From 80cd11441b790017e6f56346f36343f3bea191d1 Mon Sep 17 00:00:00 2001 From: Dev Chiniwala Date: Tue, 8 Sep 2026 18:33:17 +0530 Subject: [PATCH] fix(redact): add GitLab and PyPI token prefixes to secret detection The KEY_PREFIXES array covers content-shaped secrets that appear in bot replies, tool titles, and permission cards. Two well-documented credential prefixes were missing: - glpat- (GitLab personal access tokens) - pypi- (PyPI API tokens) Both are unmistakable and meet the "high precision on purpose" criterion stated in the module's header comment: a false positive on either prefix is essentially impossible. Co-Authored-By: Claude Opus 4.6 --- server/redact.test.ts | 2 ++ server/redact.ts | 2 ++ 2 files changed, 4 insertions(+) diff --git a/server/redact.test.ts b/server/redact.test.ts index 98ee2e6..d5d697a 100644 --- a/server/redact.test.ts +++ b/server/redact.test.ts @@ -168,6 +168,8 @@ describe("redactSecretsInText", () => { [`aws ${"AKIA" + "IOSFODNN7EXAMPLE"} and more`, /IOSFODNN7EXAMPLE/], [`google ${"AIza" + "SyA-"}${alpha.slice(0, 32)}`, /AIza/], [`npm ${"npm" + "_"}${alpha}`, /npm_[a-z]/], + [`gitlab ${"glpat" + "-"}${alpha}`, /glpat-[a-z]/], + [`pypi ${"pypi" + "-"}${alpha.slice(0, 24)}`, /pypi-[a-z]/], ]; for (const [input, leak] of cases) { const out = redactSecretsInText(input); diff --git a/server/redact.ts b/server/redact.ts index c7d2126..9bb9806 100644 --- a/server/redact.ts +++ b/server/redact.ts @@ -52,6 +52,8 @@ const KEY_PREFIXES: RegExp[] = [ /\bAKIA[0-9A-Z]{16}\b/g, // aws access key id /\bAIza[0-9A-Za-z_-]{30,}/g, // google api key /\bnpm_[A-Za-z0-9]{20,}/g, // npm + /\bglpat-[A-Za-z0-9_-]{20,}/g, // gitlab personal access token + /\bpypi-[A-Za-z0-9_-]{16,}/g, // pypi api token /\beyJ[A-Za-z0-9_-]{8,}\.[A-Za-z0-9_-]{8,}\.[A-Za-z0-9_-]{8,}\b/g, // jwt ]; const BEARER = /(\bBearer\s+)([A-Za-z0-9._~+/=-]{12,})/g;