub Copilot CLI 1.0.74.

### Steps to reproduce the behavior

Here is a little snippet from my conversation, with paths to my files redacted:
"""
The file uses \`\` which is masking the password in the DB_URL default. The view tool is showing this. Let me check the raw content to be safe. The old_str I'm trying to match includes `"localhost:5432/password_dummy"` but with what the view shows, the match should work. Let me check more carefully... Ah wait, looking at the view output again - it shows `"localhost:5432/password_dummy"` but when I tried to match this in old_str with the exact same text, it didn't match. This is strange. The view tool might be masking actual content (the `postgres://` prefix is being masked as \`\`). Let me use bash to check the actual content. Shell Read raw install.sh content 21 lines… head -20 {REDACTED} | cat Shell Check raw DB_URL line bytes 6 lines… python3 - << 'EOF' with open('{REDACTED}', 'rb') as f: content = f.read() # Show hex of the DB_URL line for line in cont… Thought for 3s OK the view tool is masking `postgres://` with \`\`. The raw content actually has `postgres://` replaced with \`\` which is the view tool masking. Wait no - let me look more carefully. The bash output also shows `localhost:5432/password_dummy`. So the actual file content has `localhost:5432/password_dummy` as the default URL. This is probably `postgres://` being masked. Actually looking at this again, the file literally contains the string `"postgres://localhost:5432/password_dummy"` and the view tool is masking the `postgres://` prefix. Let me verify by showing more bytes:
"""

### Expected behavior

_No response_

### Additional context

_No response_

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Tái hiện vấn đề trong view tool bằng cách sử dụng một tệp chứa DB_URL được hiển thị, rồi so sánh nội dung được hiển thị với các lần đọc thô bằng bash và Python. Theo dõi cách tính năng che mật khẩu xử lý giá trị postgres:// và cách agent nhận kết quả. Công việc được xem là hoàn tất khi phần văn bản URL không phải là mật khẩu được hiển thị nhất quán và agent không còn cần các lần đọc thay thế cho những chỉnh sửa tệp thông thường.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python, shell
Lĩnh vực
cli, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
38/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.